- developer A is tasked to create the prompt to ask for username and password of the email account
- developer B is tasked to call some API to upload contacts from email account
- developer C is tasked to bind two functionalities.
Now replace developers with teams and you see how simple is for the average developer to underestimate the scope and the ethical bounds of a given task.
That implies that you, as a developer, then hear new stories like this one and simply ignore any role you may or may not have had in the situation. It implies that you simply ignore that your manager or engineering leadership are asking you to do things that are unethical without informing you about how your work will be used. It implies that you continue to work for that leadership knowing that they will lie to you, hide their true intentions, and use your labor to execute profoundly unethical practices.
It's not news at this point to anyone working at FB what their leadership is engaged in, and what their work is being used to accomplish.
Perhaps several years ago you could claim some kind of ignorance.
That's no longer the case. You know who you work for. Own it.
I’m more surprised that people are still being “surprised” that Facebook isn’t a wholesome company out to make the world a better place through algorithmic social manipulation.
Let’s not be ignorant of the idea of one or two senior developers each given a suitcase full of cash. It’s not like learning to program magically gives you unbreakable ethics.
Even at this point, you’re not getting a mass exodus of workers from Facebook. Those in there are choosing to be there at this point. Koolaid or not.
But you are right, scope creep in the “unethical” aspects and it can suddenly be “no one’s fault”. That isn’t a bad plan.
I’m not one of them, but let me play the devil’s advocate...
You’re getting paid 2x market salary (“market” here being non-Facebook and non-Google, which isn’t any better) and delivering services to people who voluntarily sign up ro them... I mean there are worse jobs in the world.
“That’s a really dick of an idea and I’m pretty sure it’s illegal. Exactly how illegal, I’m not sure. But I know illegal to some degree.”
“You live in a shit apartment because housing prices are stupid and makes your salary meaningless in this town. Here’s a wheelbarrow full of hundreds and we all agree it was an accident.”
I’m dead serious when I say that no two large scale projects are done the same way. I have seen many and can tell you the possibilities are infinite how it gets approached
But seriously. There’s no accident in what happened. This is Facebook. Anyone who thinks Facebook isn’t morally corrupt probably also says “What do you mean Stalin wasn’t a pacifist?”
>what is your tipping point? Would you say no to that assignment?
When FB stops giving them a check.
At least that has been my experience watching programmers at other companies. Unless ethically bound by regulation and law, few people seem to have ethics.
Methinks that was what the OP was asking -- what is the tipping point ? Having differing ethics is fine but one can't just lean on that as a crutch when one has none.
What tipping point? Maybe the engineer themselves who recommends the practice. Everyone have ethics but might be differ than you. As long as the practice meet their goal, from their perspective it works.
From the article it sounds like there was a prompt for permission that got removed:
> Facebook told Gizmodo via email that in May 2016 it made a revision to the registration process, which originally asked the affected users for permission to upload contact lists. That change removed the opt-in prompt, though the company did not realize the underlying functionality was still operating in some cases.
It doesn't take a conspiracy to understand how a bug like that could happen.
This reminds me of the Firefox/Google tweet storm. A bunch of "bugs" or "unintentional feature" that get fixed with a seemingly honest apology, only for another "bug" or "unintentional feature" to take its place.
At some point, it goes from "the occasional bug" to negligence at best, and hostility at worst.
its such a coincidence that these accidents keep happening in ways that enable further data gathering...surely there isn't a larger problem with Facebook's attitude towards their users' private data or anything
"New Facebook Feature Allows User To Cancel Account. ... The company later confirmed that account closures would not stop Facebook from continuing to acquire, permanently store, and sell all information about its current and former users until the day they die." https://www.theonion.com/new-facebook-feature-allows-user-to...
That bug would be a critical failure and be caught, the reverse would be a non-critical bug that the PM decides to to put in the backlog because reasons. If in a year we haven't gotten around the fixing it, then it's time to clean out that backlog!
When every public-facing thing you build is centered on hoovering up data, you're going to have two broad classes of errors. Hoovering up too little data, which doesn't hit the news, and hoovering up too much, which does.
That said, when your "errors" directly line your pockets, you're not entitled to the benefit of the doubt.
It’s pretty hard for me to imagine that there’s some other function that just happens to coincide with accessing different email servers and collect past emails to collect the email addresses.
It was deliberate because of the work involved. The only investigators that think it’s accidental probably believe the internet is a small black box guarded by the “Internet wizards”.
I'm not excusing FB, but it still makes sense. Their whole business model is data collection on their users, graphing connections between these users, and brokering deals with advertisers about users on the platform. When something goes awry, you can bet that it will somehow affect one of those things.
Doing QA at large tech companies is never that simple. You have lots of teams that share code. Imagine a scenario where Team A uses code written by Team B which uses code written by Team C. Team C makes a change to their code that breaks Team B's code but only for the way Team A uses it.
For the people in the back, "Facebook is a multi-billion dollar company." They have 30,000 employees. They could spend the money to do better QA. But it's cheaper to let your end-users do it for free.
It doesn't matter if it's simple or not. We can't hold these 1k+ engineer teams to the same accountability levels as a 3 person team. When, as engineering professionals, are we going to put an end to this? This is completely unacceptable in any other engineering discipline.
One way to combat this is to let other teams register tests in other team's projects. If a test fails, you know it breaks someone's expectations. From there, you work with that team to update both sides.
Just to be devil's advocate: Google is notorious for having separate siloed teams that do not share efficiencies or updates (eg. Hangouts and other messengers). A company like Google and Facebook don't have a good excuse, but we shouldn't be surprised.
> A Facebook spokesperson also told Gizmodo that a screenshot of the original opt-in prompt was not available.
I'm not a conspiracy theorist but if you're trying to claim you cannot capture a screenshot from any release meant to be shipped out, either you're crap at release management or are full of shit. Which one is it?
Also, even if we were to suspend logic and belive this was a bug, what's FB doing to correct it? Are they deleting all uploaded contacts and going to request for consent again?
FB is a cesspit. Get out of the company if you work there and get out of the platform in any case.
> I'm not a conspiracy theorist but if you're trying to claim you cannot capture a screenshot from any release meant to be shipped out, either you're crap at release management or are full of shit. Which one is it?
That doesn't strike me as especially unlikely, especially for a specific branch of the app codebase that would likely only operate with a huge number of other co-dependent codebases for backend systems that no longer exist.
With six months to recover code and build a non-live environment with all the dependencies could it be done? Sure. But that's not really within the scope of a journalist request.
I would say it should take less than an hour for a dev to get an instance of a specific revision up and running, not months...but I agree with the thrust of your message: when the reporter asked their Facebook representative for a screenshot of the box, they looked in their pictures folder for a screenshot. They probably did not try to spin up an instance for the developer.
“For the FB employees reading this: what is your tipping point? Would you say no to that assignment?”
There is a good chance that they didn’t know how their work would eventually be used. That’s the problem with big companies. Most people are far away from seeing the consequences of their work.
The tipping point is when the utility value of their paychecks no longer exceed their personal sense of responsibility about the system they're complicit in.
In The Fine Article, it says that the feature was built on purpose, and previously asked for permission. The accident is that it wasn't completely removed.
They did have the upload-your-address-book functionality before they instituted this check. I’m very much hoping to see Facebook suffer for this, but I could conceivably see a scenario where they reused code that did more than they wanted.
It also takes extra work to ask consent. You build it. You don't notice that your confirmation screen fails to trigger. You've just unintentionally uploaded a bunch of data without consent, when your intention was to do it with consent.
It's still pretty darn negligent, but it's easy to see how it could be done unintentionally.
> It takes extra work to upload those contacts, which means several managers and developers decided to do it and then spent time implementing it.
Not really. Facebook is a bunch of autonomous services (registration, access, tracking, activities, etc.) accessing shared databases (chat logs, activities, media uploads, etc.) with some kind of automatic implicit and explicit ACL in place. The suggestion/contact service got access to data provided through the email-not-working-with-oauth-so-let-us-use-automatic-token-delivery-and-confirmation-by-accessing-user-emails because it was told a new source of contacts were available for those users. So, not a straight path.
Accident/Blunder > Evil.
Now. GDPR ? GDPR. And because of GDPR those things aren't supposed to happen in Europe.
Considering vast crowds of folks happily working for amoral places like investment banks (2008 crisis and its consequences) or wealth management (rich folks trying to keep as much money untaxed as possible and used for public spending), the moral bar for usual smart person is actually pretty low. Optimizing some ads seems pretty harmless when compared to.
As long as you don't see the evil being literally done ie in form or row of inmates being sent to gas chambers, there are almost endless ways to persuade yourself that all is actually OK and fine.
It takes extra work to upload those contacts, which means several managers and developers decided to do it and then spent time implementing it.
For the FB employees reading this: what is your tipping point? Would you say no to that assignment?