Live data from Hacker News

Facebook Network Breach Impacts Up to 50M Users

nytimes.com

151–160 of 635 posts

Re: Facebook Network Breach Impacts Up to 50M Users

#151
Does anyone else get the feeling that maybe security just doesn't scale for sites like this?

You have facebook being this huge target for attacks and you combine that with 10,000 engineers with likely not a lot of security training.

Even a single point of failure could compromise the whole site, what are the chances that no one makes a mistake?

Its like the bigger your company grows while still having a single product, the higher the probability something like this happens...

Re: Facebook Network Breach Impacts Up to 50M Users

#152
post #52

Earlier quoted context omitted.

there is also prestige associated to big names like Facebook (and Google, Apple, etc)

> there is also prestige associated to big names I hate that this has happened. The Bay Area used to be a place where working for the big, shiny company that makes your parents happy wasn't prestigious. It was safe. But taking a risk and starting something new was admired. The present state of affairs reminds me of Wall Street.

There was always a level of prestige associated with certain companies even in the 80s and 90s, no?

The tech industry, despite its shortcomings, is vastly superior to Wall Street in that regard. It's still a meritocracy above all else.

Plenty of smart people break into tech after doing something else for a few years. If you want to go into investment banking, you better come from a consulting or have already been working in finance. Your only last bastion of hope is to get an MBA and then join the rat race.

Re: Facebook Network Breach Impacts Up to 50M Users

#153

Fun fact: https://newsroom.fb.com/news/2018/09/security-update/ was published at 16:42:44. https://www.nytimes.com/2018/09/28/technology/facebook-hack-... was published at 16:45:41. NYT writes fast :)

If the NY Times doesn't have Facebook corporate and PR infiltrated, then they aren't doing their job.

Re: Facebook Network Breach Impacts Up to 50M Users

#154

Earlier quoted context omitted.

This is a very short-sighted view. Yes it has some immediate benefit in terms of pay, but you have to consider the long-term societal tradeoff of not developing addictive mental candy for people or developing societally useful technologies (or vice-versa, as it now stands). We can focussed on getting paid a lot now, or improving the wealth of everyone and generative the value we can all enjoy later.

I agree with your premise, that many Facebook employeees would give society a better return on its investment if they were employed elsewhere, but that’s hardly Facebook’s fault.

I didn't pin the blame on them. I place it as a cultural issue.

Re: Facebook Network Breach Impacts Up to 50M Users

#155
post #67

Fun fact: https://newsroom.fb.com/news/2018/09/security-update/ was published at 16:42:44. https://www.nytimes.com/2018/09/28/technology/facebook-hack-... was published at 16:45:41. NYT writes fast :)

In the journalism world, pre-written articles are apparently quite common. I assume they had a boilerplate already for the next Facebook controversy, and just wrote 2-3 opening paragraphs that were relevant for this one. CNN many years ago accidentally left some of their pre-written obituaries for (living) world figures publically accessible. https://en.wikipedia.org/wiki/List_of_premature_obituaries#T...

In the journalism world, pre-written articles are apparently quite common.

Actually, not "common" at all.

Obituaries for famous people are often done in advance, since everyone dies. It used to be one of the things that young journalists/interns did to cut their teeth.

But not every company has a massive security breach, so this was not pre-written.

It's not uncommon for big companies to fax (yes, fax) bad news to news organizations a few hours or days before posting it on their own web sites.

In the past, there would be embargoes on the information, but in the case of bad news, those are routinely ignored.

Re: Facebook Network Breach Impacts Up to 50M Users

#156

Earlier quoted context omitted.

What you call being "excited about working at 12am" I call "accepting being a corporate slave".

I don't think you can so glibly dismiss enthusiasm as Stockholm syndrome. Passionate people push the world forward, and mocking passion is a recipe for mediocrity and stagnation.

> Passionate people push the world forward

we're talking about Facebook here

Re: Facebook Network Breach Impacts Up to 50M Users

#157
post #52

Earlier quoted context omitted.

there is also prestige associated to big names like Facebook (and Google, Apple, etc)

> there is also prestige associated to big names I hate that this has happened. The Bay Area used to be a place where working for the big, shiny company that makes your parents happy wasn't prestigious. It was safe. But taking a risk and starting something new was admired. The present state of affairs reminds me of Wall Street.

What happened was that VCs started sucking up all the equity and it became not worth it from a risk-reward perspective for most people to work at a startup. This, coupled with companies staying private longer meant that in the lat 5 years, you were better off working at G/FB than a small or mid-sized startup.

e.g https://www.slideshare.net/a16z/state-of-49390473/29-29Becau...

Re: Facebook Network Breach Impacts Up to 50M Users

#158

I wonder where the "50M users" estimate comes from. It seems like the feature that caused it, "View As", is probably available to more than that many people. Does this mean that they managed to trace the attacker capturing the access tokens of 50M users? Even allowing for the bug in the first place, it seems like exploiting it should be detected before 50M uses.

They have different versions of code base deployed to different areas of the world all the time. They can reduce the user base nuber based on where the code was deployed and how much is the usage

Re: Facebook Network Breach Impacts Up to 50M Users

#159
post #92

Earlier quoted context omitted.

...but it wasn't. Which is the point, no?

I don't think that matters. "I hate travelling by air because the plane can crash" is a true statement for many people... but statistically, that's not the method of transportation that kills people. The fact of the matter is... ACLs are hard to get right. It's even harder when you have various roles that can be checked against the ACL (logged in user, batch job, logged in user impersonating someone, etc.) . But in t…

> The fact of the matter is... ACLs are hard to get right

This sounds similar to different distros of linux. Some are security focused where nothing is allowed until it is explicitly allowed. Other distros try to be more "user-friendly" and pretty much everything is open.

Starting from a wide open starting point and then trying to batten down the hatches afterwards does seem to the harder way to do it, but that's exactly where FB is. They wanted everything open, and then had to decide to start limiting that data. FB was designed as a place to share info. If you posted it, you wanted to share it. I totally get that mentality. However, as devs, I can imagine that we have all built something that the end users use in a way not envisioned, and we've probably all had "you're holding it wrong" lines of thinking. Once you get to that point, you can alienate users by telling them to stop doing it that way or embrace what's happening, and then make it work for them. Seems like the perfect situation to where bugs can get introduced.

Re: Facebook Network Breach Impacts Up to 50M Users

#160

Earlier quoted context omitted.

> According to some in the US government, Facebook can change the result of an election, so I guess that would qualify Essential infrastructure describes "assets that are essential for the functioning of a society and economy" [1]. Not things that can cause a lot of damage. Bombers aren't essential infrastructure. Facebook is non-essential. [1] https://en.wikipedia.org/wiki/Critical_infrastructure

According to your linked article, it could be considered 'Critical.' Not sure how it doesn't fit under the 'telecommunications' umbrella. Subjectively I don't like facebook nor people's dependence on it to label it 'critical', but objectively I'm not sure the linked article supports those subjective inclinations. At the very least, it's certainly debatable that facebook could be considered Telecommunications infrastr…

But it's a self fulfilling prophecy. It's only "critical" because it exists. If we shutdown every Facebook server tomorrow and set fire to their data center, it would no longer exist. And therefore have no influence on much of anything.
Post reply on HN