Live data from Hacker News

Facebook Network Breach Impacts Up to 50M Users

nytimes.com

181–190 of 635 posts

Re: Facebook Network Breach Impacts Up to 50M Users

#181

Earlier quoted context omitted.

I doubt it. The "View As" feature does not require the target to be currently logged in to Facebook AFAIK.

This is an interesting point. Right now, I can't reconcile the "we canceled active sessions thus logging people out" as a fix with the fact that "View As" was the attack vector.

I'm guessing they invalidated all access tokens for accounts that have been used as "View As" targets since the issue was introduced.

They also disabled "View As" which is the actual fix for the time being.

Re: Facebook Network Breach Impacts Up to 50M Users

#182

My mind has fashioned me to think that these leaks, so called, are planned. To why I think so, is simple. When you, as Facebook, sell user data to other companies/third parties/countries, then it is crime, or is subject to investigation when it is known. But these so called leaks, are deemed "we are sorry, we will fix it, but we are so sorry about the data". And that is it. No one is responsible. Now you have 50 mill…

Wild speculation. Any evidence?

I don't think there has been much stopping these companies selling the data up to this point. That's been the issue with Facebook and others, they have happily sold peoples data with little legal protection for the people whose data they sell. There is no crime in just selling the data within the US so your theory doesn't hold up.

Never attribute to conspiracy that which is adequately explained by incompetence.

Re: Facebook Network Breach Impacts Up to 50M Users

#185
post #59
post #45

So here is a question: my girlfriend only uses FB on her laptop, and always logs out when she's done. I usually make fun of her for doing this. But does this mean most of the time that there was no active access token and she is mostly safe? (Excluding the windows of time where she was actively using FB) Do I have to take back all of my teasing?

Only if the act of logging out explicitly invalidates the token on the server side

This is something I would suspect doesn't actually happen. FB wants to track all of the user's browsing habits, so maybe they just make the actual FB UI look logged out? Security-wise, it would seem to be more complicated by their desire to never let a user be logged out, and looks like it's complicated enough it is biting them in the backside. Oops?!

Re: Facebook Network Breach Impacts Up to 50M Users

#186
post #103

Earlier quoted context omitted.

Is Facebook now considered critical infrastructure?

The "surface" of Facebook may not be, but the parts of it that keep "personal information" certainly are, due to the scope of what can happen if it leaks.

What exactly would happen?

Edit: people take my comment to mean it won't be a big deal. It will be. However, not on the same scale of taking out the power grid, or the water system, which would lead to hundreds or thousands of deaths. Facebook is not critical infrastructure.

Re: Facebook Network Breach Impacts Up to 50M Users

#187

Earlier quoted context omitted.

On the flip side celebrating a culture where (allegedly) people are expected to toss out their personal lives and time (what is sometimes referred to as passion in some circles) is a race to the bottom. It means colleagues who DON'T do this are punished or replaced. Perhaps that's what you refer to as mediocrity, the unwillingness to put in long workdays that extend into night.

Do you think that I should be forced not to code after a certain time of day? I wouldn't work at a company that imposed this restriction.

I work at a company like this.

In fact, I need permission from my manager's manager's manager in order to stay past 7pm.

This company believes in a strong work-life balance, and this is one of the ways it achieves this.

Also, it "changes the world" in good ways, not by "connecting people" through bogus data siphoning addiction traps.

Re: Facebook Network Breach Impacts Up to 50M Users

#189

Earlier quoted context omitted.

Is Facebook now considered critical infrastructure?

If everything facebook knows about all its users and their contacts who are not themselves facebook users becomes public, people will get hurt.

You're absolutely, completely, 100% correct. Facebook holds an immense trove of private information that in the wrong hands could be leveraged to inflict unimaginable pain and suffering.

With that said, is it perhaps possible that some people might view this as subtly distinct from power plants, hospitals, roads, and ISPs? Those are what are generally considered "critical infrastructure".

Post reply on HN