Live data from Hacker News

Zuckerberg Takes Steps to Calm Facebook Employees

nytimes.com

241–250 of 274 posts

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#241
post #238

Earlier quoted context omitted.

> As for why no one is giving you a clear answer it is because there is no reason for anyone to tell some random person deep details about security policy and procedure. Where did I ask for "deep details about security policy and procedure"? > Want to know more? Too bad. No, but thanks. > There is some data that an average employee just cannot get to. "Some data" means nothing. I'm sure this is true in many, many com…

I think what you're asking for here you're never going to get. Nobody who works there currently will tell you because they'd get fired (and everyone has bills to pay). People who worked there in the past aren't going to tell you because #1) it's bad practice/bad op-sec/it's uncouth/whatever, #2) if they did it would negatively impact their future prospects and reputation. Nobody has any incentive to hand out definiti…

> Nobody has any incentive to hand out definitive numbers or break it down into "X-dev-team #1 has access to X, Y, and Z"

For goodness's sake, please stop these straw-man arguments. I said this above once, but it seems I have to say it again: nobody ever asked for that level of detail. People have been struggling with far more basic issues. No current or ex-employee or intern has even come along to try to say something simple like "as far as I know, the average Facebook intern simply cannot access private user data regardless of any business reasons"; indeed, we've gotten anecdotes that that the opposite has actually happened. How you suddenly deduce that I'm looking for specific descriptions of what teams can access what data is just beyond me.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#242

Earlier quoted context omitted.

i interned at fb a few years ago. any engineer, intern or not, can access production data. day one you set up an instance of fb on your dev server that you can mess around with, and its connected straight to the prod db. you're able to view anything you want, but they're very adamant that they monitor what you look at.

"its connected straight to the prod db" I can't believe what I am reading. Why is that? Why use customer data for dev purposes. Why not work on some mock data?

I ask out of curiosity. If you have a P1 escalation due to an issue that is reproducible only in production environment but not with your test environment with mock data, how do you plan to troubleshoot it?

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#243
post #238

Earlier quoted context omitted.

I think what you're asking for here you're never going to get. Nobody who works there currently will tell you because they'd get fired (and everyone has bills to pay). People who worked there in the past aren't going to tell you because #1) it's bad practice/bad op-sec/it's uncouth/whatever, #2) if they did it would negatively impact their future prospects and reputation. Nobody has any incentive to hand out definiti…

> Nobody has any incentive to hand out definitive numbers or break it down into "X-dev-team #1 has access to X, Y, and Z" For goodness's sake, please stop these straw-man arguments. I said this above once, but it seems I have to say it again: nobody ever asked for that level of detail. People have been struggling with far more basic issues. No current or ex-employee or intern has even come along to try to say somethi…

I suddenly deduced you were looking for specific descriptions a little ways up this comment tree where you asked the question: "As an ex-employee could you please also confirm whether or not the average employee is able to access user data, and what kinds of permissions (if any) this requires?"

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#244

Earlier quoted context omitted.

Yet another ex-FB here. When I was there I think it was possible for engineers to access pretty much anything programmatically, although the vast majority never have any reason to go near the systems that would allow them to do so. During onboarding we were basically told “If you look at any data that’s not yours, assume you will be fired”. Everything is logged, so if you might have looked at anything you shouldn’t h…

Thank you for the response. Question: if you (assumed average Facebook engineer for this discussion) observe a bug (normal severity, not something obviously critical and not something conversely trivial) with a particular profile that you cannot otherwise reproduce, and it is determined that addressing it would involve looking at the user's private data, then I assume that would be a valid business reason to do so. N…

FB’s internal security protocols are irrelevant.

The reality is that huge amounts of personal data were harvested by third parties through app permissions - apparently with FB’s knowledge and support.

No one needs back door hacks to get into a vault when the front door is wide open.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#245
post #243

Earlier quoted context omitted.

> Nobody has any incentive to hand out definitive numbers or break it down into "X-dev-team #1 has access to X, Y, and Z" For goodness's sake, please stop these straw-man arguments. I said this above once, but it seems I have to say it again: nobody ever asked for that level of detail. People have been struggling with far more basic issues. No current or ex-employee or intern has even come along to try to say somethi…

I suddenly deduced you were looking for specific descriptions a little ways up this comment tree where you asked the question: "As an ex-employee could you please also confirm whether or not the average employee is able to access user data, and what kinds of permissions (if any) this requires?"

> I suddenly deduced you were looking for specific descriptions a little ways up this comment tree where you asked the question: "As an ex-employee could you please also confirm whether or not the average employee is able to access user data, and what kinds of permissions (if any) this requires?"

That could be answered with something vague like "yes, this requires permissions from a small team of trusted individuals, which are granted only if the issue is severe/cannot otherwise get immediate attention/cannot be addressed by that team/etc., and it's never granted to most interns". No need for jumping to "X-dev-team #1 has access to X, Y, and Z".

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#246
post #243

Earlier quoted context omitted.

I suddenly deduced you were looking for specific descriptions a little ways up this comment tree where you asked the question: "As an ex-employee could you please also confirm whether or not the average employee is able to access user data, and what kinds of permissions (if any) this requires?"

> I suddenly deduced you were looking for specific descriptions a little ways up this comment tree where you asked the question: "As an ex-employee could you please also confirm whether or not the average employee is able to access user data, and what kinds of permissions (if any) this requires?" That could be answered with something vague like "yes, this requires permissions from a small team of trusted individuals,…

Really? That was a pretty specific question, and you were looking for (and would accept) a vague answer? It doesn't matter anyway, again, they have no incentive to tell you that. vague or not vague. Nobody that knows the answer to that question is dumb enough to answer that question (i would hope).

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#247
post #246

Earlier quoted context omitted.

> I suddenly deduced you were looking for specific descriptions a little ways up this comment tree where you asked the question: "As an ex-employee could you please also confirm whether or not the average employee is able to access user data, and what kinds of permissions (if any) this requires?" That could be answered with something vague like "yes, this requires permissions from a small team of trusted individuals,…

Really? That was a pretty specific question, and you were looking for (and would accept) a vague answer? It doesn't matter anyway, again, they have no incentive to tell you that. vague or not vague. Nobody that knows the answer to that question is dumb enough to answer that question (i would hope).

Yes, really. And I don't see why it would be dumb to answer that question, but no need to go on that tangent. If people can't respond then they can live with that being interpreted however it is.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#248

Earlier quoted context omitted.

Thank you for the response. Question: if you (assumed average Facebook engineer for this discussion) observe a bug (normal severity, not something obviously critical and not something conversely trivial) with a particular profile that you cannot otherwise reproduce, and it is determined that addressing it would involve looking at the user's private data, then I assume that would be a valid business reason to do so. N…

FB’s internal security protocols are irrelevant. The reality is that huge amounts of personal data were harvested by third parties through app permissions - apparently with FB’s knowledge and support. No one needs back door hacks to get into a vault when the front door is wide open.

Maybe it's irrelevant to you but I'm sure it's mighty relevant to some other users whether they are notified before employees dig into their private data to fix random bugs.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#249

Let's cut to the chase. Would you work for Facebook in your dream role, at industry leading pay. The answer, for most of us is an emphatic 'yes'

My dreams exclude anything with "Google", "Facebook" and "Uber". And if the role we talk about involves iOS, then Facebook is even less attractive, because imho their app is an example how not to do an iOS application.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#250

>> One of [the Facebook employees] said he had avoided a trip home to see his family last weekend because he did not want to answer questions about the company he worked for. Wow, some people/families are way too media-sensitive. It's just hypocrisy. Facebook is fundamentally the same company as it was last week, last year and 5 years ago. Everyone knew this, especially Facebook employees. Facebook today is mostly ma…

There's a big difference between a theoretical "Well technically they have all our data and they could share it with anyone and they could use it to target ads quite precisely"

In fact, that statement is true of the government as well. Most people just think it won't really happen, and if it does happen it'll be something fairly trivial like selling me shaving kits because I'm a man, and that my data isn't really all that revealing.

That is vastly different from:

"This specific data you gave facebook went to this specific company, in violation of facebook's own policies.

The breach of ToS wasn't followed up, and we have video of the CEO bragging about fake news, blackmail and honey traps.

This wasn't even a US company influencing the election.

Your data was directly used to campaign for someone you probably deeply oppose.

Not only that, but this specific targeting was probably highly important because we know the result of the election relied upon victories in specific states that are important to the electoral college whilst losing the popular vote.

It also turns out that what had seemed to be deep real organic discussion topics turned out to be targeted propaganda showing a scary ability to control the public discourse

Oh. And this is all carried out by a company whose CEO openly wants to run for political office and could use this to get himself elected next time."

Post reply on HN