Earlier quoted context omitted.
You request access, and justify it with something like "I need it to debug issue #123". Someone manually oks/disallows it, and there's asynchronous reviews of these requests to double check. My guess is the intern lied about what they're using it for. How else would you suggest to do privacy checks like these?
Would not be better to have a tool which automatically creates a/some profile/s similar to that/those the dev needs for debug purposes BUT filling it with fake data? So the bug is reproducible but the users data of them is not accessible to the dev
Zuckerberg Takes Steps to Calm Facebook Employees
181–190 of 274 posts
Re: Zuckerberg Takes Steps to Calm Facebook Employees
#182Earlier quoted context omitted.
Nah. In a week all of this will be forgotten (do you still remember the helicopter in the river, and the bridge that collapsed?). You and me and a few more people will remember, but we all already know that everything that is posted privately on Facebook will be leaked sooner or later. I even expect to see a few angry post from people that decided to delete their account now, and when they tried to undelete the accou…
> In a week all of this will be forgotten Nope -- there are political and legal proceedings underway, and those things take time. In a year? Maybe. > Facebook can't recover it because it is deleted "Deleted." It's easy for those people to fake up a new account, and remember the lessons they learned the last time around.
Ugh, so we're going to have the front page of HN dominated with the exact same "discussions" for another year?
Re: Zuckerberg Takes Steps to Calm Facebook Employees
#183Earlier quoted context omitted.
So, you don't know how google handles this, but you are suggesting everybody should do what google does. Are you trolling?
He is not trolling. His core point is that there is no sufficient amount of training, or expertise, or monitoring, or punishment, or trying harder the 17th time you've been caught. If you are leaving the decision up to enough/too many humans, then you are by definition providing inferior security. The real education from this story is far deeper than just Facebook. It is that Facebook employees, and Google employees,…
1. Accessing someone's data when it's not mission critical to your work means you're fired on the spot. This is drilled into new engineers over and over.
2. Privacy-related issues are escalated to the highest severity immediately (on par with data centers being down, etc.). I think the question in this whole debate is where you draw the line for this kind of issue, and what's an issue and what's a feature.
Re: Zuckerberg Takes Steps to Calm Facebook Employees
#184Earlier quoted context omitted.
As an ex-employee, I feel much more confident in Facebook's processes than the company you're describing. Facebook would have no problem terminating people who do what you're describing.
As an ex-employee could you please also confirm whether or not the average employee is able to access user data, and what kinds of permissions (if any) this requires?
Re: Zuckerberg Takes Steps to Calm Facebook Employees
#185Sounds like Facebook is having their NSA moment
can't wait for the next Snowden
Re: Zuckerberg Takes Steps to Calm Facebook Employees
#186Earlier quoted context omitted.
As an ex-employee could you please also confirm whether or not the average employee is able to access user data, and what kinds of permissions (if any) this requires?
Another ex-FB employee here. I can't believe this is even a thing people are wondering about. Of course not the average employee can't access user data, it's an immediate firing offense.
Ironically, you're undermining your own point. The fact that they would be fired afterwards in no way contradicts the notion that they could access such data, and in fact suggests they can (hence the firing policy).
Re: Zuckerberg Takes Steps to Calm Facebook Employees
#187Earlier quoted context omitted.
Cambridge Analytica’s actions had real world political consequences, so yes it’s political for that reason. But another angle of the CA portion of the story is that they were ratfucking in a very effective way—such as publishing fake news about BLM activists were organizing violent rallies, then broadcasting that to likely Trump voters. In some cases they even organized BLM events with incitement to commit violence,…
> If my news feed is tainted by a group like CA manipulating it at the algorithm level, what hope can I have that anything I’m receiving over the Internet isn’t compromised? Was it CA doing the manipulating, or was it Facebook? It's Facebook that runs Facebook...CA was merely taking advantage of Facebook to the fullest extent it could. I'm not saying what CA did was right, but your comment seems to suggest Facebook w…
Re: Zuckerberg Takes Steps to Calm Facebook Employees
#188Earlier quoted context omitted.
You request access, and justify it with something like "I need it to debug issue #123". Someone manually oks/disallows it, and there's asynchronous reviews of these requests to double check. My guess is the intern lied about what they're using it for. How else would you suggest to do privacy checks like these?
> You request access, and justify it with something like "I need it to debug issue #123". Someone manually oks/disallows it, and there's asynchronous reviews of these requests to double check. My guess is the intern lied about what they're using it for. OK so an insider can just lie and access whatever they want. Heck, they can even tell the truth! Just find a bug that's exhibited in a particular profile and use that…
Oh come on. You admit having no idea what Google does either, but surely that must be better than Facebook because you said so, until an FB insider replied and brought down your narrative.
Is it that hard to say "ok well, I stand corrected then" instead ?
Re: Zuckerberg Takes Steps to Calm Facebook Employees
#189Earlier quoted context omitted.
He is not trolling. His core point is that there is no sufficient amount of training, or expertise, or monitoring, or punishment, or trying harder the 17th time you've been caught. If you are leaving the decision up to enough/too many humans, then you are by definition providing inferior security. The real education from this story is far deeper than just Facebook. It is that Facebook employees, and Google employees,…
To be fair, at least at FB (I can't speak to Google or Apple or Amazon): 1. Accessing someone's data when it's not mission critical to your work means you're fired on the spot. This is drilled into new engineers over and over. 2. Privacy-related issues are escalated to the highest severity immediately (on par with data centers being down, etc.). I think the question in this whole debate is where you draw the line for…
This means they are capable of doing it and are merely punished afterwards, right? Not to mention that I would imagine getting fired in exchange for viewing private data could be quite a worthwhile 'transaction' for some people in some cases.
Re: Zuckerberg Takes Steps to Calm Facebook Employees
#190Earlier quoted context omitted.
He is not trolling. His core point is that there is no sufficient amount of training, or expertise, or monitoring, or punishment, or trying harder the 17th time you've been caught. If you are leaving the decision up to enough/too many humans, then you are by definition providing inferior security. The real education from this story is far deeper than just Facebook. It is that Facebook employees, and Google employees,…
Reminds me of an apocryphal story (can't find a reference but it appears to be reasonable): FCC was investigating the sale of illegal tv satellite descrambers when they confiscated a unit. Upon investigation, it was found to have been manufactured by IBM! Further investigation revealed it was manufactured at a secure IBM facility used for top-secret ("need-to-know", etc.) type projects. The manager responsible had sp…