Why are their personal profiles tied to their moderation duties? Are these not their passional profiles but one that also is tied to their identity in another way?
Facebook exposed identities of moderators to suspected terrorists
31–39 of 39 posts
Re: Facebook exposed identities of moderators to suspected terrorists
#32What good is hundreds of billions of dollars if you can't do the small things right? Or maybe too much money just allows you be mediocre. There seems to be an inflection point that happens at, but who knows what that is. Greed and pride come before the fall; hopefully all you people out there working to dethrone these companies will keep kicking.
Security is hard. You can't make this kind of statement if you haven't been a pentester. Do a stint for a year and you'll see. I personally found a remote code exec on one of the biggest security company's servers. I can't be more specific, but suffice to say, it was a small oversight that had big consequences. It's very hard not to screw up the small things. If you've written a large service, and you give me a week…
So is nuclear reactor management, but we seem to be able to go decades between substantial reactor failures.
It helps if your company considers "move fast and break things" to be a cautionary tale instead of a fucking motto. This is the only industry in the world where people actually brag about doing slapdash work.
Re: Facebook exposed identities of moderators to suspected terrorists
#33Note: The dupe filter doesn't catch a missing www. https://news.ycombinator.com/item?id=14571426
As it shouldn't. It's a different URL. It's pretty annoying when dupe filters "catch" submissions with ?repost=1 appended to them, for example. It was either Reddit or HN that did that at one point. Sometimes there are legitimate reasons to resubmit. It's also a form of letting the community express themselves -- if a thread is repeatedly flagkilled, having some mechanism to resubmit it is a way of resisting the urge…
HN, then, because Reddit loves reposts.
Re: Facebook exposed identities of moderators to suspected terrorists
#34There's a lot of "security is hard" comments here. What I can't understand is: Of the 1,000 affected workers, around 40 worked in a counter-terrorism unit based at Facebook’s European headquarters in Dublin, Ireland. If you work in a counter-terrorism unit the consequences of your identity being known by the wrong people are extreme. Extreme as possible death. Why aren't these employees identities obfuscated by multi…
Re: Facebook exposed identities of moderators to suspected terrorists
#35Why are their personal profiles tied to their moderation duties? Are these not their passional profiles but one that also is tied to their identity in another way?
When I visited the NYC Facebook office in 2015, I was told that employees were required to use their personal Facebook pages for work purposes.
Re: Facebook exposed identities of moderators to suspected terrorists
#36Earlier quoted context omitted.
That's mind boggling. I wonder if you can just create a second Facebook page and use that. Would Facebook really fire an employee for using a work Facebook? And what if you didn't use Facebook in the first place? Any Facebook employees want to chime in?
And what if you didn't use Facebook in the first place? That's even more mind boggling. Why would someone who didn't use Facebook want to work for them, much less get hired without creating an account sometime before that? These days, it seems that if you don't use Facebook you probably have a strong opinion not to, and are unlikely to even consider working for them.
However, I'd probably work at Facebook. I respect and admire Facebook's overall security organization more than just about any other large tech company except Google, Apple or Microsoft. I haven't actually looked for employment there, but I've heard it's nice, and there are probably really interesting roles available for cryptography research and engineering.
Re: Facebook exposed identities of moderators to suspected terrorists
#37Earlier quoted context omitted.
Security is hard. You can't make this kind of statement if you haven't been a pentester. Do a stint for a year and you'll see. I personally found a remote code exec on one of the biggest security company's servers. I can't be more specific, but suffice to say, it was a small oversight that had big consequences. It's very hard not to screw up the small things. If you've written a large service, and you give me a week…
> Security is hard. So is nuclear reactor management, but we seem to be able to go decades between substantial reactor failures. It helps if your company considers "move fast and break things" to be a cautionary tale instead of a fucking motto. This is the only industry in the world where people actually brag about doing slapdash work.
I understand the spirit of your point, but that's not at all a fair comparison. They're just altogether different things, and part of the problem is the nature of the tech industry, in which layers of complexity and security debt from different languages and frameworks can be piled on each other over and over again.
I think you should consider Dunning-Kruger here: instead of comparing Facebook's security to nuclear reactor safety, compare it to a company you believe has superior security; moreover, do you think you are appropriately qualified to condemn Facebook's security organization for the proportion of failures it experiences?
Re: Facebook exposed identities of moderators to suspected terrorists
#38What good is hundreds of billions of dollars if you can't do the small things right? Or maybe too much money just allows you be mediocre. There seems to be an inflection point that happens at, but who knows what that is. Greed and pride come before the fall; hopefully all you people out there working to dethrone these companies will keep kicking.
Security is hard. You can't make this kind of statement if you haven't been a pentester. Do a stint for a year and you'll see. I personally found a remote code exec on one of the biggest security company's servers. I can't be more specific, but suffice to say, it was a small oversight that had big consequences. It's very hard not to screw up the small things. If you've written a large service, and you give me a week…
This is a process and protocol oriented issue. Facebook could have allowed the moderators to use anonymized accounts, or have better error testing.
Re: Facebook exposed identities of moderators to suspected terrorists
#39What good is hundreds of billions of dollars if you can't do the small things right? Or maybe too much money just allows you be mediocre. There seems to be an inflection point that happens at, but who knows what that is. Greed and pride come before the fall; hopefully all you people out there working to dethrone these companies will keep kicking.
Security is hard. You can't make this kind of statement if you haven't been a pentester. Do a stint for a year and you'll see. I personally found a remote code exec on one of the biggest security company's servers. I can't be more specific, but suffice to say, it was a small oversight that had big consequences. It's very hard not to screw up the small things. If you've written a large service, and you give me a week…
It's not that anyone broke in and stole things here, it's that Facebook dumped their stuff out of the window.
A variation of your point I totally agree with, FB has a lot of moving parts and a lot of employees. Who is this "Facebook" that should be ashamed of their incompetence, right? It's theoretically possible for a million genius engineers to be connected in a bureaucracy created the best of intentions, by the brightest of minds, that still turns their work into swiss cheese.
Maybe one problem is making these huge things, which are supposedly monolithic but where one hand doesn't quite know what the other is doing. That's at least a claim worth examining, right? And if you want to exclude the people who don't have that kind of experience because they consider it a dead end that never enticed them, that's both reasonable and circular. Yes, I don't know what I'm talking about, though I have enough imagination and whiffs of knowledge to at least know that -- but no, I don't have to be a ninja coder or a corporate high roller either, I learned to separate wheat from chaff, to appreciate skillful tight programs and to despite gimmicky bloat, sometimes around the Amiga, as a kid. Even as a user who pays a modicum of attention I can do this. I guess floppy drives helped, but the principle is still valid today, nothing changed.
So no, I don't need experience in maintaining giants that do a thousand things badly to wish for the return of a lot of little things that do a handful of things well. That's part of the reason I sleep soundly but angrily. It's 2017 and I still can't have a phone call with the quality I had in, say, 1990, because for every step of technological progress and insight, there seem to be five steps of greed and idiocy. It's 2017 and people are on Facebook. For me that's "the" problem, and making a "secure" Facebook is not the solution.
Freedom requires vigilance, that's not just words, that means if we have even just one lapse in your history, a period where we were not on your toes, where we left our drink unattended, we should be frightened stiff. A lot of people who should be aren't.
We laughed at AOL and whatever that thing was Microsoft cooked up before they realized the internet was going to be more than just a Microsoft product. And now, in the shape of Facebook and others, that won. It was cute to use "googling" as a verb meaning "to look something up on the internet", for a while, but it's not really, and I'm sick of it and I still say it. Yeah yeah, search engines are hard, operating systems are hard, but that stuff used to be even harder and it's silly that we seem to have less diversity now the more resources there are to go around. I don't hate on anyone's success, their success is hating on my imagined opportunities >:[
I'm not sorry for rambling, but as a more sober and delineated final point, something more actionable if you will.. from the article:
> Facebook confirmed the security breach in a statement and said it had made technical changes to “better detect and prevent these types of issues from occurring”.
What kind of "active" measures do they have in mind? What "type of issue" is this, even? Do they have something in mind they're "just" not sharing, or is that just a bluff? Without saying that, or hey, without actually showing the code and the understandable mistake that lead to this, that just sounds like "yeah, whatever it is you care most about, that's exactly what we'll fix". I know it's an article on The Guardian, I know they just can't show off code, but it's not really my fault that both incompetence and good faith speak in the same meaningless corporate verbiage.
Show me the goods, in some way or other. If you say something most people don't understand, but which YOU understand and which you're absolutely sincere and concentrated about, guess what, even babies, even dogs might trust you. And the people who do know what you're talking about can also rest well. But this way, the way this stuff gets handled lest the lawyers freak out, it's just completely empty. To actually learn something, a FB employee would have to violate their contract, and that that's normal doesn't make it less nuts. Yes, security is hard when you build super tall towers that move at hundreds of miles an hour. Then how about let's not?