Live data from Hacker News

Facebook exposed identities of moderators to suspected terrorists

theguardian.com

11–20 of 39 posts

Re: Facebook exposed identities of moderators to suspected terrorists

#11

Earlier quoted context omitted.

Security is hard. You can't make this kind of statement if you haven't been a pentester. Do a stint for a year and you'll see. I personally found a remote code exec on one of the biggest security company's servers. I can't be more specific, but suffice to say, it was a small oversight that had big consequences. It's very hard not to screw up the small things. If you've written a large service, and you give me a week…

It might be hard, but if you've got those kind of resources available to you and the consequence of being wrong is hundreds of your employees might not ever be safe again, you'd better make sure you are right. A bug in the software, discovered late last year, resulted in the personal profiles of content moderators automatically appearing as notifications in the activity log of the Facebook groups, whose administrator…

I think the time to fix is the most telling. I can understand how bugs get shipped sometimes even by good engineers but what I don't understand is how they don't have someone fixing it immediately if lives are endangered.

Re: Facebook exposed identities of moderators to suspected terrorists

#12
post #7

Earlier quoted context omitted.

When I visited the NYC Facebook office in 2015, I was told that employees were required to use their personal Facebook pages for work purposes.

That's mind boggling. I wonder if you can just create a second Facebook page and use that. Would Facebook really fire an employee for using a work Facebook? And what if you didn't use Facebook in the first place? Any Facebook employees want to chime in?

When I worked at Facebook, an intern had never had a profile before. She made one for work, and kept commenting that she was the only person who was seeing the features Facebook advertises heavily to the low-friendcount users.

She doesn't seem to have used it since leaving.

Re: Facebook exposed identities of moderators to suspected terrorists

#13

What good is hundreds of billions of dollars if you can't do the small things right? Or maybe too much money just allows you be mediocre. There seems to be an inflection point that happens at, but who knows what that is. Greed and pride come before the fall; hopefully all you people out there working to dethrone these companies will keep kicking.

Security is hard. You can't make this kind of statement if you haven't been a pentester. Do a stint for a year and you'll see. I personally found a remote code exec on one of the biggest security company's servers. I can't be more specific, but suffice to say, it was a small oversight that had big consequences. It's very hard not to screw up the small things. If you've written a large service, and you give me a week…

Security is hard. But it's impossible when you are idiotic. Only an idiot would think tying someone's personal account to their work account (where their work is counter terrorism) is a good idea!

Re: Facebook exposed identities of moderators to suspected terrorists

#14

Earlier quoted context omitted.

Security is hard. You can't make this kind of statement if you haven't been a pentester. Do a stint for a year and you'll see. I personally found a remote code exec on one of the biggest security company's servers. I can't be more specific, but suffice to say, it was a small oversight that had big consequences. It's very hard not to screw up the small things. If you've written a large service, and you give me a week…

Security is hard. But it's impossible when you are idiotic. Only an idiot would think tying someone's personal account to their work account (where their work is counter terrorism) is a good idea!

We decided to not give our employees life preservers even though they are sailors. We didn't know they were going to drown!

Re: Facebook exposed identities of moderators to suspected terrorists

#15
I've locked my FB profile down quite heavily, including hiding it from search engines. But my name leaks out to Google anyway, through its "view the profiles of people named" user list feature. Social networks pay lip-service to privacy, and incidents like this underscore that.

Re: Facebook exposed identities of moderators to suspected terrorists

#16

I've locked my FB profile down quite heavily, including hiding it from search engines. But my name leaks out to Google anyway, through its "view the profiles of people named" user list feature. Social networks pay lip-service to privacy, and incidents like this underscore that.

"Don't put anything on the internet you'd like to keep private."

Re: Facebook exposed identities of moderators to suspected terrorists

#18
post #7
post #4

Why are their personal profiles tied to their moderation duties? Are these not their passional profiles but one that also is tied to their identity in another way?

When I visited the NYC Facebook office in 2015, I was told that employees were required to use their personal Facebook pages for work purposes.

That's like something out of The Circle :)

Re: Facebook exposed identities of moderators to suspected terrorists

#19
post #17

Note: The dupe filter doesn't catch a missing www. https://news.ycombinator.com/item?id=14571426

As it shouldn't. It's a different URL.

It's pretty annoying when dupe filters "catch" submissions with ?repost=1 appended to them, for example. It was either Reddit or HN that did that at one point. Sometimes there are legitimate reasons to resubmit.

It's also a form of letting the community express themselves -- if a thread is repeatedly flagkilled, having some mechanism to resubmit it is a way of resisting the urge to cry censorship. It often gets a thread to the front page (albeit with cement boots).

That's a bit tangential, but I'm just providing a few counterpoints to resist the urge to tighten the dupe filter. The manual method works pretty well.

Re: Facebook exposed identities of moderators to suspected terrorists

#20
post #17

Note: The dupe filter doesn't catch a missing www. https://news.ycombinator.com/item?id=14571426

As it shouldn't. It's a different URL. It's pretty annoying when dupe filters "catch" submissions with ?repost=1 appended to them, for example. It was either Reddit or HN that did that at one point. Sometimes there are legitimate reasons to resubmit. It's also a form of letting the community express themselves -- if a thread is repeatedly flagkilled, having some mechanism to resubmit it is a way of resisting the urge…

>It's a different URL.

It seems ripe for abuse. #walawalabingbang is also able to pass.

https://news.ycombinator.com/item?id=14573297

That opens the door to unlimited resubmissions.

Post reply on HN