That's confusing. Is Palantir regarded as better or worse than Google?
Your role in your job there could cross the line of what some people would as ethical to some people, and Facebook's malicious behavior is making employees who work there to be viewed in a similar light.
This case is a small but clear oversight, one team (Security) set-up a necessary 2FA option; another (Growth) re-using information attached to a profile without context. Both teams have clear objectives but should have clearer lines when edge-cases like these appear. Two remarks on that: 1. clarity in large organisation and 2. prioritisation.
1. Overall, Facebook teams need clearer demarkation but every company in the world has far, far worst practice so as soon as you try to interview, you reek in horror at practices anywhere else — and that’s what they are willing to tell you before you join.
The internal discussion is probably split between many debates; I’ve never been very good at expecting issues around security, but probably a dozen philosophical questions like:
- phone numbers and SMS are not safe from MITM attack, the company should not accept them at all; vs. other options like a device are too selective, demanding, etc. so if people are happy and their threat model doesn’t include MITM SMSs, the company should offer that as an option;
- this is the only piece of information that is “User only” and that visibility option was removed because it used to lead to abuses; vs. we can monitor abusive use of a visibility feature even if that’s extra work, more technical plumbing that could lead to more internal abuse;
- there are no identified threat actually unblocked if there were, our bug bounty would have caught them; vs. we do not have to limit Security to known threats, but “feels” for bad practices should be trusted as a sign there is a threat in there that the company should respect even if we can’t isolate why.
Knowing what to do as an individual contributor when you have gods fighting over your head can be daunting; you want to have a clearer picture that, say “Only me” will be a visibility option for longer and not replaced by “Hide that from anyone, even having access to the account to prevent an access even from escalating into a worse security threat” or that when it’s replaced, this piece of information won’t be missed or excluded.
Anyone who has build large data schemas would be familiar with how tricky changes like that can be when done without coordination. Anyone who follows visibility of information from Facebook has noticed a lack of clear purpose: more nuanced options appear and disappear because there’s a tension between simplification and curating interests.
2. Overall, working for Facebook feels like you are dealing with a fire, an earthquake, a zombie invasion, a revolution and a flood at the same time — and the public only seems to care about electricity shortages. And when you look into internal numbers about who cares about any of the above, the flood seems like a big deal, no one cares about electricity but someone you know that the fire and the zombie invasion are far worst. Facebook is the only place where managers are very clear that the fire will destroy your water pump much faster than the water goes up, and zombies are actually quite slow — and you can not prevent earthquakes, only deal with the aftermaths, so they want you to deal with them in a specific order: #1 Extinguish Fire, #2 Automate the water pumping for the Flood, into the fire-prevention stock, #3 Delegate the dyke-building, #4 Once you have a plan for that, expand dykes to protect from zombies, #5 Schedule a town-hall for after the physical security of everyone is guaranteed because talk is better than a revolution, #6 Imagine what seismographs could be like (network?) and how they could prevent bad things, given how fast earthquakes are. Nothing about electricity because it escapes everyone’s mind at this point.
I once had a task that was about preventing thousands of crimes from happening; it was #3 on my list. That felt wrong, but my manager explained how, if #1 and #2 were not done, I couldn’t do #3. It felt very strange. #2, in particular, was very debatable: I reached out to a friend of mine, a lawyer outside the company and probably one of the top 10 people on deciding if something like #2 was ethical. My friend told me that he had far bigger issues to deal with. So I did #2 reluctantly; I did it first because it made #1 easier. In the mean time, #1 was cancelled without my manager telling me. I had asked someone else to do #3 and he got a massive promotion.
Two years later, the press was up in arms because thinking about #7 was presumably unethical. #7 is about making sure that vulnerable users were even more protected than they were on Facebook (while no other platform did anything for them) and the press really objected to vulnerable users being on Facebook at all. The most widely circulated OpEd on the topic explicitly didn’t care for them being protected: that they were on Facebook at all was the problem. As a former employee, I knew why they really needed to be there: it is their only source of needed social life.
My experience was a little extreme, but it’s quite representative.
Take the recent appeal to have more community monitoring:
- Facebook notices, years before anyone, external agents using social media to spread inflammatory messages; they understand that they won’t be able to prevent the gutter-press from spreading it, so they appeal to institutions because they carry editorial authority and local understanding that Facebook can’t have.
- That is dismissed as interference, and Facebook is mocked for knowing nothing about the free press. As a reaction, Facebook publishes articles on polarisation and clearly point at external sources; they asks researchers to measure how much the News Feed bridges that gap and helps moderate the worst messages. The article is summarised clearly with graphs by internal comms. The article is summarised in the press as: Facebook is pouring gas on the political fire.
- Facebook anticipates that astroturfing will get worst, at an exponential rate, and decides to enforce strict “authentic identity” rules to cut most of it; also starts efforts in identifying “fake news”. Explicitly connects the efforts to political manipulation. Both efforts are openly disparaged by people who spread false information and openly ignore that Facebook has a clear handling process for people who don’t want to be found for legitimate reasons. Political parties gladly finance negative attack ads that are the main source of inauthentic, false coverage.
- Facebook gets signal that human censoring is not scaling; details become increasingly worrying. Facebook ramps up their AI research program to identify increasingly relative inauthentic users, messages; the program is ignored, or only presented as an Orwellian effort by “the Borg”. Mentions of issues in human reporting are completely overlooked by the press.
- Facebook realise that scaling its community enforcement won’t work because they don’t know how to manage those and the third-party company are treating them like lab rats at best. Asks for improvement on work conditions; nothing, or rather systematic executive-level Me-Too scandals. Facebook fires said companies out of desperation. Instant backlash because ‘Facebook fired journalists’. Facepalm, partial decision reversal. Silence from the press, which honestly is a relief at this point.
- Major progress on the front of automated community enforcement. Facebook is the first to identify several threats to democracy (Cambridge Analytica is banned in 2014; everyone finds Trump funny when he asked for Russia’s help, while Facebook Security reveals to the FBI suspicious behaviour). Unsurprisingly, Facebook is blamed for acting as a Good Samaritan; internal debate on whether to come clean publicly, or only tell law enforcement. Law enforcement is clearly dependent on electoral results, so coming clean publicly proves important… but extremely costly for the company brand. Should the company sacrifice the little goodwill it has left among the press now, to prevent current threats, or keep it for a worse crisis?
- No surprise: political parties don’t like being targetted as being bad actors and defend themselves by empowering lunatics and doubling down on a constant barrage of incendiary news. Community enforcement is completely overwhelmed by its own scale and size and catastrophic situations emerges. No one raises that Facebook has offered several solutions, from institutional standards, automated detection, visibility control and just blames the company for its subsidiaries. The company is just the enemy of everyone at this point. Facebook has two options: not having any community enforcement, or trusting suppliers that have repeatedly lied to them. The third one is what many employees are working on: automation.
Your question is: why wouldn’t they leave? Answer: many do. Drama is hurtful no matter how you understand the whole story. Whether those who stay are more confident, or less reliable in their ethical stand is debatable.
If you care more for technical problems, I’m happy to explain why facebook.com/ads/preferences is the best implementation at the moment of user-control over dark data brokers. It’s insufficient, but helping people identify threats and we can implement reporting from there that no other company will let you have, not without the transparency of Facebook.
To summarize:
1) "As long as there's someone worse we don't have to worry"
2) "working for Facebook feels like you are dealing with making profit, pleasing management, pleasing partners, progressing your career and going home early at the same time — and the public only seems to care about privacy violations."
I’m also not saying that large or influential companies should not be held to higher standards; they absolutely should, and they are where I come from. I’m simply saying that, if you consider problems where Facebook made a bad decision (a minority of the scandals) those issues trickle down to two systemic problems: clear, non-contradictory internal guidelines and prioritisation. Facebook employees are trained to recognise both. When they consider other options, they would often see companies where both are significantly worse. Other companies have simply not been through a decade of excruciating oversight by the international press. Those who have are not managed by someone who is nearly as willing to admit his fault as Mark.
I doesn’t mean that those companies are not better options for ex-Facebooker: they often are; or that they would not make the world a better place by joining those, and advocating for higher standards: they often would. Those companies typically should be held to a lesser standard because they have less of an overall impact. But, as an employee, if you want to prevent problems like those that you regret being a witness to at Facebook, leaving is hard because you can easily see the rest of the world as worst more often than not. If you come with your expectation, gained from working at Facebook, that any minor issue will be twisted into a scandal, most other companies feel very wrong.
You can see that by looking at how many people are above ex-Facebookers at the companies that they join: it’s unusually few. That’s because they rarely trust too many layers to make the right call.
Happy to give more examples, or to argue that the most visible and debated issues are not the most relevant. Even happy to say that this is a problem, but I don’t see it as an internal problem.
However, I wonder if you'd agree that maybe the main reason for Facebook problems is their desire to overconnect the social graph basically. All those moderation problems wouldn't be there if the newsfeed stayed simple chronological summary of updates by their friends and families instead of an algorithmically generated mess. Reddit AFAIK doesn't have problems as huge as Facebook's, and the reason for that is that communities tend to moderate themselves pretty well, and moderating communities themselves (e.g. banning drug sale groups) scales way, way better. In a sense FB itself kinda acknowledges that with its recent emphasis on Groups.
On the other hand, interpersonal connections between real-life friends and families (what Facebook sold to its audience and the way it keeps the users on the platform) barely need any moderation at all. It's quite unlikely your uncle James starts promoting antivax (or child suicide) in your family, and even if he does, he can either be contested (not letting spiral of silence to form) or banned/muted/unfriended/etc. Unfortunately, it's not how FB works: it baits you with friends and family and switches to engagement optimised cesspool.
It feels like the hyperconnected, algo-driven feed is actually the root of most facebook troubles, despite (obviously) generating massive revenues.
Yes, because Facebook would not be a usable service. This is not a joke: raw feed is really bad. Unusable. Spam-folder on steroids bad. If you care about the Facebook employees mindset: “My News Feed should be chronological” is about three times worse than “I’m just looking for a technical co-founder, I’m an ideas guy” to the HN crowd.
> Reddit AFAIK doesn't have problems as huge as Facebook's, and the reason for that is that communities tend to moderate themselves pretty well,
Reddit has significant efforts into massaging their own feeds. It’s less visible, but quite significant, mainly around abuses from large coordinated groups. They’ve talked about it extensively. They have fewer issues because a subreddit community has clear values (_News_ value immediacy; _Politics_ controversy; _WritingPrompt_ values long comments more than total Upvotes) which allows them to tailor their algorithm per context rather than per person. Well, they do that too, but it’s significantly messier. This part is hidden because there’s a lot more than you can see on Reddit, so you see a lot of good things, no matter the order. There is less good content from your friends simply because you don’t have a million of them, so your Facebook News Feed is a lot more sensitive to clues. Reddit also has a lot more input information with upvotes; people really don’t understand their feed would become massively better if they click on Like — including professionals who build recommendation engines for a living and complain about not having good data.
Finally, if you think that Reddit is a welcoming community without issues, I can easily guess your gender. That’s a big part of what Facebook empowers.
> interpersonal connections between real-life friends and families (what Facebook sold to its audience and the way it keeps the users on the platform) barely need any moderation at all
This is not true: anti-vaxxers (and before them, MLM) are a massive hindrance to their family; usually, they get ignored now, but being able to hide them (and dynamically detect problematic posts from important, non-MLM updates) is a key feature of the News Feed. The most common, and occasionally biggest pain-points that we’ve measured have been where friends and family merged, from your lame dad barging in a Let’s-go-to-the-club thread to gay people still in the closet liking posts about flamboyant things.
What you might be trying to say is that there is a real problem in merging all your aspects of life into one context. That’s definitely true. Without going into drama-prone topics, I speak several languages and that was not taken into account at all when I joined; my cousin routinely complained that she didn’t understand why I wrote in English “all the time”. There was some progress (thanks in very small part to my impulse) there.
Raising consciousness around those issues was part of what I did more generally. One effective and clear solution for that was Groups, that finally, for the last two years, got their place in the sun with a dedicated, empathic team in _Engagement_, rather than be a subsidiary of Pages that where a subsidiary of Ads. I don’t have internal knowledge but from public communications from Facebook management, I’m guessing they are growing much faster than Reddit, with a similar product.
> generating massive revenues.
Not really. The family stuff is great because if gets people to post more: they feel like they can share if they see similar things in their feed. That’s empowering people which Facebook believes in as a core value, but it’s not making much money. If Facebook wanted to print dollars, they’d go full Video.
The money comes from basic stuff: age, gender, location, family status (age of children) and interests; language, too: you’d be shocked to see how many ads are shown to people who just can’t read them. The money comes for “Custom audience” which is essentially Upload the emails of your users, and we’ll find them on Facebook, and “Similar audience” which is an augmentation of that, and let you advertise to those groups separately. That you love sharing lame puns with your uncle, or photos playing with your nephews isn’t going to attract anyone’s crazy CPA. If you click on ads about nappies, that‘s a really good signal though.
Honestly, Facebook is eating other people’s lunch in ads because they get very basic things right: separate your customers from non-customers. They don’t advertise for diamond rings next to an article about the war in Congo, like the NYTimes does, or for stilettos to burly football players. They remember which ads work for you, and show more of that. In my case, I’m in the market for a nice leather bag: Facebook knows that and shows me a lot of that. They are certainly making more than the average $50 by helping me general a list of a dozen nice options for my birthday.
Marketing (outside, possibly of political advertising) hasn’t really moved to crazy Orwellian stuff at scale. If, one day, posting landscape in black-and-white is correlated to you liking yogurt, maybe… but for now, it’s probably easier to ask your local supermarket.
This seems critically relevant to the issue at hand - can you explain it in a little more detail please?
When I was working there, I’ve worked on custom visibility option (things like lists of friends, a feature that hardly anyone used; home city, languages had been occasional “Smart lists”). Those options were unsupported or become discontinued in some cases. There was a significant mental load to have more visibility options than ‘Friends‘ and ‘Public’, and very few reasons (as in: active users) to support more. One option that I felt really corresponded to a lot of people’s need was “Friends except Acquaintances”: ‘Acquaintances’ had become a really good shorthand for “drama-prone” relations. Yes, you are friends with them, they can see some activity from you, just not everything. They have no reason to think you’ve excluded them. It was discontinued and I never figured out why.
I can imagine the “Only me” option being changed because of someone, either working on an easier audience selector or trying to make bad-behaviour-detection faster, might overlook the need to have some information on the site not shared with your friends. The impact of visibility option on every aspect of the site is nightmarishly complicated, and genuinely hard to keep in mind to think about clearly. I’ve dedicated a decade to that, and I struggled. People who are officially very smart (Math Olympiad laureates, Mensa-type: not that those are proof of social smart, but they should understand formal reasoning really well) struggled. If you include blockages, it gets really hairy. If you include bad actor and impersonation, you will lose your sanity. The alternative that I suggested (that information is probably what hackers would look for, so hide it even from an authenticated user) is probably more likely, given the overall privacy-conscious of the company. In that case, that information changes status even more.
I’m not saying that kind of blatant or casual disregard for nuanced privacy control is not bad. God knows I raised hell before I joined the company and after about list support, and more. I even convinced a friend to join because he made a great tool to manage your list of friends. He joined the company before me, helped me a lot internally — but never even mentioned his tool to anyone internally because there was no appetite for it, inside or outside the company. Just to tell you how much: do you remember the fiasco that was Google Plus Circles? Well, after _that_ blew up, I had low expectations. This was lower.
The company moved to Groups, non-friends contextual entities, and that was I think a lot better in many ways.
- Facebook employees consider that Cambridge Analytica was caught, abused their power, lied under oath and was never able to leverage Facebook Custom Audience anyway; short of using Police forces (and Facebook really should not have that kind of power) there wasn’t much that Facebook could have done more;
- As a consequence of that, there was a movement to control abusive pages in politics, and everyone was claiming for a clamp-down. It took 24 hours for Facebook to ask for ID for the moderators of all large political pages, because they realised that any of those could be GRU operatives, and 5 minutes for everyone to find this deeply objectionable. :facepalm:
- Apps sending their user’s actions to Facebook Analytics when those actions are Heartbeats, blood pressure, migraine and Period time: Facebook employees consider that Analytics is a service for people to target their own users based on their own classification. There are some possible issues with it (the classic being ethnic discrimination for real estate) but no one at Facebook cares about your period. Facebook could enforce more strongly that the apps communicate with their users about the Analytics tool, but that’s 100% going to blow back around the common theme that Facebook is abusing their power. You’ll have virulent op-ed outraged at how their dare to threaten to de-platform feminist apps about empowering women and their health, and how dare they. I’m happy to bet real money that the people asking for more control will be the same to protest against it, less than a week later.
_Catch-22_ comes to mind.