Live data from Hacker News

Facebook Network Breach Impacts Up to 50M Users

nytimes.com

591–600 of 635 posts

Re: Facebook Network Breach Impacts Up to 50M Users

#591
post #408

Earlier quoted context omitted.

They've been showing me that banner for a while. In fact, they stopped showing it to me about a week ago. Are your sure it's related?

This is 100% the banner I have received. The call to action directs you to this page: https://www.facebook.com/help/2687943754764396?ref=comms Which is the issue at hand.

This banner is crazily insufficient. It disappears forever after you visit any other page, without you having to acknowledge its existence.

I just checked fb, and went quickly to my first notification. I didn't really register what the banner was until maybe a second after it loaded - at which point I had already clicked on my first notification. By that point, the banner is gone forever. I can't find any way to get it back.

It's so, so easy to miss this message.

Re: Facebook Network Breach Impacts Up to 50M Users

#592
post #586
post #560

Earlier quoted context omitted.

Would you feel the same way if this vulnerability was for, say, a major banking website?

I work for a major (by Norwegian standards) bank. This level of authentication integration trickery wouldn't be attempted by us. Mainly because we try hard to avoid serious technical debt (due to timeline/delivery pressure) in our security infrastructure. We occasionally take such shortcuts in places that are not mission-critical, but they are always considered carefully as the tradeoff that they are. I believe that…

Meanwhile I work for a major US IB. While I don't work on anything customer facing our internal SSO infrastructure basically consists of a single cookie that gets access to almost everything.. And its really not difficult to sniff one from another user (like say getting them to visit a link like http://mydesktop.companyname.com/..).

Its so bad that for certain systems we check the origin of your connection and will only trust you if you've come from the DMZ rather than internal.

Re: Facebook Network Breach Impacts Up to 50M Users

#593
post #491

Earlier quoted context omitted.

They're one of the few big names NOT on haveibeenpwned.com Have Amazon, Google, Twitter, Microsoft or Apple been on haveibeenpwned? That’s what I think of when I hear “big names”.

MS yes, via LinkedIn (at least)

Not the same.. that breach was way before the acquisition, you can't conclude from that breach that MS development or security practices were lacking ..

Re: Facebook Network Breach Impacts Up to 50M Users

#595

Earlier quoted context omitted.

I wonder if archive.org could actually store that much data.. and how long it would take to create a tar.xz of it.

What file systems would support a tar that big?

https://en.wikipedia.org/wiki/ZFS

Re: Facebook Network Breach Impacts Up to 50M Users

#596
post #383
post #333

What really freaks me out is the day Facebook die, what will happen to all of this data? If you heard about the NCIX story where they basically abandoned their servers filled with users data (over 13 years of data) and someone scooped them up and tried to resell them on the black market, one could think that a similar fate is possible. source : https://www.privacyfly.com/articles/ncix_breach/ Obviously if Facebook wa…

> What really freaks me out is the day Facebook die, what will happen to all of this data? Interestingly, Facebook owns your data. I believe if they wanted to, they could close the company tomorrow and put a facebook.tar.xz of everything they collected on archive.org or somewhere else.

No. You own your data stored at Facebook. Facebook just have license to use "as they wish" while respecting your privacy settings (i.e. uploading facebook.tax.xz is definitely not according to privacy settings of most people).

At least that written and TOS or so.

Re: Facebook Network Breach Impacts Up to 50M Users

#598

My mind has fashioned me to think that these leaks, so called, are planned. To why I think so, is simple. When you, as Facebook, sell user data to other companies/third parties/countries, then it is crime, or is subject to investigation when it is known. But these so called leaks, are deemed "we are sorry, we will fix it, but we are so sorry about the data". And that is it. No one is responsible. Now you have 50 mill…

I had the same feeling when Google accidentally gained access to medical records from the NHS. Everyone involved acknowledged they need to do better, yet no one ever suggested to delete the illegally obtained data.

https://www.telegraph.co.uk/technology/2017/07/03/googles-de...

Re: Facebook Network Breach Impacts Up to 50M Users

#599

Excerpts from the press call transcript [1] by Guy Rosen explaining what lead to this breach being possible: > The first bug was that, when using the View As function to look at your profile as another person would, the video uploader shouldn’t have actually shown up at all. But in a very specific case, on certain types of posts that are encouraging people to post happy birthday greetings, it did show up. > The secon…

How likely is it that the three bug combination could be discoverd without access to source code ?

Re: Facebook Network Breach Impacts Up to 50M Users

#600
post #271
post #234

Earlier quoted context omitted.

Many users are still going to use the same password for their FB account and email account. All the security in the world won't fix people.

Pervasive biometric security may be the next step. I know it's scary and could actually be abused but it also can generally increase the level of security for everyone.

Something like left eye iris scan for Google, right eye iris scan for FB, left index fingerprint for AWS?
Post reply on HN