{"id":123701,"date":"2018-12-10T12:00:30","date_gmt":"2018-12-10T12:00:30","guid":{"rendered":"https:\/\/www.transcend.org\/tms\/?p=123701"},"modified":"2018-12-06T13:42:06","modified_gmt":"2018-12-06T13:42:06","slug":"heres-facebooks-former-privacy-sherpa-discussing-how-to-harm-your-facebook-privacy","status":"publish","type":"post","link":"https:\/\/www.transcend.org\/tms\/2018\/12\/heres-facebooks-former-privacy-sherpa-discussing-how-to-harm-your-facebook-privacy\/","title":{"rendered":"Here\u2019s Facebook\u2019s Former \u201cPrivacy Sherpa\u201d Discussing How to Harm Your Facebook Privacy"},"content":{"rendered":"<div id=\"attachment_123702\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/www.transcend.org\/tms\/wp-content\/uploads\/2018\/12\/facebook-privacy-web-summit.jpg\" ><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-123702\" class=\"wp-image-123702\" src=\"https:\/\/www.transcend.org\/tms\/wp-content\/uploads\/2018\/12\/facebook-privacy-web-summit-1024x512.jpg\" alt=\"\" width=\"600\" height=\"300\" srcset=\"https:\/\/www.transcend.org\/tms\/wp-content\/uploads\/2018\/12\/facebook-privacy-web-summit-1024x512.jpg 1024w, https:\/\/www.transcend.org\/tms\/wp-content\/uploads\/2018\/12\/facebook-privacy-web-summit-300x150.jpg 300w, https:\/\/www.transcend.org\/tms\/wp-content\/uploads\/2018\/12\/facebook-privacy-web-summit-768x384.jpg 768w, https:\/\/www.transcend.org\/tms\/wp-content\/uploads\/2018\/12\/facebook-privacy-web-summit.jpg 1440w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><p id=\"caption-attachment-123702\" class=\"wp-caption-text\">The Facebook booth at the Web Summit in Dublin on March 11, 2015.<br \/>Photo: Niall Carson\/PA Wire via AP<\/p><\/div>\n<p><em>6 Dec 2018 &#8211; <\/em>In 2015, rising star, Stanford University graduate, winner of the 13th season of \u201cSurvivor,\u201d and Facebook executive Yul Kwon was <a target=\"_blank\" href=\"https:\/\/splinternews.com\/the-guy-standing-between-facebook-and-its-next-privacy-1793844996\" >profiled<\/a> by the news outlet Fusion, which described him as \u201cthe guy standing between Facebook and its next privacy disaster,\u201d guiding the company\u2019s engineers through the dicey territory of personal data collection. Kwon described himself in the piece as a \u201cprivacy sherpa.\u201d But the day it published, Kwon was apparently chatting with other Facebook staffers about how the company could vacuum up the call logs of its users without the Android operating system getting in the way by asking for the user for specific permission, according to\u00a0<a target=\"_blank\" href=\"https:\/\/www.parliament.uk\/documents\/commons-committees\/culture-media-and-sport\/Note-by-Chair-and-selected-documents-ordered-from-Six4Three.pdf#page=243\" >confidential Facebook documents<\/a>\u00a0released today by the\u00a0British Parliament.<\/p>\n<blockquote><p><strong><em>\u201cThis would allow us to upgrade users without subjecting them to an Android permissions dialog.\u201d<\/em><\/strong><\/p><\/blockquote>\n<p>The document, part of a larger 250-page parliamentary trove, shows what appears to be a copied-and-pasted recap of an internal chat conversation between various Facebook staffers and Kwon, who was then the company\u2019s deputy chief privacy officer and is currently working as a product management director, according to his LinkedIn profile.<\/p>\n<p>The conversation centered around an internal push to change\u00a0which\u00a0data Facebook\u2019s Android app had access to, to grant the software the ability to record a user\u2019s text messages and call history, to interact with bluetooth <a target=\"_blank\" href=\"https:\/\/en.wikipedia.org\/wiki\/Facebook_Bluetooth_Beacon\" >beacons<\/a> installed by physical stores, and to offer better customized friend suggestions and news feed rankings . This would be a momentous decision for any company, to say nothing of one with Facebook\u2019s privacy track record and reputation, even in 2015, of sprinting through ethical minefields. \u201cThis is a pretty high-risk thing to do from a PR perspective but it appears that the growth team will charge ahead and do it,\u201d\u00a0Michael\u00a0LeBeau, a Facebook <a target=\"_blank\" href=\"https:\/\/www.linkedin.com\/in\/mlebeau\/?originalSubdomain=uk\" >product manager<\/a>, is quoted in the document as saying of the change.<\/p>\n<p><a href=\"https:\/\/www.transcend.org\/tms\/wp-content\/uploads\/2018\/12\/facebook-privacy.jpg\" ><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-123703\" src=\"https:\/\/www.transcend.org\/tms\/wp-content\/uploads\/2018\/12\/facebook-privacy-808x1024.jpg\" alt=\"\" width=\"700\" height=\"888\" srcset=\"https:\/\/www.transcend.org\/tms\/wp-content\/uploads\/2018\/12\/facebook-privacy-808x1024.jpg 808w, https:\/\/www.transcend.org\/tms\/wp-content\/uploads\/2018\/12\/facebook-privacy-237x300.jpg 237w, https:\/\/www.transcend.org\/tms\/wp-content\/uploads\/2018\/12\/facebook-privacy-768x974.jpg 768w, https:\/\/www.transcend.org\/tms\/wp-content\/uploads\/2018\/12\/facebook-privacy.jpg 1000w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/a><\/p>\n<p>Crucially, LeBeau commented, according to the document, such a privacy change would require Android users to essentially opt in; Android, he said, would present them with a permissions dialog soliciting their approval to share call logs when they\u00a0were to upgrade\u00a0to a version of the app that collected the logs and texts. Furthermore, the Facebook app itself would prompt users to opt in to the feature, through a notification referred to by LeBeau as \u201can in-app opt-in NUX,\u201d or\u00a0<a target=\"_blank\" href=\"https:\/\/medium.com\/facebook-research\/speaking-design-what-a-few-key-terms-taught-me-82d1491d6da2\" >new user experience<\/a>. The Android dialog was especially problematic; such permission dialogs \u201ctank upgrade rates,\u201d LeBeau stated.<\/p>\n<p>But Kwon appeared to later suggest that the company\u2019s engineers might be able to upgrade users to the log-collecting version of the app without any such nagging from the phone\u2019s operating system.\u00a0He also indicated that the plan to obtain text messages had been dropped, according to the document. \u201cBased on [the growth team\u2019s] initial testing, it seems this would allow us to upgrade users without subjecting them to an Android permissions dialog at all,\u201d\u00a0 he stated. Users would have to click to\u00a0effect the upgrade, he added, but, he reiterated, \u201cno permissions dialog screen.\u201d<\/p>\n<p>It\u2019s not clear if Kwon\u2019s comment about \u201cno permissions dialog screen\u201d applied to the opt-in notification within the Facebook app. But even if the Facebook app still sought permission to share call logs, such in-app notices are generally designed expressly to get the user to consent and are easy to miss or misinterpret. Android users rely on standard, clear dialogs from the operating system to inform them of serious changes in privacy. There\u2019s good reason Facebook would want to avoid \u201csubjecting\u201d its users to a screen displaying exactly what they\u2019re about to hand over to the company:<\/p>\n<p><a href=\"https:\/\/www.transcend.org\/tms\/wp-content\/uploads\/2018\/12\/facebook-privacy2.jpg\" ><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-123704\" src=\"https:\/\/www.transcend.org\/tms\/wp-content\/uploads\/2018\/12\/facebook-privacy2-1024x766.jpg\" alt=\"\" width=\"700\" height=\"524\" srcset=\"https:\/\/www.transcend.org\/tms\/wp-content\/uploads\/2018\/12\/facebook-privacy2.jpg 1024w, https:\/\/www.transcend.org\/tms\/wp-content\/uploads\/2018\/12\/facebook-privacy2-300x224.jpg 300w, https:\/\/www.transcend.org\/tms\/wp-content\/uploads\/2018\/12\/facebook-privacy2-768x575.jpg 768w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/a><\/p>\n<p>It\u2019s not clear how this specific discussion was resolved, but Facebook did eventually begin obtaining call logs and text messages from users of its Messenger and Facebook Lite apps for Android. This proved highly controversial when revealed in press accounts and by <a target=\"_blank\" href=\"https:\/\/www.theverge.com\/2018\/3\/25\/17160944\/facebook-call-history-sms-data-collection-android\" >individuals<\/a> posting on Twitter after receiving data Facebook had collected on them; Facebook <a target=\"_blank\" href=\"https:\/\/newsroom.fb.com\/news\/2018\/03\/fact-check-your-call-and-sms-history\/\" >insisted<\/a> it had obtained permission for the phone log and text massage collection, but some users and journalists <a target=\"_blank\" href=\"https:\/\/newsroom.fb.com\/news\/2018\/03\/fact-check-your-call-and-sms-history\/\" >said<\/a> it had not.<\/p>\n<p>It\u2019s Facebook\u2019s corporate stance that the documents released by Parliament \u201care presented in a way that is very misleading without additional context.\u201d The Intercept has asked both Facebook and Kwon personally about what context is missing here, if any, and will update with their response.<\/p>\n<p>__________________________________________________<\/p>\n<p><em>Related:<\/em><\/p>\n<ul>\n<li><em><a target=\"_blank\" href=\"https:\/\/theintercept.com\/2018\/11\/16\/chuck-schumer-caved-to-facebook-and-donald-trump-he-shouldnt-lead-senate-democrats\/\" ><strong>Chuck Schumer Caved to Facebook and Donald Trump. He Shouldn\u2019t Lead Senate Democrats.<\/strong><\/a><\/em><\/li>\n<li><em><a target=\"_blank\" href=\"https:\/\/theintercept.com\/2018\/11\/02\/facebook-ads-white-supremacy-pittsburgh-shooting\/\" ><strong>Facebook Allowed Advertisers to Target Users Interested in \u201cWhite Genocide\u201d \u2014 Even in Wake of Pittsburgh Massacre<\/strong><\/a><\/em><\/li>\n<li><em><a target=\"_blank\" href=\"https:\/\/theintercept.com\/2018\/11\/29\/google-china-censored-search\/\" ><strong>Google Shut Out Privacy and Security Teams From Secret China Project<\/strong><\/a><\/em><\/li>\n<li><em><a target=\"_blank\" href=\"https:\/\/theintercept.com\/2018\/11\/27\/hundreds-of-google-employees-tell-bosses-to-cancel-censored-search-amid-worldwide-protests\/\" ><strong>Hundreds of Google Employees Tell Bosses to Cancel Censored Search Amid Worldwide Protests<\/strong><\/a><\/em><\/li>\n<\/ul>\n<p style=\"padding-left: 30px;\"><a href=\"https:\/\/www.transcend.org\/tms\/wp-content\/uploads\/2017\/03\/sam-biddle-staff-e1492275425120.jpg\" ><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-89314\" src=\"https:\/\/www.transcend.org\/tms\/wp-content\/uploads\/2017\/03\/sam-biddle-staff-e1492275425120.jpg\" alt=\"\" width=\"100\" height=\"100\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 30px;\"><em><a target=\"_blank\" href=\"https:\/\/theintercept.com\/staff\/sambiddle\/\" >Sam Biddle<\/a> &#8211; <a href=\"mailto:sam.biddle@theintercept.com\">sam.biddle@\u200btheintercept.com<\/a> <\/em><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><a target=\"_blank\" href=\"https:\/\/theintercept.com\/2018\/12\/05\/facebook-privacy-android-app\/\" >Go to Original \u2013 theintercept.com<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>6 Dec 2018 &#8211; In a chat seized by U.K. authorities, privacy officer Yul Kwon discussed how Facebook planned to circumvent an Android privacy dialog.<\/p>\n","protected":false},"author":4,"featured_media":123702,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[62],"tags":[],"class_list":["post-123701","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-media"],"_links":{"self":[{"href":"https:\/\/www.transcend.org\/tms\/wp-json\/wp\/v2\/posts\/123701","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.transcend.org\/tms\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.transcend.org\/tms\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.transcend.org\/tms\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.transcend.org\/tms\/wp-json\/wp\/v2\/comments?post=123701"}],"version-history":[{"count":0,"href":"https:\/\/www.transcend.org\/tms\/wp-json\/wp\/v2\/posts\/123701\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.transcend.org\/tms\/wp-json\/wp\/v2\/media\/123702"}],"wp:attachment":[{"href":"https:\/\/www.transcend.org\/tms\/wp-json\/wp\/v2\/media?parent=123701"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.transcend.org\/tms\/wp-json\/wp\/v2\/categories?post=123701"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.transcend.org\/tms\/wp-json\/wp\/v2\/tags?post=123701"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}