Live data from Hacker News

Zuckerberg Takes Steps to Calm Facebook Employees

nytimes.com

91–100 of 274 posts

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#91
post #85

Earlier quoted context omitted.

> I'm not sure if Google even has an internal red team, last time I talked with someone there they didn't (was 18 months ago though). 2012: Google staffs up ‘Red Team’ And this was literally just a Google away: https://nakedsecurity.sophos.com/2012/08/24/google-red-team-...

Red team is an overloaded term: "Analyze software and services from a privacy perspective, ensuring they are in line with Google's stated privacy policies, practices, and the expectations of our users." Doesn't sound like adversary simulation to me.

https://careers.google.com/jobs#!t=jo&jid=/google/security-e...

The job even lists insider threat as part of their responsibility.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#92

These performances by CEOs before their employees to “calm” them reminds me of Jonestown or some other cult. Everyone kind of knows the leaders are corrupt liars and false prophets. It’s all a scam. But they’ve invested so much of their lives and identities into the ideology, there’s not really any turning back. It’s like some “When Prophesy Fails” inflection point for the whole industry. https://en.wikipedia.org/wik…

> These performances by CEOs before their employees to “calm” them reminds me of Jonestown or some other cult.

To be fair, the sentence that refers to "calming the employees" was from the New York Times and probably supposed to evoke that sort of feeling. The facts presented in the article are simply that Zuck had a meeting with employees to talk about current issues, which is pretty much standard practice for any company.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#93

Facebook's Board of Directors is a remarkable collection of silent-yet-complicit heavyweights: -Marc Andreessen; -Erskine Bowles ("President Emeritus of the University of North Carolina" and "White House Chief of Staff from 1996 to 1998"); -Ken Chenault ("Chairman and Chief Executive Officer of American Express Company"); -Susan Desmond-Hellmann ("Chief Executive Officer of The Gates Foundation" and former "Chancello…

Doesn't Zuckerberg have full control of the board?

> Doesn't Zuckerberg have full control of the board?

Zuckerberg has voting control of Facebook, in part due to some financial engineering in 2016 [1]. He does not control the Board.

Board members have a fiduciary "duty of care," i.e. "the duty to pay attention and to try to make good decision" [2]. This duty is to the company as a whole, not just its majority vote-holder [3][4]. (That said "American courts simply do not hold directors liable for business decisions, made without a conflict of interest, unless those decisions are completely irrational. The doctrine of noninterference is known as the business judgment rule." [2])

[1] https://www.bloomberg.com/view/articles/2016-04-28/mark-zuck...

[2] http://www.oecd.org/daf/ca/corporategovernanceprinciples/187... page 6

[3] https://en.wikipedia.org/wiki/Shareholder_oppression

[4] http://www.sgalaw.com/news-and-views/2010/4/27/shareholder-o...

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#94
post #70

Earlier quoted context omitted.

> It was true at Google. Yes, because Google is not your average company. It takes security extremely seriously... in fact it's about as awful of an example as you can give for a blanket statement you made about "most companies".

I'm not sure if Google even has an internal red team that performs breaches, last time I talked with someone there at a conference they didn't (that was 2016). So I am not sure Google has metrics on how easy it is to gain access by an adversary.

Google has a gaggle of security teams, almost all of which occasionally red team and some of which exclusively do. I'm not sure who told you otherwise but they were certainly mistaken. Source: I TL'd a security team there several years ago.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#96
post #58

Earlier quoted context omitted.

You request access, and justify it with something like "I need it to debug issue #123". Someone manually oks/disallows it, and there's asynchronous reviews of these requests to double check. My guess is the intern lied about what they're using it for. How else would you suggest to do privacy checks like these?

> You request access, and justify it with something like "I need it to debug issue #123". Someone manually oks/disallows it, and there's asynchronous reviews of these requests to double check. My guess is the intern lied about what they're using it for. OK so an insider can just lie and access whatever they want. Heck, they can even tell the truth! Just find a bug that's exhibited in a particular profile and use that…

So, you don't know how google handles this, but you are suggesting everybody should do what google does. Are you trolling?

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#97
post #78

Earlier quoted context omitted.

probably because speaking out would cause more trouble than its worth. i recall an Uber director decided to open his mouth during the incidents of last year...

Or recall the HP leaks.

> the HP leaks

The HP leak and spying scandal was so convoluted and left so many loose ends that I question its pedagogical utility.

"On September 5, 2006, Newsweek revealed that Hewlett-Packard's general counsel, at the behest of HP chairwoman Patricia Dunn, had contracted a team of independent security experts to investigate board members and several journalists in order to identify the source of an information leak. In turn, those security experts recruited private investigators who used a spying technique known as pretexting. The pretexting involved investigators impersonating HP board members and nine journalists (including reporters for CNET, the New York Times and the Wall Street Journal) in order to obtain their phone records. The information leaked related to HP's long-term strategy and was published as part of a CNET article.

Board member George Keyworth was ultimately accused of being the source and on September 12, 2006, he resigned, although he continued to deny making unauthorized disclosures of confidential information to journalists and was thanked by Mark Hurd for his board service. It was also announced at that time that Dunn would continue as chairwoman until January 18, 2007, at which point HP CEO Mark Hurd would succeed her. Then, on September 22, 2006 HP announced that Dunn had resigned as chairwoman because of the "distraction her presence on our board" created. On September 28, 2006, Ann Baskins, HP's general counsel, resigned hours before she was to appear as a witness before the House Committee on Energy and Commerce, where she would ultimately invoke the Fifth Amendment to refuse to answer questions."

https://en.wikipedia.org/wiki/Hewlett-Packard_spying_scandal

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#98
post #5
post #2

I feel like someone should also give Zuckerberg the memo that it's only a matter of time before an insider also goes rogue and abuses data access (edit: or otherwise; see below). Facebook fundamentally seems to trust itself way too much, and it worries me that it thinks the only threats are external entities... to me, this is another silently ticking time bomb. EDIT: And don't forget that going rogue is just one scen…

You'd think so, but most companies have pretty strict internal controls for this sort of thing. Access is also carefully logged so a leaker is pretty much guaranteed to get caught at which point they'd immediately lose their job and likely face criminal prosecution. With so much to lose and so little to gain internal leaks of this sort are extremely rare.

> With so much to lose and so little to gain internal leaks of this sort are extremely rare

I recently downloaded my Facebook archive [1]. If it were legal, I would certainly pay thousands if not tens of thousands of dollars for certain peoples' archives. I can think of several practical contexts in which an unethical actor would find it profitable to pay a Facebook employee a million dollars for someone's Facebook archives.

[1] https://www.facebook.com/help/131112897028467/

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#99
post #5
post #2

I feel like someone should also give Zuckerberg the memo that it's only a matter of time before an insider also goes rogue and abuses data access (edit: or otherwise; see below). Facebook fundamentally seems to trust itself way too much, and it worries me that it thinks the only threats are external entities... to me, this is another silently ticking time bomb. EDIT: And don't forget that going rogue is just one scen…

You'd think so, but most companies have pretty strict internal controls for this sort of thing. Access is also carefully logged so a leaker is pretty much guaranteed to get caught at which point they'd immediately lose their job and likely face criminal prosecution. With so much to lose and so little to gain internal leaks of this sort are extremely rare.

Who watches the watchers?

#1 - There's always a back door. I did some medical records stuff for a while. I looked myself up, just to confirm for myself how trivial it was to do. Yup, there I was. Which is why I insist that all data at rest is encrypted. (I have yet to win this argument.)

#2 - Our "portal" product had access logs for auditing. Plus permissions, consent trees, delegation. The usual features. Alas. We also had a "break the glass" scenario, ostensibly for emergency care, but was more like the happy path. And to my knowledge, during my 6 years, none of our customers ever audited their own logs.

#3 - My SO at the time worked in a hospital and went to another disconnected hospital for care because she knew her coworkers routinely, illegally looked up patient records, and she didn't want them spying on her.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#100

Can someone explain to me why the Cambridge Analytica story is making people so much angrier than the later revelation that Facebook was scraping call+text info? That seems to be the larger problem to me. Somewhere at Facebook there is a team of people who wrote software to scrape, store and analyze the personal call+text data that users didn't explicitly mean to give to Facebook. The data that Cambridge Analytica at…

Probably because of some of the things that Cambridge Analytica stands accused of, or else things they have blatantly admitted to while being secretly recorded: blackmail and bribery of politicians in multiple countries, hacking election results, and even more unethical acts[1,2].

People are upset that their data was essentially stolen from Facebook (it was collected for use in an academic study, then turned around and sold for profit to CA), used by a company with ethical failures as serious as Cambridge Analytica, and then Facebook buried the story. It was two years before it came to light thanks to Guardian journalist Carole Cadwalladr.

Facebook also worked closely with CA during the Trump campaign, even though they would have known by that time that data obtained under the pretense of an academic study had been sold to CA.

1. http://www.bbc.com/news/uk-43528219

2. https://www.channel4.com/news/cambridge-analytica-revealed-t...

Post reply on HN