Facebook: Rules of Engagement

(original photo by Makeen M.Alaa on Unsplash)

Facebook has become a crucial battleground in politics.

On Facebook, waves of comments expressing toxic views create an illusion of mainstream agreement, establishing dangerous social norms.

On Facebook, deliberately contrived propaganda is carried into regular communities to harm positive and progressive causes.

On Facebook, soundbite opinions about political events are circulated, spread, and refined.

If you’re still on Facebook, you’ve seen how wild it gets over there. It can feel like reality has been swamped by bots and monsters. Take heart! The troll army is smaller and weaker than it seems. We can push back, and make a (small but mighty) difference.

(1) Why Facebook matters

The internet has changed a great deal in the last decade, and now we are dealing with a single overwhelmingly important truth: Facebook is the only social media platform where regular people talk to each other.

Other big social media sites (Instagram, TikTok, YouTube, Snapchat, etc.) are broadcast channels for receiving content as an audience. Other talk-based social media sites (Reddit, X/Twitter, Mastodon, Bluesky, Threads) are small next to Facebook, and do not really attract a membership of regular people. (Users tend to be ‘very online’.) Specialist community social media (Neighbourly in NZ, Nextdoor in the US, the NeighbourhApp in Dignity Falls) gets close but doesn’t have the reach.

Regular people go to Facebook and use it daily for regular person reasons:

  • It has a peer-to-peer marketplace that dominates informal selling.
  • It is the online front door of many small and medium businesses.
  • It has an events system that makes it easy to organize parties, special occasions, public events, and more.
  • It shows you what your friends and family are up to, and lets you share your activities with them. (Although this functionality has been degraded, it still works enough to keep people on the site.)
  • And, crucially, it has interest group spaces, where you can see and join discussions about whatever you’re interested in. (This is the only aspect of Facebook that genuinely works well.)

One of the most popular interest group types is the local community group, where a broad cross-section of people in your city, town, or suburb can report lost pets, complain about driving, and discuss the news. On the entire internet, Facebook is the only place this happens at scale.

This makes Facebook crucially important for societies and communities. Politics happens there in a way that it does not happen anywhere else online.

We’d better not abandon it to the right wing machines.

(2) On Facebook, influence is tilted.

In the New Zealand election 2026, Facebook posts and comments will directly influence the voting decisions and political beliefs of countless Kiwi voters.

That influence will be overwhelmingly tilted in favour of reactionary, conservative, and paranoid right-wing parties.

The right has several advantages that help create this tilt:

  • They have the money to place their messages into the platform’s machinery. The political parties directly, but also lobby groups such as the Taxpayers Union and the Sensible Sentencing Trust.
  • They benefit from the structure of the platform. Hot take posts with a simple message provoking a negative emotional reaction generate the kind of activity that leads to circulation via the algorithm. These kinds of post suit right-wing politics much more than left-wing politics.
  • They have the global moment in their favour. Reactionary forces have not been so dominant around the world for over half a century. International messages are delivered into local context by the algorithm.
  • They might also have international interference operations in their favour. Russian activity is real, and while it remains to be seen whether this will a factor in the coming election, it was a factor in the last one.
  • They have the benefit of mendacity. Knowingly false or extravagantly exaggerated claims can easily be illustrated with AI slop and thrown into the algorithm to powerful effect; these kinds of posts serve right-wing messaging much more than left.

These advantages give right wing forces high visibility on Facebook.

There are many Facebook interest groups founded on social fear. Groups spring up expressing worry about immigration, or new health measures, or governance changes. Some are created deliberately by malign actors working to a strategic plan, but others form genuinely as grass-roots actions by concerned people who hold on to social fears.

These groups can become thick with discussion about what is feared, and spread worry and anxiety. Discussion in these groups is almost never about limiting worry or calming members down. The direction of travel is always towards greater fear, and more extreme views. In this way, these groups become entry points into more extreme message groups, which promote ever more elaborate and toxic views of the world.

The distance from a toxic fear group to a busy local community group is small. For those caught up in these fear beliefs, all of these items appear in the same scroll on their Facebook feed. They see paranoid hatred towards Jacinda Ardern that deems her a mass-murdering globalist, and just below, a National Party member scaremongering about the dangers of the Labour government. It all becomes one thing.

Inevitably, then, fear messages from these toxic communities make their way into regular discussion. They come from genuine members of these communities who earnestly hold these beliefs and express them; they come from cynical provocateurs who enjoy stirring up trouble by poking at the ‘do-gooders’ of the world; they come from bad faith political actors who have no actual beliefs to speak of but recognize these messages serve their ends; they come from fake accounts operated by foreign actors seeking to harvest engagement or stir up trouble.

The way Facebook works right now, these messages propagate on neutral spaces in numbers that vastly overrepresent the actual social presence of these beliefs.

They make it seem like there are lots of them. Like their views are extremely common, even the majority. They are not, not even close.

That discrepancy is territory we have ceded.

We can push back.

(3) Rules of engagement for Facebook

On the largest scale, there is not much to be done that will change this election. These factors on Facebook are locked in place. The playing field is tilted. That can’t be fixed in the next few months. It’s an important battle, but the best thing to do for it right now is strive to get the best people for that fight into government.

But there is a huge amount that can be achieved as part of our everyday engagement with our social media environment.

Whenever you visit Facebook, aim to make it just a little bit more pleasant and a little bit more real.

Here’s how to make your contributions most effective, and avoid making things accidentally worse.

[NOTE: Am I missing something? Is something wrong? Let me know so I can improve this list.]

How to engage depends on the kind of post you are looking at:

Posts from right-wing sources: Scroll past any post from a right-wing source. National/ACT/NZ First politicians, Destiny Church, lobby groups… Don’t engage. This just promotes their messages and gets the algorithm humming. They want battles under their posts, do not give them such. (Hardcore options: Read to identify key messages; screenshot and reply elsewhere without sending views to the original post.)

Neutral media sources: Under media sources, e.g. political news articles from RNZ or The Spinoff or NZ Herald, we can comment without driving engagement to RW messages. Particular things to do:
* take messages from the story that resonate and restate them in your own words. Many people won’t click the link.
* directly quote key lines from the story, with a comment like “this is the most important bit”.
* respond to a political message with a real world example from your life. (Don’t make one up!) “This policy would make a huge difference to my brother who does X, Y, Z.”
* reply to other people saying positive messages with more positive messages, particularly if they are getting shitty replies.
* if there are racist/hate messages in the comments (surprisingly common), make a comment (not a reply to an offender) asking for comment moderation.

Things to avoid:
* replying to RW troll/propaganda/negative messages. The engagement just pushes their comments to the top of the heap so people scrolling by will see them first. In fact, the “Most Relevant” filter will often hide your comment and just show theirs.

Friendly sources: Under posts by left-bloc politicians and parties, science outlets commenting on issues of concern, progressive activist folks, etc, you can get stuck in in support. Any action here will help the algorithm push this further. Particular things to do:
* heart and like reacts for the main post
* respond with any kind of positive personal message, something very ordinary is good to set the tone (but not revealing! Don’t open yourself to targeting by trolls!)
* reproduce and celebrate specific points made that you agree with
* wherever possible, emphasise how these politics are extremely normal in the global context. Giving NZ a chance to catch up with other countries is always a great message. Something having worked well in other countries similar.
* reply to any post with hateful subtext not with rage or disgust, that’s what they want. Dismissive contempt is the way. Don’t let hate sit unremarked, but don’t give it heat either, chill the temperature down until everything is icy cold.
* if you want to reply to less offensive troll posts with dunks, mocking rebuttals, sad GIFs, or whatever, this is the place to do it. Can’t do much damage here.

Things to avoid:
* don’t get over your skis, going too hard and overstating how amazing someone is. Regular people react badly to puffery. If you have a personal story of how someone genuinely did something amazing, then go for it, but if it’s just generalised cheerleading, watch the tone.
* don’t get so caught up in fighting trolls that you start to hate the internet and yourself. There is a cohort of people out there who are literally playing a game where they win by emotionally exhausting you. You can always ignore them, and should do so forever.
* by the same token, if a troll account challenges you to prove something or say something or whatever, don’t do it. Even if you do have the answer, just don’t do it. Treating these asks seriously is giving them respect they do not deserve and prolonging a conversation that helps them more than you. Just leave them hanging, like they don’t matter to you in the least. They hate that.
* (if it’s a normal person asking for more info, then go for it, keep chatting. You have to use your judgment about who is normal and who is troll. Some people have aspects of both, humans are complex!)

Local community groups: In these spaces, you can definitely make a difference. Here are some things to do:

* Share political posts from good sources into the group, with a context note about how it will affect local services or local people. Advanced mode: in the context note, instead of saying the thing, ask everyone a question about how the subject might help your community. You want the question to close off avenues for troll/shitpost responses as much as possible.
* Uphold an expectation of respect and kindness in your community. Every community wants to see itself as respectful and kind. Call out instances where kindness fails or respect has not been shown; “here in X town, we show respect to each other.” Don’t come in too hard, but don’t waver either.
* Be present and supportive in non-politics posts too. Community members will remember your name from post to post.

Things to avoid:
* International politics issues. Trans discrimination in the UK, the death toll in Gaza, freedom of speech in the US… Local people just don’t want to see these invoked. Even if they are relevant to what you’re discussing, don’t bring them up. Find another way to deal with the real topics. Yes these things matter! But you are not being negligent by not bringing them up as part of this process.
* Criticising people who don’t get everything right. Sometimes people are wrong on the internet, let it go. You have bigger targets.

(4) Look after yourself

Remember to log off. If you are not used to getting involved in this kind of talk on Facebook, it can be… unpleasant. People act awful online, much more so than in real life. Comments can feel very personal even if they’re not. And sometimes they will be personal, and that’s not okay! Don’t wreck your wellbeing for the sake of a few Facebook comments, that’s not helping anyone.

Find some friendly support. Any Facebook friends who are on the same page as you? Give them a message. Have each others’ back out there.

Consider locking down your account, especially if you are anything other than a white guy.

Accept that you will never see any proof it helped. There’s no way around that. You’re working to shift an invisible vibe among lurking users. There’s no way to see if it works. You just need to trust that it does, because real people are on Facebook and then those people vote. No matter what you do, the laugh react guys will keep laugh reacting, but you can be confident voters have seen your signal too.

That’s it. Repeat until the election. Good luck.

(Thanks to Kelly Whyte for some very helpful advice.)

Dear Spark

(Update 19 August at bottom of post)

Your “Tell us how we went” email has sat in my inbox for some weeks, waiting for me to get to it. Also, I suppose, waiting for some late reply to my last message that might have rescued the situation. Of course that didn’t end up happening. So, this message in your feedback form, which will be too long to fit. So I’m also posting publicly on my blog.

The lapse in your provision of service was relatively small in the grand scheme of things. However, it’s the nature of the failure that has stuck with me. And the more I tried to dig into it, the worse it all seemed, to the point that we are considering leaving Spark entirely.

Here is what happened.

My wife and I have been Spark customers for a long time. You provide us with broadband and mobile phone accounts (also a landline that we no longer use after recent renovations). We have been happy as your customers.

On June 17, my wife and I both received emails from mysparksupport@spark.co.nz titled We’ve removed an account from your Spark ID:

“Hi [NAME],
You no longer have access to Spark account [NUMBER].
If you think you’ve received this in error, please let us know.
Thanks!
From the Spark team”

This brief message was somewhat lost in the welter of emails we receive, and quite frankly it looks like some kind of spam or error. I tried to log into the Spark dashboard to see if I could understand what was going on.

This was unsuccessful in the most unhelpful ways. My password was simply not accepted, as if it was incorrect. I attempted to reset the password, but these attempts failed with no explanation. Finally, when I tried to use Google as a login method, the site gave a different message, that my email identity was locked out.

This began a lengthy process of investigation. My wife had created our account, and so I couldn’t even get any functional responses from support because I hadn’t been given account authority by her (something we had never previously needed or understood we might ever need). She had to spend a lengthy period, many hours, on the phone to establish who she was and figure out what was happening. Once she was able to set me up with authority, I took over and several more hours were spent on calls to get our account access back.

Throughout all the above, your helpdesk workers were unfailingly helpful and responsive. We are very happy with the direct service we received from these staffers. The problem was the limited information they had, the limited understanding they had, and the questions we have remaining at the end of this process.

We were, eventually, told that our accounts had been removed by the fraud prevention team, to protect us, because there were signs of access by a third party. Our account access was fully restored.

I persisted in email conversation with the fraud prevention team, trying to get more information, but there was very little forthcoming. At the end of this process I remain utterly infuriated.

To be clear: your fraud prevention systems are not fit for purpose and we are extremely dissatisfied.

We know that fraud prevention detected an attempt to log into our MySpark account from an international IP address. It was blocked, and an action of some kind was taken that removed access from our email address logins. This in turn generated the emails. Later, when we eventually proved our identities over the phone, our email addresses were linked back to the accounts.

Here are my problems:

What was the trigger event that led to access to our accounts being removed? Fraud prevention provided unclear information here. Fraud prevention could not tell me: which email address was used in a login attempt; was the login just an attempt with an email address, or did they have the correct password as well; were there multiple login attempts; where did these attempts take place; was there a successful login before access was revoked; or any other details at all. I find it hard to understand how this is possible; that our accounts were at such risk that they were taken out of our hands, but the information behind this action is so vague and undefined.

How was the decision made to remove access to our accounts? Was this decision made according to a standard procedure? (In which case, why is there no standard procedural followup?) Was this decision made by a person, or by an automatic process? Is fraud prevention of this nature managed by an AI system or entirely by a human team?

Why didn’t you check with us first? If there was a problem with our accounts from overseas, why didn’t you ever take the step of asking us about it? You have our phone numbers right there! You can verify our identities immediately! Surely the appropriate way to deal with a problem like this is to call and speak to someone, not delete our access, send an email, and abandon us to your FAQ and helpdesk to figure out what to do?

If access was at such risk that our emails were removed, why were they immediately restored? After establishing our identities, our emails were back on the accounts with the same passwords. Belatedly I received a comment from fraud prevention that we might want to change our passwords to be extra safe. But if our account details had been compromised, surely they were still compromised? How had the threat changed? And if it hadn’t changed, why was everything suddenly restored to normal as if nothing had happened? None of this makes any sense at all. Logically, either the initial action or the remedy was faulty. To be enitrely clear about what is at stake here: Are our personal details exposed, or not?

Why was your communication throughout nearly nonexistent? Such a significant event as removal of access for both account users generated a short email with no explanation, and nothing else. Figuring out what had happened took hours. Your systems created a huge problem for us, and then offloaded on to us every aspect of trying to solve it. I’m fairly sure your organisation would agree that “creating a messy problem for us to solve” is not an acceptable customer experience.

What is the risk being mitigated here? Fraud prevention also could not tell me what an intruder might do if they did gain access to our account. Presumably a malicious actor wants to do more than change our mobile phone plans! While this is a secondary issue, our continued ignorance on this point demonstrates just how poorly you have managed our experience.

It has been over a month since this event and I remain thoroughly dissatisfied by what transpired, and I have no confidence at all that the same poor experience will happen to other customers or, indeed, to us again in the future.

I expect a clear explanation, in writing, as to what exactly has happened here, from beginning to end.

Within this, I expect clear answers to these questions: Have our email addresses and passwords been exposed internationally? What information do you have that demonstrates this? If they have been exposed, why were our accounts restored with no changes? If not, why did this intervention happen in the first place? (Note that this information, our email addresses and passwords, counts as personal information under The Privacy Act 2020.)

Also, I want an indication that you understand and accept that your processes dropped the ball here. Our experience as your customers has been well below the standard we should expect from you. It is simply not good enough.

I await your response.

Update 19 August: After several prompts via multiple channels, I finally heard from a Spark customer rep via their in-app messaging service and eventually by phone call. It sounded like this person, and the whole structure of Spark customer support, wasn’t really able to engage with the kinds of concerns raised here. The rep said they would endeavour to send it up to someone who might be able to help in a more substantive way. I’m not sure if this will be successful; they did not sound confident. Which suggests to me that there isn’t any escalation path to speak of here. Perhaps I’m old fashioned but I find this shocking; when a customer-facing part of your business (fraud prevention in this case) leaves a customer unsatisfied, it seems self-evident to me that there should be a way to raise a ticket with whoever manages that business unit, and if that manager can’t help, to step up so someone who can address the issue. Apparently not in this case? Spark as a business seems structurally impenetrable. Needless to say, this doesn’t do anything to ease my frustrations, which remain as intense as ever.