Live data from Hacker News

Facebook exposed identities of moderators to suspected terrorists

theguardian.com

1–10 of 39 posts

Re: Facebook exposed identities of moderators to suspected terrorists

#2
What good is hundreds of billions of dollars if you can't do the small things right? Or maybe too much money just allows you be mediocre. There seems to be an inflection point that happens at, but who knows what that is.

Greed and pride come before the fall; hopefully all you people out there working to dethrone these companies will keep kicking.

Re: Facebook exposed identities of moderators to suspected terrorists

#3

What good is hundreds of billions of dollars if you can't do the small things right? Or maybe too much money just allows you be mediocre. There seems to be an inflection point that happens at, but who knows what that is. Greed and pride come before the fall; hopefully all you people out there working to dethrone these companies will keep kicking.

Security is hard. You can't make this kind of statement if you haven't been a pentester. Do a stint for a year and you'll see.

I personally found a remote code exec on one of the biggest security company's servers. I can't be more specific, but suffice to say, it was a small oversight that had big consequences. It's very hard not to screw up the small things.

If you've written a large service, and you give me a week with it, odds are better than 50/50 that I'll at least find an XSS. I think out of fifty or so pentests, there were only two that I didn't find an XSS or better, and one was a read-only informational pamphlet.

Re: Facebook exposed identities of moderators to suspected terrorists

#5

What good is hundreds of billions of dollars if you can't do the small things right? Or maybe too much money just allows you be mediocre. There seems to be an inflection point that happens at, but who knows what that is. Greed and pride come before the fall; hopefully all you people out there working to dethrone these companies will keep kicking.

Security is hard. You can't make this kind of statement if you haven't been a pentester. Do a stint for a year and you'll see. I personally found a remote code exec on one of the biggest security company's servers. I can't be more specific, but suffice to say, it was a small oversight that had big consequences. It's very hard not to screw up the small things. If you've written a large service, and you give me a week…

It might be hard, but if you've got those kind of resources available to you and the consequence of being wrong is hundreds of your employees might not ever be safe again, you'd better make sure you are right.

A bug in the software, discovered late last year, resulted in the personal profiles of content moderators automatically appearing as notifications in the activity log of the Facebook groups, whose administrators were removed from the platform for breaching the terms of service. The personal details of Facebook moderators were then viewable to the remaining admins of the group.

So nobody noticed that or fixed it for 2 weeks (edit: the article actually says that the bug was active for 2 weeks before being discovered and not fixed for another 2 weeks, and was retroactively exposing employees for more than a year - is that security)? Thousands of employees and nobody is checking for that?

Come on. We praise Elon sending things into space but FB can't do some basic error checking? Something doesn't add up.

Re: Facebook exposed identities of moderators to suspected terrorists

#6

Earlier quoted context omitted.

Security is hard. You can't make this kind of statement if you haven't been a pentester. Do a stint for a year and you'll see. I personally found a remote code exec on one of the biggest security company's servers. I can't be more specific, but suffice to say, it was a small oversight that had big consequences. It's very hard not to screw up the small things. If you've written a large service, and you give me a week…

It might be hard, but if you've got those kind of resources available to you and the consequence of being wrong is hundreds of your employees might not ever be safe again, you'd better make sure you are right. A bug in the software, discovered late last year, resulted in the personal profiles of content moderators automatically appearing as notifications in the activity log of the Facebook groups, whose administrator…

Did I mention that the other pentesters on the team completely missed that remote code exec I found? I hate to brag, but sometimes it's the best way to get a point across.

Security is so hard that you can't find everything. One of the dirty secrets of the security industry that nobody likes to talk about is that when you do a pentest, you're deemed secure, but it's overwhelmingly likely that the pentesters didn't find all the vulnerabilities.

Security breaches are rare, which is why this system works. But it's not malicious -- it's just very, very hard to be secure all the time. Security isn't even a priority in most cases.

I get that you're saying Facebook has resources. But with resources comes scale. How many programmers do you suppose worked on that feature? It could be one or two out of a dozen assigned to that arm of the project. Or it could be a dozen involved in a multi-month refactoring of spaghetti code. Or it could be one overworked person who threw in a "fix" before crawling home to bed. FB hires exceptional people, and even exceptional people ship bugs.

By the way, two weeks is a tiny amount of time. A real-world pentest takes about that long to book, unless you already have pentesters on retainer. I'm sure Facebook does, but as I said, pentesters can't catch everything.

Re: Facebook exposed identities of moderators to suspected terrorists

#7
post #4

Why are their personal profiles tied to their moderation duties? Are these not their passional profiles but one that also is tied to their identity in another way?

When I visited the NYC Facebook office in 2015, I was told that employees were required to use their personal Facebook pages for work purposes.

Re: Facebook exposed identities of moderators to suspected terrorists

#8
post #7
post #4

Why are their personal profiles tied to their moderation duties? Are these not their passional profiles but one that also is tied to their identity in another way?

When I visited the NYC Facebook office in 2015, I was told that employees were required to use their personal Facebook pages for work purposes.

That's mind boggling. I wonder if you can just create a second Facebook page and use that. Would Facebook really fire an employee for using a work Facebook? And what if you didn't use Facebook in the first place? Any Facebook employees want to chime in?

Re: Facebook exposed identities of moderators to suspected terrorists

#10

Earlier quoted context omitted.

It might be hard, but if you've got those kind of resources available to you and the consequence of being wrong is hundreds of your employees might not ever be safe again, you'd better make sure you are right. A bug in the software, discovered late last year, resulted in the personal profiles of content moderators automatically appearing as notifications in the activity log of the Facebook groups, whose administrator…

Did I mention that the other pentesters on the team completely missed that remote code exec I found? I hate to brag, but sometimes it's the best way to get a point across. Security is so hard that you can't find everything. One of the dirty secrets of the security industry that nobody likes to talk about is that when you do a pentest, you're deemed secure, but it's overwhelmingly likely that the pentesters didn't fin…

It's frustration speaking, but you're right in what you are saying.

Good security folks are valuable for a reason. Good luck to your efforts.

Post reply on HN