Live data from Hacker News

Facebook Network Breach Impacts Up to 50M Users

nytimes.com

561–570 of 635 posts

Re: Facebook Network Breach Impacts Up to 50M Users

#561

Earlier quoted context omitted.

Trading anecdotes, I have a number of friends at Facebook (both at Menlo Park and the NYC office), and they complain about the opposite: lots of people just coasting and doing the minimum needed to get by, really hard to fire people, etc.

This is part of why I left last year so... too true.

This is seemingly the case in a lot of places.

Unfortunately the number of lazy people far outweigh the number of hard workers.

Re: Facebook Network Breach Impacts Up to 50M Users

#562
post #560
post #550

Earlier quoted context omitted.

Technical debt, multiple systems using multiple old authentication routines getting slowly upgraded to new auth methods. And no one taking the time to fully understand the ramifications. And honestly it seems like that was the right choice for the teams responsible. They all made tons of money delivered features and now years later a bug is found.

Would you feel the same way if this vulnerability was for, say, a major banking website?

Ha, major banking website won't do any improvement. Can't have enhancement vulnerability if there are no enhancement we smart.

Re: Facebook Network Breach Impacts Up to 50M Users

#563
post #281

Its sad that everytime there is a post about Facebook the comments are extremely toxic and negative, and don't really even discuss the article itself. I would argue that 80% of all tech companies are doing close to 0 in making the world a 'better place'.

I wouldn't call this toxic in the least. There is no name calling or childish behavior. I would just call it debating. I have a coworker that is jealous of me and my boss because we go at it, but we both know it isn't personal. It is about making the right call on a project. We each think we are right and just trying to make our point So I think this thread is just more intense but there is no ill will

I find it ironic that you agree with yourself that you are a good guy (which I am not saying you are not).

Re: Facebook Network Breach Impacts Up to 50M Users

#565

Earlier quoted context omitted.

Why the downvotes ? This is important data, and no one gave this information in the whole thread.

Probably because it's entirely anecdotal and attempts to extrapolate from such a small sample size.

It's more a problem of a biased sample than a small sample - this attack spread through the friend network, and so if one of your Facebook friends is in the attacked/vulnerable group then other ones are also likely to be.

Re: Facebook Network Breach Impacts Up to 50M Users

#566

Earlier quoted context omitted.

"NYT writes fast :)" Facebook wrote it. They called their friend at NYT and handed over the article - then mentioned they would be sharing it with other outlets later. [just my guess].

That's a serious ethical accusation to make against a journalist. Make it if you have evidence, but not reasoning from first principles.

They wrote it in 3 minutes, are you seriously saying first principles are not sufficient here?

Re: Facebook Network Breach Impacts Up to 50M Users

#567
post #434

Until they can provide some data that say the 50 million number is a fact, I don't believe it's that low. Every breach starts out on the low end, and miraculously ends up being double or triple as they do "more research" and the initial anger dies down.

I'm pretty sure they logged out more than <5% (90m of 2B) of their users, because of the people I talk to on a daily basis on Messenger like well over 2/3s got logged out. I could see if they meant 90m of American users or something.

Also if the tokens can be used for 3rd party “Sign in through Facebook” authentication this just compromised millions of people’s entire digital identities for everything from dating sites to financial logins.

Re: Facebook Network Breach Impacts Up to 50M Users

#568
post #549

Earlier quoted context omitted.

If you're more interested in tech discussion or maybe some subcultures, and less interested in food photos/anecdotes about babies, just join http://mastodon.social/ already. Set your preferences to show posts of your native language only, start poking around the timelines, and follow people who post something interesting. Follow, boost, reply, it only takes a few days before you have plenty of interesting content in…

> Probably less chance you get caught up in any kind of breach -- it's too obscure to be a target, plus the code is open source so many eyes on it, etc. Security through obscurity... Open source != secure. I can guarantee that a hell of a lot more folks with a lot of security expertise have combed through the fb codebase than Mastodon.

>Security through obscurity...

...is not a solution by itself but is a perfectly valid part of a defense in depth strategy, for example running SSH on a port other than the default is a common and good practice.

> I can guarantee that a hell of a lot more folks with a lot of security expertise have combed through the fb codebase than Mastodon.

This is the same argument Microsoft always made in defense of Windows security back in the XP era. "We hire the best experts in the world so Windows must be fantastically secure." And Windows security turned out to be a train wreck. Now in Microsoft's defense it has improved considerably over the years, but Windows desktops still get owned far more often than Linux desktops do, for a reason that would probably apply to Mastodon today as well: not that many people use it, so it is not nearly as common a target for exploits.

I don't think I deserved downvotes for making these points btw, that button is way overused on HN.

Re: Facebook Network Breach Impacts Up to 50M Users

#569
post #198

Earlier quoted context omitted.

React + GraphQL Where B is the sum of the set consisting of: -Breaking democracy in the US and the UK by being _the_ platform for disinformation. -Disinformation assisting genocide in Myanmar. -Use correlating strongly with poor mental health -Manipulating behaviour to encourage poor attention spans for the sake of ad-clicking -Constantly violating basic standards of privacy -(I could go on..) Oh wait, excuse my arit…

I think the sadder part of this argument is that nobody outside of software engineers know or care what GraphQL is, yet it’s being touted as a “societal benefit”. How about the fact that my grandma with limited mobility can still attend church virtually through the Live feature? Regardless of how often the scions of the Valley disavow their own technology (I would /never/ let my children use our products!), there are…

This argument I agree is far more compelling than "reductio ad JS library"

Re: Facebook Network Breach Impacts Up to 50M Users

#570
The second bug was that this video uploader incorrectly used the single signon functionally, and it generated an access token that had the permissions of the Facebook mobile app. And that’s not the way the single sign-on functionality is intended to be used. Is it just me or does this sound like an terrible idea in the first place? Guess we can't know for sure, but why would anything unrelated to authentication generate access tokens?
Post reply on HN