Tuesday, 2 October 2018

A Blog Isn’t a Blog, It’s a Business

I wrote my very first blog post on July 24, 2005. That blog post is no longer live because it was terrible.

The post was called, “Winning the Search Engine Marketing War.”

It was 412 words long, contained no images, no external links, and it didn’t provide much value because it didn’t teach you anything.

But you know what, back in 2005, the blog post was pretty darn good.

See, I wasn’t competing with a lot of blogs back then. Currently, there are well over 440 million blogs and back in 2011, that number was 173 million. And in 2005, the web was still so small that there were only 64 million websites (with only a small portion of them being blogs).

In other words, my first blog post was pretty darn good because something is better than nothing. People were just happy to get some information, even though it wasn’t great.

But over the years, blogging has changed. What it used to be in 2005, isn’t what it is today.

What blogging used to be

A blog used to just be a blog.

It was a place where you would share your personal experiences with the world. From photos of the places you traveled to and blogging about the food you ate to even sharing personal information about your family life…

In 2005, social networks weren’t popular. Facebook launched in 2004, but it wasn’t what it is now. And sites like MySpace focused heavily on music.

As social networks evolved, people realized it was easier to share personal stories on Facebook and Instagram than it was to write a whole blog post.

instagram stories

Over 250 million people share what they are doing in their personal life each day just on Instagram. All you have to do is talk (or look) into your phone for just a few seconds. It’s really that simple.

And that’s why more of you use social networks on a daily basis than a blog.

Just think of it this way… if you wanted to update your friends on your life, is it easier for you to just upload some pictures to Facebook or is it easier for you to write a blog post?

Of course, it’s easier to just upload some photos to Facebook. It’s why Facebook is so popular.

For that reason, people started to focus their attention on Instagram, Facebook, Twitter, LinkedIn, and Snapchat over blogging.

So why do people continually create more blogs?

There are many reasons why blogs have grown in popularity. As I mentioned above, there are well over 400 million blogs today.

The biggest reason why blogs have grown in popularity is that you are an end user and continue consuming the content that blogs put out.

Just in the United States alone, 42.23% of people from the ages of 18 to 49 read blogs.

united states reads

And because people want to read blogs, Google has no choice but to rank them. The average page that is listed on page one of Google has 1,890 words:

word count

There are many reasons you may want to create a blog, but from someone who blogs on a weekly basis and has been for 13 years, here are the main reasons to have a blog:

  1. You control your own destiny – social networks have restricted how many of your friends actually see your content. With a blog, you have more control over your destiny. You can collect emails to get people back to your site, you can build a push notification subscriber list, you can rank your content on Google… overall, it’s just easier to get a consistent stream of traffic from a blog than it is from a social profile because you aren’t relying on 1 traffic source. This is more important than ever because the top referring sites on the web are starting to send less traffic out to other sites.
  2. Paid ads are expensive – Google generate 6 billion dollars in ad revenue in 2005 and that number shot up to 95 billion in 2017. With ad costs continually rising, you have no choice as a business but to find other traffic channels. A blog is an obvious question as Google loves ranking text-based content. Just look at Wikipedia, they rank for everything and generate 5.4 billion visits a month.
  3. Marketing has moved to an omnichannel approach – there are currently 1,766,926,408 websites on the web. In 2005 that number was only 64,780,617. That’s a 2,627% increase. That means you as a business have more competition online, which gives consumers more choices. Why should someone choose you over the competition? Well, branding plays a huge part, if you can get a consumer to see or hear about your brand 7 times they are much more likely to be a customer. A blog creates another additional touchpoint.

A blog isn’t a blog, it’s a business

As more sites have come online, SEO has become more competitive. Yes, more people are using Google, but they are searching for the same popular terms.

With Ubersuggest, we have a database of 646,777,704 keywords.

word database

And out of those keywords, only 15,301,405 keywords generate a search volume of an excess of 10,000 searches per month.

As more people come online, it doesn’t mean that they search for brand new keywords. It just means that the popular terms get even more popular.

That’s why it is harder to get people to come to your site over the competition because you are competing with more companies to get those eyeballs.

See, as SEO has become more competitive, you have no choice but to treat it as a business. It takes time and money to produce content. It takes time and money to promote your content. And then once you have those visitors, it takes more time and money to convert those visitors into paying customers.

In other words, because it is so competitive, you won’t do that well unless you put in tons of time or money (or ideally both).

Just look at Quick Sprout, the marketing blog I don’t put much money into it. Even though it’s older than NeilPatel.com, it generates a lot less traffic.

quicksprouttraffic

NeilPatel.com blog generates 693% more traffic because I put over 6 figures into the blog each month (mainly in developing free tools and creating audio and video content), and I treat it like a business.

neil patel traffic

Conclusion

Look, I am not trying to persuade you into not building a blog. But I believe most companies should have a blog. And if you don’t have one, just follow this guide to get up and running.

A blog is the only way you are going to rank well on Google and generate traffic without directly paying for it by using Google AdWords or Facebook Ads.

But if you want to do well, you can’t treat your blog like a “blog”… you have to treat it like a business. If you don’t, then you won’t do well.

Here are the 3 important steps you need to take if you want to do well:

  1. Focus on writing amazing content consistently – it’s not about writing one or two amazing posts… you have to be consistently awesome. The market is so competitive, you can’t write 400-word blog posts as I did in 2005. Sure, if you are in a new niche with no competition, by all means, write 400-word posts, but the chances are you are going to eventually have some competition. And if you don’t have the time, you should just hire a writer to help you out.
  2. Promote your content – after you have content, you’ll have to promote it. Promotion isn’t easy but I’ve broken it down into 4 steps for you. Just follow them and you’ll do well.
  3. Focus on monetization last – most bloggers who get this far face one big problem… as their traffic increases their revenue typically stays flat. Just because you have more visitors, it doesn’t guarantee an increase in revenue. Towards the end of this blog post, I teach you how to convert those visitors into leads and customers. Follow them.
  4. Don’t forget about voice – I know I said you only have to follow 3 steps, but if you’ve followed all of them successfully, you’ll need to start thinking about voice. 40% of adults use voice search daily, so don’t take it for granted. Follow this guide to ensure that you capture the voice search market share before your competition.

What do you think about blogging? Are you going to start taking it seriously?

The post A Blog Isn’t a Blog, It’s a Business appeared first on Neil Patel.



source https://neilpatel.com/blog/a-blog-isnt-a-blog-its-a-business/

Twitter widens its view of bad actors to fight election fiddlers

Twitter has announced more changes to its rules to try to make it harder for people to use its platform to spread politically charged disinformation and thereby erode democratic processes.

In an update on its “elections integrity work” yesterday, the company flagged several new changes to the Twitter Rules which it said are intended to provide “clearer guidance” on behaviors it’s cracking down on.

In the problem area of “spam and fake accounts”, Twitter says it’s responding to feedback that, to date, it’s been too conservative in how it thinks about spammers on its platform, and only taking account of “common spam tactics like selling fake goods”. So it’s expanding its net to try to catch more types of “inauthentic activity” — by taking into account more factors when determining whether an account is fake.

As platform manipulation tactics continue to evolve, we are updating and expanding our rules to better reflect how we identify fake accounts, and what types of inauthentic activity violate our guidelines,” Twitter writes. “We now may remove fake accounts engaged in a variety of emergent, malicious behaviors.”

Some of the factors it says it will now also take into account when making a ‘spammer or not’ judgement are:

  •         Use of stock or stolen avatar photos
  •         Use of stolen or copied profile bios
  •         Use of intentionally misleading profile information, including profile location

Kremlin-backed online disinformation agents have been known to use stolen photos for avatars and also to claim accounts are US based, despite spambots being operated out of Russia. So it’s pretty clear why Twitter is cracking down on fake profiles pics and location claims.

Less clear: Why it took so long for Twitter’s spam detection systems to be able to take account of these suspicious signals. But, well, progress is still progress.

(Intentionally satirical ‘Twitter fakes’ (aka parody accounts) should not be caught in this net, as Twitter has had a longstanding policy of requiring parody and fan accounts to be directly labeled as such in their Twitter bios.)

Pulling the threads of spambots

In another major-sounding policy change, the company says it’s targeting what it dubs “attributed activity” — so that when/if it “reliably” identifies an entity behind a rule-breaking account it can apply the same penalty actions against any additional accounts associated with that entity, regardless of whether the accounts themselves were breaking its rules or not.

This is potentially a very important change, given that spambot operators often create accounts long before they make active malicious use of them, leaving these spammer-in-waiting accounts entirely dormant, or doing something totally innocuous, sometimes for years before they get deployed for an active spam or disinformation operation.

So if Twitter is able to link an active disinformation campaign with spambots lurking in waiting to carry out the next operation it could successfully disrupt the long term planning of election fiddlers. Which would be great news.

Albeit, the devil will be in the detail of how Twitter enforces this new policy — such as how high a bar it’s setting itself with the word “reliably”.

Obviously there’s a risk that, if defined too loosely, Twitter could shut innocent newbs off its platform by incorrectly connecting them to a previously identified bad actor. Which it clearly won’t want to do.

The hope is that behind the scenes Twitter has got better at spotting patterns of behavior it can reliably associate with spammers — and will thus be able to put this new policy to good use.

There’s certainly good external research being done in this area. For example, recent work by Duo Security has yielded an open source methodology for identifying account automation on Twitter.

The team also dug into botnet architectures — and were able to spot a cryptocurrency scam botnet which Twitter had previously been recommending other users follow. So, again hopefully, the company has been taking close note of such research, and better botnet analysis underpins this policy change.

There’s also more on this front: “We are expanding our enforcement approach to include accounts that deliberately mimic or are intended to replace accounts we have previously suspended for violating our rules,” Twitter also writes.

This additional element is also notable. It essentially means Twitter has given itself a policy allowing it to act against entire malicious ideologies — i.e. against groups of people trying to spread the same sort of disinformation, not just any a single identified bad actor connected to a number of accounts.

To use the example of the fake news peddler behind InfoWars, Alex Jones, who Twitter finally permanently banned last month, Twitter’s new policy suggests any attempts by followers of Jones to create ‘in the style of’ copycat InfoWars accounts on its platform, i.e. to try to indirectly return Jones’ disinformation to Twitter, would — or, well, could — face the same enforcement action it has already meted out to Jones’ own accounts.

Though Twitter does have a reputation for inconsistently applying its own policies. So it remains to be seen how it will, in fact, act.

And how enthusiastic it will be about slapping down disinformation ideologies — given its longstanding position as a free speech champion, and in the face of criticism that it is ‘censoring’ certain viewpoints.

Hacked materials

Another change being announced by Twitter now is a clampdown on the distribution of hacked materials via its platform.

Leaking hacked emails of political officials at key moments during an election cycle has been a key tactic for democracy fiddlers in recent years — such as the leak of emails sent by top officials in the Democratic National Committee during the 2016 US presidential election.

Or  the last minute email leak in France during the presidential election last year.

Twitter notes that its rules already prohibit the distribution of hacked material which contains “private information or trade secrets, or could put people in harm’s way” — but says it’s now expanding “the criteria for when we will take action on accounts which claim responsibility for a hack, which includes threats and public incentives to hack specific people and accounts”.

So it seems, generally, to be broadening its policy to cover a wider support ecosystem around election hackers — or hacking more generally.

Twitter’s platform does frequently host hackers — who use anonymous Twitter accounts to crow about their hacks and/or direct attack threats at other users…

Presumably Twitter will be shutting that kind of hacker activity down in future.

Though it’s unclear what the new policy might mean for a hacktivist group like Anonymous (which is very active on Twitter).

Twitter’s new policy might also have repercussions for Wikileaks — which was directly involved in the spreading of the DNC leaked emails, for example, yet nonetheless has not previously been penalized by Twitter. (And thus remains on its platform so far.)

One also wonders how Twitter might respond to a future tweet from, say, US president Trump encouraging the hacking of a political opponent….

Safe to say, this policy could get pretty murky and tricky for Twitter.

“Commentary about a hack or hacked materials, such as news articles discussing a hack, are generally not considered a violation of this policy,” it also writes, giving itself a bit of wiggle room on how it will apply (or not apply) the policy.

Daily spam decline

In the same blog post, Twitter gives an update on detection and enforcement actions related to its stated mission of improving “conversational health” and information integrity on its platform — including reiterating the action it took against Iran-based disinformation accounts in August.

It also notes that it removed ~50 accounts that had been misrepresenting themselves as members of various state Republican parties that same month and using Twitter to share “media regarding elections and political issues with misleading or incorrect party affiliation information”.

“We continue to partner closely with the RNC, DNC, and state election institutions to improve how we handle these issues,” it adds. 

On the automated detections front — where Twitter announced a fresh squeeze just three months ago — it reports that in the first half of September it challenged an average of 9.4 million accounts per week. (Though it does not specify how many of those challenges turned out to be bona fide spammers, or at least went unchallenged).

It also reports a continued decline in the average number of spam-related reports from users — down from an average of ~17,000 daily in May, to ~16,000 daily in September.

This summer it introduced a new registration process for developers requesting access to its APIs — intended to prevent the registration of what it describes as “spammy and low quality apps”.

Now it says it’s suspending, on average, ~30,000 applications per month as a result of efforts “to make it more difficult for these kinds of apps to operate in the first place”.

Elsewhere, Twitter also says it’s working on new proprietary systems to identify and remove “ban evaders at speed and scale”, as part of ongoing efforts to improve “proactive enforcements against common policy violations”.

In the blog, the company flags a number of product changes it has made this year too, including a recent change it announced two weeks ago which brings back the chronological timeline (via a setting users can toggle) — and which it now says it has rolled out.

“We recently updated the timeline personalization setting to allow people to select a strictly reverse-chronological experience, without recommended content and recaps. This ensures you have more control of how you experience what’s happening on our service,” it writes, saying this is also intended to help people “stay informed”.

Though, given that a chronological timeline remains not the default on Twitter, with algorithmically surfaced ‘interesting tweets’ instead being most actively pushed at users, it seems unlikely this change will have a major impact on mitigating any disinformation campaigns.

Those in the know (that they can change settings) being able to stay more informed is not how election fiddling will be defeated.

US midterm focus

Twitter also says it’s continuing to roll out new features to show more context around accounts — giving the example of the launch of election labels earlier this year, as a beta for candidates in the 2018 U.S. midterm elections. Though it’s clearly got lots of work to do on that front — given all the other elections continuously taking place in the rest of the world.

With an eye on the security of the US midterms as a first focus, Twitter says it will send election candidates a message prompt to ensure they have two-factor authentication enabled on their account to boost security.

“We are offering electoral institutions increased support via an elections-specific support portal, which is designed to ensure we receive and review critical feedback about emerging issues as quickly as possible. We will continue to expand this program ahead of the elections and will provide information about the feedback we receive in the near future,” it adds, again showing that its initial candidate support efforts are US-focused.

On the civic engagement front, Twitter says it is also actively encouraging US-based users to vote and to register to vote, as well as aiming to increase access to relevant voter registration info.

“As part of our civic engagement efforts, we are building conversation around the hashtag #BeAVoter with a custom emoji, sending U.S.-based users a prompt in their home timeline with information on how to register to vote, and drawing attention to these conversations and resources through the top US trend,” it writes. “This trend is being promoted by @TwitterGov, which will create even more access to voter registration information, including election reminders and an absentee ballot FAQ.”



source https://techcrunch.com/2018/10/02/twitter-widens-its-view-of-bad-actors-to-fight-election-fiddlers/

A Slice of MozCon Magic: The 2018 Video Bundle is HERE!

Posted by HayleyBowyer

Your tweets haven't gone unnoticed — we know the MozCon #FOMO is very real. Many of you would be there in a second if it weren’t for busy schedules and pesky back-to-back meetings. So, while you're hard at work, we’re here to make one thing easy: providing you with the insights you need whenever you need them.

Yes, that’s right — the MozCon 2018 Video Bundle is here and we can’t wait share it with you!

Ready to dive in? Feel free to skip straight to the fun part!

Buy the MozCon 2018 Video Bundle

Did you attend MozCon 2018? You’re in luck! The full video bundle is included with your ticket price. Check your inbox for an email with a link to exclusive video access. Can’t find it? Email us — we're happy to help!

If you weren’t able to make it, MozCon 2018 was awesome, to say the least. I’m not just saying that because I want to see you at MozCon 2019, but because, in just three short days, I witnessed magic happen.

No, not the kind you find at Disneyland (even though I firmly believe MozCon is Disneyland for marketers… but that’s another story), but the kind you find when you bring hundreds of people together from different walks of life, each with their own special talents, and watch them create one of the most thought-provoking, engaging, and inclusive communities I've ever seen. They fostered a wealth of knowledge and resources that left everyone with plenty of new ideas and answers to marketing’s most challenging questions. That, coupled with the impressive speaker line up and innovative topics, made 2018 one of the best MozCons to date. I am honored to have been a part of it.

Even our attendees thought so:

99.1% of attendees said they were either satisfied, very satisfied, or extremely satisfied with the conference overall.

And when it came to the topics, 77.8% said the topics were just the right amount of advanced — there was plenty to learn, but we weren’t too overwhelmed.


Here’s what Lily Ray, SEO Director at Path Interactive, had to say about MozCon 2018:

I’ve made MozCon an annual ritual. I leave each year feeling invigorated with new ideas, new skills, and a refreshed approach to client strategies. The information I’ve learned at MozCon has improved my abilities as an SEO and has led to better results for my clients.



I hope you experience a slice of MozCon magic with the MozCon 2018 Video Bundle. With it, you’ll gain access to 12 hours of content full of actionable tactics you can instantly put to work for you and your team. The sessions are sure to help energize your online marketing strategy.

What you’ll get:

For just $299, you can enjoy the full MozCon experience from the comfort of your home or office. The bundle includes:

  • 26 full-length videos from some of the brightest minds in digital marketing
  • Instant downloads and streaming to your computer, tablet, or mobile device
  • Downloadable slide decks for presentations

Buy the MozCon 2018 Video Bundle

Not convinced yet? Watch a session now… for free!

To help you decide whether the video bundle is right for you, we're sharing one of our highest-rated sessions with you for free! In this session, Moz’s own marketing scientist and SEO extraordinaire Dr. Pete Meyers discusses mapping keywords to searcher intent and capitalizing on the promise of ranking to drive results that attract clicks and customers. Enjoy!

Ranking is a Promise: Can You Deliver? with Dr. Pete Meyers

Finally, a BIG thank you to the team who made MozCon and this video bundle possible. We love sharing all this knowledge and couldn’t do it without the support of our vendors, partners, and the entire MozCon team.

And to the community, we wish you happy learning and hope to see you at MozCon 2019!


Sign up for The Moz Top 10, a semimonthly mailer updating you on the top ten hottest pieces of SEO news, tips, and rad links uncovered by the Moz team. Think of it as your exclusive digest of stuff you don't have time to hunt down but want to read!



source https://moz.com/blog/mozcon-video-bundle-2018

Monday, 1 October 2018

Facebook breach hit up to 5M EU users, and it faces up to $1.63B in fines

Less than 10 percent of the 50 million users attacked in Facebook’s recent breach lived in the European Union, tweeted the Irish Data Protection Commission which oversees privacy in the region. However, Facebook still could be liable for up to $1.63 billion in fines, or 4 percent of its $40.7 billion in annual global revenue for the prior financial year, if the EU determines it didn’t do enough to protect the security of its users.

Facebook wrote in response to the IDPC’s tweet that “We’re working with regulators including the Irish Data Protection Commission to share preliminary data about Friday’s security issue. As we work to confirm the location of those potentially affected, we plan to release further info soon.”

Facebook alerted regulators and the public to the breach Friday morning after discovering it Tuesday afternoon. That’s important because it came under the 72-hour deadline for announcing hacks that can trigger an additional fine of up to 2 percent of a company’s global revenue if not met.

That hack saw sophisticated attackers combine three bugs in Facebook’s profile, privacy, and video uploading features to steal the access token of 50 million users. These access tokens could allow the attackers to take over user accounts and act as them on Facebook, Instagram, Oculus, and other sites that rely on Facebook’s login system. The EU’s GDPR laws threaten heavy fines for improper security practices and are seen as stricter than those in the US, so its findings during this investigation carry weight.

The big question remains what data was stolen and how it could potentially be misused. Unless investigators or journalists discover a nefarious application for that data, such as how Cambridge Analytica’s illgotten data was used to inform Donald Trump’s campaign strategy, it’s unlikely for the public to see this as more than just another of Facebook’s constant privacy scandals. It could still trigger regulation, or push partners away from using Facebook’s login system, but the world seems to be growing numb to the daily cybersecurity breaches that plague the internet.



source https://techcrunch.com/2018/10/01/facebook-breach-europe/

Facebook can’t keep you safe

Another day, another announcement from Facebook that it has failed to protect your personal information. Were you one of the 50 million (and likely far more, given the company’s graduated disclosure style) users whose accounts were completely exposed by a coding error in play for more than a year? If not, don’t worry — you’ll get your turn being failed by Facebook. It’s incapable of keeping its users safe.

Facebook has proven over and over again that it prioritizes its own product agenda over the safety and privacy of its users. And even if it didn’t, the nature and scale of its operations make it nearly impossible to avoid major data breaches that expose highly personal data.

For one thing, the network has grown so large that its surface area is impossible to secure completely. That was certainly demonstrated Friday when it turned out that a feature rollout had let hackers essentially log in as millions of users and do who knows what. For more than a year.

This breach wasn’t a worst case scenario exactly, but it was close. To Facebook it would not have appeared that an account was behaving oddly — the hacker’s activity would have looked exactly like normal user activity. You wouldn’t have been notified via two-factor authentication, since it would be piggybacking on an existing login. Install some apps? Change some security settings? Export your personal data? All things a hacker could have done, and may very well have.

This happened because Facebook is so big and complicated that even the best software engineers in the world, many of whom do in fact work there, could not reasonably design and code well enough to avoid unforeseen consequences like the bugs in question.

I realize that sounds a bit hand-wavy, and I don’t mean simply that “tech is hard.” I mean that realistically speaking, Facebook has too many moving parts for the mere humans that run it to do so infallibly. It’s testament to their expertise that so few breaches have occurred; the big ones like Cambridge Analytica were failures of judgment, not code.

A failure is not just inevitable but highly incentivized in the hacking community. Facebook is by far the largest and most valuable collection of personal data in history. That makes it a natural target, and while it is far from an easy mark, these aren’t script kiddies trying to find sloppy scripts in their free time.

Facebook itself said that the bugs discovered Friday weren’t simple; it was a coordinated, sophisticated process to piece them together and produce the vulnerability. The people who did this were experts, and it seems likely that they have reaped enormous rewards for their work.

The consequences of failure are also huge. All your eggs are in the same basket. A single problem like this one could expose all the data you put on the platform, and potentially everything your friends make visible to you as well. Not only that, but even a tiny error, a highly specific combination of minor flaws in the code, will affect astronomical numbers of people.

Of course, a bit of social engineering or a badly configured website elsewhere could get someone your login and password as well. This wouldn’t be Facebook’s error, exactly, but it is a simple fact that because of the way Facebook has been designed — a centralized repository of all the personal data it can coax out of its users — a minor error could result in a total loss of privacy.

I’m not saying other social platforms could do much better. I’m saying this is just another situation in which Facebook has no way to keep you safe.

And if your data doesn’t get taken, Facebook will find a way to give it away. Because it’s the only thing of value that they have; the only thing anyone will pay for.

The Cambridge Analytica scandal, while it was the most visible, was only one of probably hundreds of operations that leveraged lax access controls into enormous datasets scraped with Facebook’s implicit permission. It was their job to keep that data safe, and they gave it to anyone who asked.

It’s worth noting here that not only does it only take one failure along the line to expose all your data, but failures beyond the first are in a way redundant. All that personal information you’ve put online can’t be magically sucked back in. In a situation where, for example, your credit card has been skimmed and duplicated, the risk of abuse is real, but it ends as soon as you get a new card. For personal data, once it’s out there, that’s it. Your privacy is irreversibly damaged. Facebook can’t change that.

Well, that’s not exactly right. It could, for example, sandbox all data older than three months and require verification to access it. That would limit breach damage considerably. It could also limit its advertising profiles to data from that period, so it isn’t building a sort of shadow profile of you based on analysis of years of data. It could even opt not to read everything you write and instead let you self-report categories for advertising. That would solve a lot of privacy issues right there. It won’t, though. No money in that.

One more thing Facebook can’t protect you from is the content on Facebook itself. The spam, bots, hate, echo chambers — all that is baked on in. The 20,000-strong moderation team they’ve put on the task is almost certainly totally inadequate, and of course the complexity of the global stage and all its cultures and laws ensures that there will always be conflict and unhappiness on this subject. At the very best it can remove the worst of it after it’s already been posted or streamed.

Again, it’s not really Facebook’s fault exactly that there are people abusing its platform. People are the worst, after all. But Facebook can’t save you from them. It can’t prevent the new category of harm that it has created.

What can you do about it? Nothing. It’s out of your hands. Even if you were to quit Facebook right now, your personal data may already have been leaked and no amount of quitting will stop it from propagating online forever. If it hasn’t already, it’s probably just a matter of time. There’s nothing you, or Facebook, can do about it. The sooner we, and Facebook, accept this as the new normal, the sooner we can get to work taking real measures towards our security and privacy.



source https://techcrunch.com/2018/10/01/facebook-cant-keep-you-safe/

Meet Adam Mosseri, the new head of Instagram

Zuckerberg must face public scrutiny over latest data breach, say UK MPs

UK members of parliament have once again called for Facebook’s founder, Mark Zuckerberg, to travel to the country to face questions about how his business operates.

They’re renewing calls for facetime with the Facebook CEO in light of the massive data breach it disclosed on Friday — which the company said could affect as many as 90 million users, with 50M confirmed to have been compromised. It’s not clear exactly how many UK (or European) accounts are involved at this stage.

Facebook said on Friday that it had fixed the flaws, which were introduced after an update in July, and had been exploited by hackers to swipe access tokens. Attackers had been able to use its APIs to scrape some user data, it also said. It reset all potentially affected tokens once it discovered the hack late last month.

Damian Collins, who chairs a UK parliamentary select committee which, earlier this year, spent several months this year interrogating data protection issues, and recently called for a levy on social media platforms to help defend democratic institutions from online disinformation, told the Telegraph: “Facebook’s latest data breach demonstrates more clearly than ever why Mark Zuckerberg should face public scrutiny about the practices and policies his company employs to keep British users’ data safe.”

Julian Knight, another member of the committee, also said: “It would be helpful to hear from Mr Zuckerberg, but I won’t be holding my breath.”

Earlier this year MPs on the Department for Digital, Culture, Media and Sport (DCMS) select committee appealed for Zuckerberg to personally give evidence as they scrutinized the impact of online disinformation on democractic processes. However Facebook repeatedly declined to send its founder — instead sending some alternative staffers, including — finally — its CTO.

The committee was not satisfied, complaining that the reps it sent were unable to answer their questions. Collins also slammed the company for what he described as an evasive “pattern of behaviour” — and “a desire to hold onto information and not disclose it”.

It also kept up its pressure for Zuckerberg to testify — offering the chance for him to answer questions remotely, via video link. Still Facebook declined.

In May, in a pretty extraordinary development, the DCMS committee then told Facebook that if its founder stepped foot on UK soil they would issue him with a formal summons.

Safe to say, Zuckerberg made no trips to the UK, although he did attend a meeting of the EU parliament’s conference of presidents towards the end of May (where he was heckled for also avoiding MEPs’ questions).

Given his record of rejecting invitations from the UK parliament, it seems unlikely the company will suddenly offer its CEO up now — to discuss an awkward security breach to boot.

Though Facebook’s lack of engagement with UK politicians might make the government keener to seize on the committee’s recommendation of a social media levy to offset damage caused by tech platforms’ accelerating online disinformation.

We’ve reached out to Facebook with questions and will up date this story with any response.

The data breach is the first that falls clearly under new EU-wide privacy rules which carry beefed up penalties for violations.

On Friday, in a statement commenting on the Facebook hack, the UK’s data protection agency said: “It’s always the company’s responsibility to identify when UK citizens have been affected as part of a data breach and take steps to reduce any harm to consumers. We will be making enquiries with Facebook and our overseas counterparts to establish the scale of the breach and if any UK citizens have been affected.”

The company does appear to have abided by the requirements of GDPR to report major breaches within 72 hours of discovery.



source https://techcrunch.com/2018/10/01/zuckerberg-must-face-public-scrutiny-over-latest-data-breach-say-uk-mps/