Live data from Hacker News

Zuckerberg Takes Steps to Calm Facebook Employees

nytimes.com

251–260 of 274 posts

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#251

Earlier quoted context omitted.

> Google is not your average company. It takes security extremely seriously While this is certainly true, you've admitted elsewhere not knowing anything specifically about either Google or Facebook's security process, so how can you compare them ? You seem to just "know" Facebook doesn't take security seriously (which is of course a ludicrous thing to say)

> While this is certainly true, you've admitted elsewhere not knowing anything specifically about either Google or Facebook's security process You already misquoted me once and I already replied to you. Why do you ignore it and do it again ? Like I said: no, I never "admitted elsewhere not knowing anything specifically about either Google or Facebook's security process" . You are misquoting me again just like you alr…

I am most definitely not misrepresenting you.

People like me or [1] have called you out because you keep contrasting Google and Facebook's internal security processes for no good reason, making definitive assertions like "[Google] takes security very seriously" [2], suggesting that Facebook doesn't and should do "Whatever Google does" [3]. And you're doing this not based on any specific knowledge of what the internal security process looks like at either company, but on your (flawed) perception of what engineering interns might or might not be able to do.

When people like esman1 who actually have that knowledge and context, volunteer to explain to you [4] some of the safeguards in place (and he told you the truth), instead of taking the point, you won't have any of what he says and keep going at it stubbornly.

I think this is the point where reasonable people stop arguing, and anyone else who cares can check your comments in this thread and make their own opinion.

[1] https://news.ycombinator.com/item?id=16675843 [2] https://news.ycombinator.com/item?id=16675508 [3] https://news.ycombinator.com/item?id=16675707 [4] https://news.ycombinator.com/item?id=16675670

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#252
post #66

Earlier quoted context omitted.

Former Googler here. I'm pretty sure the vast majority of Googlers understand they work for an advertising company with a gigantic and generally well-run software "engineering" department. I don't mean that in any derogatory sense. Well-regulated advertising is important in helping consumers make informed purchasing decisions.

>Well-regulated advertising is important in helping consumers make informed purchasing decisions. Do you think the adtech industy is "well-regulated"?

I think most consumer electronics are advertised reasonably, and it's fairly easy for consumers to evaluate advertising claims there.

On the other hand, health products / dietary supplements seem woefully under-regulated, especially since the layperson seems to have great difficulty in evaluating health claims. It seems crazy that dietary supplement and drug advertising are treated so very differently.

So, I think in some areas we need better advertising regulation, but not across the board.

More importantly, my point is that I'm not holding my nose up at my former colleagues. Without the second half of my post, the first half could be read as having a very judgemental tone.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#253

Can someone explain to me why the Cambridge Analytica story is making people so much angrier than the later revelation that Facebook was scraping call+text info? That seems to be the larger problem to me. Somewhere at Facebook there is a team of people who wrote software to scrape, store and analyze the personal call+text data that users didn't explicitly mean to give to Facebook. The data that Cambridge Analytica at…

Can someone explain to me why the Cambridge Analytica story is making people so much angrier than the later revelation that Facebook was scraping call+text info?

The lie that facebook (and the like) are sold on is that there are zero possible negative ramifications of giving Facebook that data. Of course that's not true. But something has caught people's attention and they're waking up to it.

Now is the time to tell them all the other reasons to not trust facebook. Loudly scratching your head about why people care about Cambridge Analytica is to miss the opportunity you have.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#254
post #55
post #40

I respect Facebook and their engineering chops as much as the next person, they are truly world class programmers, but how the holy hell is everyone daydreaming that they don’t work for an advertising company? You sell and use people’s data to get money: this is the business plan. Full stop. Connecting people can definitely be lucrative and useful in other ways but facebooks particular implementation is impression ba…

The money probably helps, especially given the Bay Area cost-of-living. The FB employees I've met have been fine with explaining away the consequences of their actions with "oh it's just a job", "that's not my team", or "the technology is really interesting". And as an idealist, I'll invoke Goodwin's Law depending on our relationship.

“Hans, are we the baddies?” https://www.youtube.com/watch?v=hn1VxaMEjRU

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#256
post #129

Earlier quoted context omitted.

HITRUST CSF is a framework for auditably proving HIPPA compliance. It prescribes controls such as encrypting data at rest. If you have a business relationship with a company which provides you PHI without explicit user consent you must have an agreement (a BAA) with the third party which puts them under the same requirements (backed up with third party audits). Everything you’re describing sounds like it’s either inc…

I've worked in health care a couple of times now. And while the companies I've worked for have gone well beyond the minimum required for legal compliance, the scary bit really is the sorts of things you could, if you were lazy enough, do and still legally be compliant.

Yeah, HIPPA has some holes you could drive a truck through. I also hate OAuth (so much focus on access, so little focus on what gets done with that access).

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#257
post #231

Honestly, I am not very worried about rouge data analytic companies or Russian trolls on facebook. I am worried that questionable semi-private German entity can block me (e.g. 30 days ban) on facebook at will. I am an US citizen and don't live in Germany. This is outrageous.

Whatabout a semi-private German entity?

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#258

Earlier quoted context omitted.

As an ex-employee could you please also confirm whether or not the average employee is able to access user data, and what kinds of permissions (if any) this requires?

Another ex-FB employee here. I can't believe this is even a thing people are wondering about. Of course not the average employee can't access user data, it's an immediate firing offense.

I've read that, for a time, "view anyone's profile" was an advertised perk of being a Facebook employee (maybe just a wink-wink, nudge-nudge thing in an interview, I have no firsthand experience). I'm sure they don't do that anymore, but how much have they really tightened up the ship after having a culture like that?

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#259
post #129

Earlier quoted context omitted.

Who watches the watchers? #1 - There's always a back door. I did some medical records stuff for a while. I looked myself up, just to confirm for myself how trivial it was to do. Yup, there I was. Which is why I insist that all data at rest is encrypted. (I have yet to win this argument.) #2 - Our "portal" product had access logs for auditing. Plus permissions, consent trees, delegation. The usual features. Alas. We a…

HITRUST CSF is a framework for auditably proving HIPPA compliance. It prescribes controls such as encrypting data at rest. If you have a business relationship with a company which provides you PHI without explicit user consent you must have an agreement (a BAA) with the third party which puts them under the same requirements (backed up with third party audits). Everything you’re describing sounds like it’s either inc…

Uh huh. We were the first to market with portable electronic medical records. "Fly by night." Sounds about right.

In the USA, there is no way to encrypt medical records at rest and permit data interchange. Because in the USA we do not have universal MRNs (PIDs, GUIDs, whatever). Meaning that if demographic data is encrypted, the system cannot match records across org boundaries, meaning care providers aren't 100% sure they have the correct medical history for the patient, meaning prescription errors, cutting off the wrong arm, misdiagnosis, etc.

Some enclaves like Medicare and VA can encrypt their own data for their own usage, but that protection is moot the moment data is shared with other orgs. It's been a while since I've checked, but I doubt they do encrypt, because that's a bottom up design decision.

Re: Zuckerberg Takes Steps to Calm Facebook Employees

#260

Earlier quoted context omitted.

Who watches the watchers? #1 - There's always a back door. I did some medical records stuff for a while. I looked myself up, just to confirm for myself how trivial it was to do. Yup, there I was. Which is why I insist that all data at rest is encrypted. (I have yet to win this argument.) #2 - Our "portal" product had access logs for auditing. Plus permissions, consent trees, delegation. The usual features. Alas. We a…

As an ex-employee, I feel much more confident in Facebook's processes than the company you're describing. Facebook would have no problem terminating people who do what you're describing.

If data at rest is unencrypted, I don't believe you. Sorry. Someone, somewhere is peeking at the naughty bits.

This is the best resource I've found for protecting such things:

Translucent Databases: Confusion, Misdirection, Randomness, Sharing, Authentication And Steganography To Defend Privacy http://a.co/eLgQACC

Maybe differential privacy stuff will supersede, compliment these techniques. I'm keeping an open mind.

Post reply on HN