Live data from Hacker News

Zuckerberg Takes Steps to Calm Facebook Employees

nytimes.com

131–140 of 274 posts

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#131
post #23
post #20

Earlier quoted context omitted.

I believe it's true of Google! I do not believe it's true in general.

shrug Without evidence we're both just guessing. Perhaps someone else will chime in with direct knowledge of how FB works.

I believe it's true of Facebook as well.

Source: I interviewed with their security team once and got a fair idea of how their various security teams are organized.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#132
post #102
post #91

Earlier quoted context omitted.

https://careers.google.com/jobs#!t=jo&jid=/google/security-e... The job even lists insider threat as part of their responsibility.

Yeah, still not the same as actually performing breaches themselves to see how long it takes to compromise, and if they get detected and how long it takes to remediate and evict the adversary. I should have been a bit clearer with what I meant initially.

How do you know there isn’t a team at Google doing this? It’s standard practice at companies of even middling size and Google is so large your friend might just be unaware of it.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#133
post #2

I feel like someone should also give Zuckerberg the memo that it's only a matter of time before an insider also goes rogue and abuses data access (edit: or otherwise; see below). Facebook fundamentally seems to trust itself way too much, and it worries me that it thinks the only threats are external entities... to me, this is another silently ticking time bomb. EDIT: And don't forget that going rogue is just one scen…

"Our efforts to protect our company data or the information we receive may also be unsuccessful due to software bugs or other technical malfunctions, employee error or malfeasance , government surveillance, or other factors. "In addition, third parties may attempt to fraudulently induce employees or users to disclose information in order to gain access to our data or our users' data ." "Although we have developed sys…

Honestly that is all just legal boilerplate that could be found in the annual report of any public internet business.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#134
post #8

Zuckerberg should resign at this moment. Facebook needs new leadership if it wants to change the way it has been operating.

Nah. In a week all of this will be forgotten (do you still remember the helicopter in the river, and the bridge that collapsed?). You and me and a few more people will remember, but we all already know that everything that is posted privately on Facebook will be leaked sooner or later. I even expect to see a few angry post from people that decided to delete their account now, and when they tried to undelete the accou…

I don't think anybody expects this surge of anti-Facebook articles to continue indefinitely. Personally I'm just hoping that all of this makes people dislike the company just enough to shatter the illusion of usefulness. Plenty of people will still heavily use Facebook, but if we can pull even 5% of the technologically-aware, that's a smidgen of influence that Facebook no longer has and a chunk of people who no longer serve as lures for others to join.

It's not going to happen quickly, but if this awareness gains momentum a much more healthy (federated, preferably open source) social media site could have a higher chance of survival. I think that's worth something.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#135
post #58

Earlier quoted context omitted.

You request access, and justify it with something like "I need it to debug issue #123". Someone manually oks/disallows it, and there's asynchronous reviews of these requests to double check. My guess is the intern lied about what they're using it for. How else would you suggest to do privacy checks like these?

> You request access, and justify it with something like "I need it to debug issue #123". Someone manually oks/disallows it, and there's asynchronous reviews of these requests to double check. My guess is the intern lied about what they're using it for. OK so an insider can just lie and access whatever they want. Heck, they can even tell the truth! Just find a bug that's exhibited in a particular profile and use that…

Facebook's data is very different from Google's. At Facebook you might have a bug that's related to how many thousands of different objects (and their specific properties) interrelate. How could you safely mock that out?

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#136
post #106

Earlier quoted context omitted.

> With so much to lose and so little to gain internal leaks of this sort are extremely rare I recently downloaded my Facebook archive [1]. If it were legal, I would certainly pay thousands if not tens of thousands of dollars for certain peoples' archives. I can think of several practical contexts in which an unethical actor would find it profitable to pay a Facebook employee a million dollars for someone's Facebook a…

I would certainly pay thousands if not tens of thousands of dollars for certain peoples' archives Really? For what purpose?

> For what purpose?

On the upside, any case where one is engaging in high-value transactions (broadly speaking). Knowing a negotiating counterpart's likes, dislikes, communication style, et cetera can help one avoid mistakes, build a personal connection and draft (and frame) terms correctly on the first try.

More seedily, such information about a political opponent (whether a politician, rival on a commercial or non-profit board, or commercial competitor) is useful.

As a risk mitigation tool, such data would find a natural home in a due diligence file. Prospective executives, board members, business partners, political donation recipients, et cetera expose one to reputational risks. Catching those in advance is already worth tens of thousands of dollars of legal time.

I would hate to live in a country where the above is legal. We should recognize the value of the information every single single Facebook employee has routine access to.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#137
post #38
post #23

Earlier quoted context omitted.

shrug Without evidence we're both just guessing. Perhaps someone else will chime in with direct knowledge of how FB works.

Evidence suggests it wasn't true at the NSA five or so years back... It's _probably_ true that things in general have gotten better since then, and it's probably true that they're better at _some_ companies like Google, Facebook, and Amazon - but I'd tend to agree that it's very unlikely to be true for "most companies".

The Snowden case is an interesting example. He went out of his way to get access to information, going so far as to transfer into a role that had more access (I don’t recall all the details but I remember that much). Every company has some category of employee whose job it is to ensure enforcement of policies, for instance, and if these people set out to subvert the system you should expect them to be able to do so. The watching watchers onion does eventually run out of skin (and it’s not even that deep most places).

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#138
post #15

Earlier quoted context omitted.

It was true at Google. It's certainly true at financial institutions. I dunno about Amazon. I'm not sure what other comparisons would be relevant here. EDIT/NOTE: https://news.ycombinator.com/item?id=16675493

> It was true at Google. Yes, because Google is not your average company. It takes security extremely seriously... in fact it's about as awful of an example as you can give for a blanket statement you made about "most companies".

Internal abuse is a big area of effort for Facebook and google but things still go wrong. Here was googles moment for that back in 2010:

https://www.wired.com/2010/09/google-spy/

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#139
post #8

Zuckerberg should resign at this moment. Facebook needs new leadership if it wants to change the way it has been operating.

Nah. In a week all of this will be forgotten (do you still remember the helicopter in the river, and the bridge that collapsed?). You and me and a few more people will remember, but we all already know that everything that is posted privately on Facebook will be leaked sooner or later. I even expect to see a few angry post from people that decided to delete their account now, and when they tried to undelete the accou…

> In a week all of this will be forgotten

Nope -- there are political and legal proceedings underway, and those things take time. In a year? Maybe.

> Facebook can't recover it because it is deleted

"Deleted." It's easy for those people to fake up a new account, and remember the lessons they learned the last time around.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#140
post #60

Earlier quoted context omitted.

Yes, but you have to explicitly request data every time you access anything. IDK what it was like when you interned, but that's what it's like today.

was not the case when i was there, and it wasn't all that long ago

You and esman1 both could be right. I work at a company of similar size and sophistication as Facebook. Sometimes whether or not you have access to production data by default depends on which team you work for.
Post reply on HN