Audit Approved of Facebook Policies, Even After Cambridge Analytica Leak (nytimes.com)
Nicholas Confessore reports via The New York Times: An auditing firm responsible for monitoring Facebook for federal regulators told them last year that the company had sufficient privacy protections in place, even after the social media giant lost control of a huge trove of user data that was improperly obtained by the political consulting firm Cambridge Analytica. The assertion, by PwC, came in a report submitted to the Federal Trade Commission in early 2017. The report, a redacted copy of which is available on the commission's website, is one of several periodic reviews of Facebook's compliance with a 2011 federal consent decree, which required Facebook to take wide-ranging steps to prevent the abuse of users' information and to inform them how it was being shared with other companies. The accounting firm, formerly known as PricewaterhouseCoopers, effectively gave Facebook a clean bill of health. "Facebook's privacy controls were operating with sufficient effectiveness to provide reasonable assurance to protect the privacy" of users, said the assessment, which stretched from February 2015 to February 2017. But during that period, Facebook was aware that a researcher based in Britain, Aleksandr Kogan, had provided Cambridge Analytica with private Facebook data from millions of users.
The Cambridge Analytica leak was the result of technical incompetence, and poor code review, not bad policy at the level an auditor would see. It is not reasonable to expect a financial auditor to discover bad code.
You can't. I have no Facebook account, but it will have my data anyway from anyone who has ever put me in their contacts. I have no idea if I've been 'tagged' in photos and due to the closed nature I can't search to find out.
They do have a page to see what data they hold on you if you don't have an account, but to use it of course you need to....send them your data so they can check for matches. Catch 22.
Problems: 1) auditors are paid by the auditees, 2) they do their job, what they were asked for, and not more. Why do you think these audit / consultancy firms are that expensive? An audit, done to reveal the kind of recent leaks, would only truly work if done by a public institution.
Slashdot, fix the reply notifications... You won't get away with it...
Funny that as a matter of public policy they approved of the Democrats doing it years earlier.
"His name was James Damore."
The Cambridge Analytica leak shows us that Facebook has surprisingly no clue or hold on their assets. If user data is the product, that product is freely harvested by third parties outside the control of Facebook.
The article and post play into the usual misunderstandings of what a true external audit is. A auditor NEVER gives a clean bill of health to ANYONE.
It would be the equivalent of saying "My 14 year old daughter is incapable of lying!" Or to hit closer to this group "This networked system is totally secure for the next 10 years!" No, those are stupid! Any competent IT guy would say "This system has all the latest patches and best industry practices to remain secure." They would check a few patches and see if they were applied quickly enough to come to that conclusion.
An auditor collects enough information from a client for an owner of the firm to provide a SECONDARY agreeing or decenting OPINION of the company's financial or security or operational position. The company can say "We are going bankrupt." and the auditor will say "I think they are right!"
operating with sufficient effectiveness to provide reasonable assurance
The key words that you will find in almost all audit work is "sufficient effectiveness" and "reasonable assurance". Which is complete true in this situation. Facebook doesn't have policies that give your data out to anyone. They don't violate their policies by doing such. A partner did really go above and beyond what they should have. Facebook failed to regulate such partner but may have had reasonable measures to prevent abuse.
Also, keep in mind that auditors are not here to catch the client in lies, nor catch collusion between people (reportee buys a car, mgr approves, they sell & split profits).
Basically the article is "Auditors did their job but it wasn't enough to prevent this."
Truth be told, CA was likely Facebook giving one customer everything they give all of their customers. The Clinton campaign probably hired at least 4 equivalents to CA themselves, and there's probably dozens, if not hundreds more, using that same kind of data for non-political purposes..
This is my signature. There are many like it, but this one is mine.
This is the same PWC that theoretically audited AIG before they went belly up with the financial crash. They also "audited" JPMC and then was fined for basically not doing their job. Seriously, PWC is who you hire when you want to report results without actually doing an audit. https://en.wikipedia.org/wiki/...
Those of us old enough remember the Arthur Andersen debacle only too well. The modus operandi is always the same: the companies carrying out the audit, usually requested by the companies being audited, simply do like the proverbial $25 whore.
It didn't audit as a "leak" because it WASN'T A LEAK?
This was the facebook API working essentially as intended. To a malign purpose (ie helping Trump) and to a degree in excess of what the researcher was expected to pull, but this was in no sense someone 'hacking' fb's systems to get information that wasn't intended to be collected somehow.
-Styopa