Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There is a legitimate question here -- do you own the information about your friends, or do your friends? Many things on Facebook are a shared quasi-public, quasi-private space where the ownership isn't clear, and don't fit into our usual mental model of "I own my own data!"

This example is even clearer. The app lets you export your friends' names and contact information. This isn't your information, it's your friends'. What if one of them wanted to take their phone number off the site? What if one of them wanted to hide their information from you specifically? If you've downloaded it already you're depriving them of the right to control their own data.

Clearly social networks should be required to offer some sort of friend list information for export. Maybe a bare list of user ID's is all that should be required -- the information about who your friends are seems legitimately like it's yours. Joining it against names and contact information is the potentially privacy-invasive step; that could be done online, under control of your friends, not you.



> What if one of them wanted to take their phone number off the site? What if one of them wanted to hide their information from you specifically? If you've downloaded it already you're depriving them of the right to control their own data.

Consider how ridiculous that would sound if you asked "What if one of your friends had emailed you their phone number and wanted to remove your access to it (or had emailed you and wanted to remove your knowledge of their email address)? What if they gave you information in person and now want to hide it from you specifically?"

That's the mental model I, personally, use for social networks: any information you choose to publish on it is fair game for whatever your friends want to do with it (and they can do whatever they want with any information I publish on it). Anyone who does not want to be contacted (or have their contact information exported into other formats - such as the linking of name and email address which is required to email) should not make it available - there's no reason to publish an email if you don't want to be emailed, and no reason to publish a phone number if you don't want to be called.


> Consider how ridiculous that would sound if you asked "What if one of your friends had emailed you their phone number and wanted to remove your access to it (or had emailed you and wanted to remove your knowledge of their email address)?

That would be a fine system -- where phone numbers and other means of contact can become invalidated if the owner wants them to.


You never tell your friends secrets in real life, and trust them not to tell the rest of the world?


If they do, I'll be pissed at them, not at the technology they use to share my secrets.


But you don't have a problem with them sharing your information with anyone as long as it's a technology provider? Even if that technology provider has a fundamental interest in abusing that access and using your data for purposes far beyond than what you or your friend ever intended?


You are choosing to share the information with them. They can view your profile and see it and type it wherever else they want, the only thing that preventing automatic export achieves is making it inconvenient for someone to leave facebook, not prevent someone from taking any conceivable action they wanted with your information.


That is unrelated to an issue that essentially amounts to adding your friends' phone numbers (phone numbers they already made available to you) to your new address book when you get a new phone.


> That is unrelated

Not if Google subsequently decide to make your information available more widely than it was originally, it's not -- and I would remind you that several of the Internet giants, including both Google and Facebook, have faced heavy criticism for deliberately doing exactly that in the not-so-distant past.


If I may go back a few years...

If my number is listed in the 1995 local big yellow phonebook but then I choose to have it unlisted in the 1996 phonebook, is it wrong for someone with the older phonebook to have my phone number?


No, but it is wrong for them to start plugging that number into some database of telesales people they feel like working with.

(Edit: To those downvoting, do you not like the analogy, or do you not agree with the ethical principle?)


I believe sorbus's comment covers it: http://news.ycombinator.com/item?id=2730277


I don't really see why. The world is not black and white. I tell my friends things that are sensitive all the time, and they understand that as a matter of simple good manners and common courtesy they would keep that information between us. How come as soon as we're on the Internet, suddenly all the shades of gray disappear, and I either trust someone with my entire life story to do with as they wish or I don't trust them at all?


You are confusing trust with the right to have an address book. if you give me your phone number I can save that number in my Verizon cell phone, then when I switch to ATT I can move the number to my ATT cell phone. That IS a black and white issue.

Because I demand the right to move phone numbers to my new phone, does not mean that I demand the right to sell your phone number to telemarketers or send your phone number to sex offenders. Doing things like that would make me a shitty friend. And being a shitty friend is totally unrelated to what websites/phones I store contact information on


> You are confusing trust with the right to have an address book.

And most of the people in this discussion are confusing the right to have an address book (which you control and to which only you have access) with giving someone else's personal data to Google (a global giant that would squish you like a bug if it meant a 0.001% increase in its data mining efficiency, with absolutely no loyalty to either you or the person whose data you are providing to it). Is that clear enough?


So google is going to sell me out? But facebook isn't? What about Verizon? How do you know what companies to trust with private information?


That's not the point. Your friend made a decision to share their private data with you using Facebook, knowing that it was Facebook that would be holding the sensitive data. You are talking about sharing that data with other organisations, which your friend has no control over. The point isn't whether or not you trust those organisations, it's whether it's abusing the privilege of having access to your friend's data to spread that data around where they don't control it any more. I think doing so is, at best, a betrayal of confidence.

(Edit: And in answer to your other question, about which organisations I personally can trust, we have fairly strict laws in my country about privacy and data protection, which limit what any of these companies may legally do and give me various rights with regard to any personally identifiable data anyone holds about me. I don't think those laws go far enough, but IMHO they're certainly better than the free-for-all you seem to want. So I can have some confidence in how my data will be handled by any company operating in our jurisdiction, which immediately makes me more likely to trust them than US-based companies like Facebook and Google whose business models fundamentally rely on undermining privacy in ways that are rarely going to be in the interests of the exposed.)


My friend has shared their contact information on Facebook, I decide to contact them using my iPhone, and save their contact information. That now gets sync'ed from my phone to my Mac, which is sync'ed with Google because I use gmail for my main email account and I like to have all of my contact information also available from within gmail and more importantly google voice so that I know when people send me text messages and when they call me.

If my friends have trusted me with their information they also trust me to make sure to keep it safe. What service I use to store my data should not be of any consequence for them. That is the same way with this Facebook exporter (BTW, the iPhone app allows one to sync contacts from Facebook to the iPhone address book, which can then get sync'ed to .Mac, Me, or the new iCloud, from there back to a Mac and then back up to Google), it allows the user to get the data from Facebook and store it in their address book. Instead of having to go through each entry one by one this plugin automates the process.

I don't see how my friends that clearly have made this data available to me (so I could contact them) should now have a say as to how and where I store said data. Just because I decide to store it in my address book on Google doesn't make much if a difference, if they didn't want me to have that data in the first place they should have A. never have given it to me, or B. ask me to please remove their information.


I'm giving up on this thread now. The endless downvotes instead of replies and people missing the point are just disheartening.

One more time, for the record: Your friend trusted you with their personal data, not Google. You may not personally have a problem with sharing your own personal data with Google, but not everyone is like you, and some people do. That doesn't mean they have a problem with sharing the data with you in the first place or that it was somehow unreasonable of them to give it to you.

I really can't understand why so few people in this discussion seem to understand the distinction. We have multiple Acts of Parliament on the subject here in the UK and an entire government department whose primary responsibility is enforcing the rules, so I'm clearly not the only one who gets it or thinks it's important. Maybe it's a cultural/generational thing, and the average person on HN just sees the world differently or something. Then again, the average person on HN today downvotes rather than replying if they disagree, based on my experience in this discussion and what's happened to several other people in other discussions I've been following, so things have obviously gone way downhill.


You really expect every one of your contacts to let you know before the buy an Android cell phone, or sign up for gmail or call you on google voice? What if one of your contacts doesn't trust ANY company other than Google? Using your logic, you shouldn't contact them on anything other than Google services.


Unfortunately I am unable to remember any and all of my friends contact information. I store it somewhere for easy retrieval when I need it.


Your phone number and email address were never meant to be secret. That only provides security by obscurity and leads to exactly this problem - you, a user, being upset when the security you were led to expect doesn't align with reality.

If you wish to not receive certain communications the way to do this is by screening incoming connections/contents. This works, unlike secrets.

Now, understanding that what you wanted to do (keep an email address secret) is a bad idea - it won't do what you want, you can see why those who understand don't care about this "privacy" - it isn't.

Claiming to authorize your email address being shared with CompanyX but not CompanyY is like saying "Here's my phone number, I'm only lettingVerizon subscribers know it, to keep AT&T from snooping on which of their users calls me." It's just nonsensical.


When you tell your friends, the information loss over distance and time eventually makes the words turn to shades of grey.

The internet preserves those words in their original state, black and white, which makes them stick out against the shades of grey composing the background.

Even simpler...when your friends die, with them go the words you have shared. Not so with the internet. It appears to be immortal.


I don't think that's really a legitimate question.

If you tell a friend e.g. your email address, you willingly give up the control you had over that piece of information, and accept that he now knows your email address. What you're expecting is that you can control when your friend forgets the information you voluntarily gave him. I doubt that's a legitimate expectation.


Why did Facebook import e-mails over years and still hold them in their databases? There is no way to remove them and when someone with this address enters Facebook he gets recommendations for Friends.

Do they own this data?

Think about this before you blame people who just try to find a way to reconnect with their friends (who are ok with being your friend on FB) on another Platform.


> If you've downloaded it already you're depriving them of the right to control their own data.

If you don't forget them between meetings you're trampling their right to a fresh impression.

If you remember that tune you're infringing on the RIAA's right to sell you another impression.

But that's not how information works.

If we pander to this mindset we're only letting them down when their illusion of control is shattered by the cold, hard, reality of cut-and-paste.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: