Live data from Hacker News

Zuckerberg Takes Steps to Calm Facebook Employees

nytimes.com

211–220 of 274 posts

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#211

Earlier quoted context omitted.

Another ex-FB employee here. I can't believe this is even a thing people are wondering about. Of course not the average employee can't access user data, it's an immediate firing offense.

> Another ex-FB employee here. I can't believe this is even a thing people are wondering about. Of course not the average employee can't access user data, it's an immediate firing offense. Ironically, you're undermining your own point. The fact that they would be fired afterwards in no way contradicts the notion that they could access such data, and in fact suggests they can (hence the firing policy).

Yet another ex-FB here. When I was there I think it was possible for engineers to access pretty much anything programmatically, although the vast majority never have any reason to go near the systems that would allow them to do so. During onboarding we were basically told “If you look at any data that’s not yours, assume you will be fired”.

Everything is logged, so if you might have looked at anything you shouldn’t have, it’s flagged and you’re audited; if you didn’t have permission (from a user and/or manager) and a valid business reason, then (we were told during onboarding) you’re likely to be fired and possibly sued.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#212

Earlier quoted context omitted.

Their business model does not rely on third parties accessing private user information.

Agreed, it's quite the opposite in fact : their business model relies on jealously guarding private user information to remain the only entity in the world who can sell highly-targeted ads

How do you sell highly targeted ads without revealing your data? How did the Obama campaign download the entire U.S. social graph in 2012, and brag about doing so, with Facebook’s approval? How did Cambridge Analytica do a comparable thing in 2016?

Facebook doesn’t sound that jealous to me.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#213

Earlier quoted context omitted.

> It was true at Google. Yes, because Google is not your average company. It takes security extremely seriously... in fact it's about as awful of an example as you can give for a blanket statement you made about "most companies".

> Google is not your average company. It takes security extremely seriously While this is certainly true, you've admitted elsewhere not knowing anything specifically about either Google or Facebook's security process, so how can you compare them ? You seem to just "know" Facebook doesn't take security seriously (which is of course a ludicrous thing to say)

> While this is certainly true, you've admitted elsewhere not knowing anything specifically about either Google or Facebook's security process

You already misquoted me once and I already replied to you. Why do you ignore it and do it again? Like I said: no, I never "admitted elsewhere not knowing anything specifically about either Google or Facebook's security process". You are misquoting me again just like you already did in [1], and it's quite improper that you choose to do this when I have already responded to you and called out your misrepresentation there. If you are looking for a response, see that post. If you are not, then please stop.

[1] https://news.ycombinator.com/item?id=16676704

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#214

"KW: Mark, can you give us a sense of the timing and cost for this? Like, the audits that you're talking about. Is there any sense of how quickly you could do it and what kind of cost it would be to the company? I think it depends on what we find. But we're going to be investigating and reviewing tens of thousands of apps from before 2014 , and assuming that there's some suspicious activity we're probably going to be…

And even if anyone ever considers it "complete," the reality is, that it's just going to be white wash and bullshit.

Why waste the fucking money. Quit being sentimental. Just trash Facebook and pivot (lol pivot). Be a real motherfucker, and let Facebook burn. Make something cooler than Facebook. Fuck this audit stupidity.

Come on, man.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#215
post #5

Earlier quoted context omitted.

You'd think so, but most companies have pretty strict internal controls for this sort of thing. Access is also carefully logged so a leaker is pretty much guaranteed to get caught at which point they'd immediately lose their job and likely face criminal prosecution. With so much to lose and so little to gain internal leaks of this sort are extremely rare.

Who watches the watchers? #1 - There's always a back door. I did some medical records stuff for a while. I looked myself up, just to confirm for myself how trivial it was to do. Yup, there I was. Which is why I insist that all data at rest is encrypted. (I have yet to win this argument.) #2 - Our "portal" product had access logs for auditing. Plus permissions, consent trees, delegation. The usual features. Alas. We a…

Facebook has a long history of employees doing sketchy shit like peeking at the profile/timeline of the new SO for their former SO. This has been one of the top threat scenarios internally for more than a decade and they have built significant security infrastructure to protect against this sort of problem. Yes, there is 'always a back door', but that back door has gotten smaller and much harder to find over the years. It is always a possibility, and while the system will prevent attempts to exfil large chunks of data for smaller breaches like this the audits/alarms will probably take a day or so before you are sitting in someone's office with HR present to have a discussion regarding your user data access patterns. So compromise the security infra you say? Yeah, there are other systems watching for that too...

-Former custodiet of the custodes

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#216
post #180
post #118

Earlier quoted context omitted.

He is not trolling. His core point is that there is no sufficient amount of training, or expertise, or monitoring, or punishment, or trying harder the 17th time you've been caught. If you are leaving the decision up to enough/too many humans, then you are by definition providing inferior security. The real education from this story is far deeper than just Facebook. It is that Facebook employees, and Google employees,…

Reminds me of an apocryphal story (can't find a reference but it appears to be reasonable): FCC was investigating the sale of illegal tv satellite descrambers when they confiscated a unit. Upon investigation, it was found to have been manufactured by IBM! Further investigation revealed it was manufactured at a secure IBM facility used for top-secret ("need-to-know", etc.) type projects. The manager responsible had sp…

On an only slightly different topic, about 15 years ago, there was a pretty healthy community of people distributing the circuit boards and accompanying software to program DirectTV smart cards. These would unlock all of the channels that "Dave was already beaming at everyone's house anyway", according to the in group parlance used to absolve oneself of such things.

A decent part of that conversation seemed to center around how it seemed highly unlikely that the whole hack was even possible without insider information leading to the development of the tool in the first place.

Fifteen years later, knowing what hacks have been at least claimed to have been pulled off through social engineering, I think the more important take away is that we need to stop portraying the worst case of hacking as a masked man executing some bond villain style hack, because it is fundamentally recommending a terrible heuristic. It by definition casts aside all of the incompetence that is equally likely to cause harm, and in the case of sheer volume, the far more likely scenario to occur.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#217

Earlier quoted context omitted.

Are you genuinely asking a question you would like to know the truthful answer to, or are you just interested in confirming the strong preexisting bias on display in each of your comments on this story ? You asked about the "average employee" having access to user data, and the answer is unequivocally "no", with both technical and disciplinary safeguards. There are only a few roles (moderation) who can access the rel…

No, I'm interested in knowing the truthful answer. It's just that I've received plenty of seemingly truthful responses (both here and elsewhere, e.g. [1]) that seem quite consistent with the notion that an average-employee(-turned-malicious) would be capable of accessing user data, punishments and all notwithstanding. > You asked about the "average employee" having access to user data, and the answer is unequivocally…

Regarding your question about a dev setting up a test server and accessing live data, that hole has been closed for years. There is some data that an average employee just cannot get to. For some data a dev can access it but the pattern of access and amount of data accessed will be audited and anomalies will raise an alarm.

As for why no one is giving you a clear answer it is because there is no reason for anyone to tell some random person deep details about security policy and procedure. The people building the internal controls and defenses are smarter than you, they know what needs to be protected and are rather devious about thinking up attack scenarios and possible paths of compromise, and eventually get tired of repeating the same answers. Want to know more? Too bad.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#218
post #2

I feel like someone should also give Zuckerberg the memo that it's only a matter of time before an insider also goes rogue and abuses data access (edit: or otherwise; see below). Facebook fundamentally seems to trust itself way too much, and it worries me that it thinks the only threats are external entities... to me, this is another silently ticking time bomb. EDIT: And don't forget that going rogue is just one scen…

"Our efforts to protect our company data or the information we receive may also be unsuccessful due to software bugs or other technical malfunctions, employee error or malfeasance , government surveillance, or other factors. "In addition, third parties may attempt to fraudulently induce employees or users to disclose information in order to gain access to our data or our users' data ." "Although we have developed sys…

To anyone who actually reads annual reports on a regular basis, this is a copy/paste for basically every single tech company, on every year's annual report

There's like 50 pages of this stuff that covers literally every possible scenario in case of legal liabilities. Has no meaning whatsoever

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#219
post #217

Earlier quoted context omitted.

No, I'm interested in knowing the truthful answer. It's just that I've received plenty of seemingly truthful responses (both here and elsewhere, e.g. [1]) that seem quite consistent with the notion that an average-employee(-turned-malicious) would be capable of accessing user data, punishments and all notwithstanding. > You asked about the "average employee" having access to user data, and the answer is unequivocally…

Regarding your question about a dev setting up a test server and accessing live data, that hole has been closed for years. There is some data that an average employee just cannot get to. For some data a dev can access it but the pattern of access and amount of data accessed will be audited and anomalies will raise an alarm. As for why no one is giving you a clear answer it is because there is no reason for anyone to…

> As for why no one is giving you a clear answer it is because there is no reason for anyone to tell some random person deep details about security policy and procedure.

Where did I ask for "deep details about security policy and procedure"?

> Want to know more? Too bad.

No, but thanks.

> There is some data that an average employee just cannot get to.

"Some data" means nothing. I'm sure this is true in many, many companies, ranging from the most competent to the most incompetent.

> For some data a dev can access it but the pattern of access and amount of data accessed will be audited and anomalies will raise an alarm.

This is yet again consistent with what I've said.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#220

Earlier quoted context omitted.

As an ex-employee, I feel much more confident in Facebook's processes than the company you're describing. Facebook would have no problem terminating people who do what you're describing.

Imagine you are the Egyptian government. You want to squash a social media fueled rebellion, lead by some anonymous person. How hard is it to get one of your bright and loyal minds hired by Facebook? How much data could such a person exfiltrate before getting fired? The 'We will log your access and fire you' line of defense prevents nothing from someone who only has a job for the purpose of moving data out.

They don’t fire you, they arrest you. And then they find out who you work for.
Post reply on HN