Live data from Hacker News

Facebook Network Breach Impacts Up to 50M Users

nytimes.com

611–620 of 635 posts

Re: Facebook Network Breach Impacts Up to 50M Users

#611
post #504
post #306

Earlier quoted context omitted.

I think treating Facebook as a singular project is the bigger fallacy. What about those who argued for React to move to a more reasonable license? What about those who pushed for open sourcing code and hardware in the first place? Companies at the 25k+ employee size are complex, often internally-disagreeing enterprises. Code may be pure, but resource allocation (programmer time) is political. Of the recent Facebook n…

By your reasoning it would be a fallacy to call any large project unethical. I think that is clearly a fallacy. Nobody is arguing that every individual within Facebook is an unethical person. The argument is that the overall project is unethical and the ethical people within it should take that possibility seriously. For more philosophical background on this idea: https://m.youtube.com/watch?v=ToKcmnrE5oY

By my reasoning it would be a fallacy to assume that all the members of a large project are unethical, which is exactly what some in the comments are suggesting.

And is ridiculous, for anyone who's worked in the real world.

We all make ethical compromises, and have worked for companies that made ethical decisions we didn't agree with.

That was the crux of the Nuremberg Trials: what portion of an endeavor's ethical decisions can be assigned to an individual.

The answer was "more than none, but less than all."

Re: Facebook Network Breach Impacts Up to 50M Users

#612
post #281

Its sad that everytime there is a post about Facebook the comments are extremely toxic and negative, and don't really even discuss the article itself. I would argue that 80% of all tech companies are doing close to 0 in making the world a 'better place'.

Say, how much money can one make in astroturfing?

[deleted]

Re: Facebook Network Breach Impacts Up to 50M Users

#614

Earlier quoted context omitted.

Someday in the future the "Internet Morality Police" will flash their cryptographically signed badges stored on a blockchain

If you are serious, YC applications are still open.

Lol - it is the kind of thing they would waste their money on ;)

Re: Facebook Network Breach Impacts Up to 50M Users

#615

Excerpts from the press call transcript [1] by Guy Rosen explaining what lead to this breach being possible: > The first bug was that, when using the View As function to look at your profile as another person would, the video uploader shouldn’t have actually shown up at all. But in a very specific case, on certain types of posts that are encouraging people to post happy birthday greetings, it did show up. > The secon…

The "View as" feature has been the source of many security vulnerabilities. There was a time where you could read other peoples' chats using this feature.

Any link to this type of vulnerability? Sounds like a juicy read.

Re: Facebook Network Breach Impacts Up to 50M Users

#616

Excerpts from the press call transcript [1] by Guy Rosen explaining what lead to this breach being possible: > The first bug was that, when using the View As function to look at your profile as another person would, the video uploader shouldn’t have actually shown up at all. But in a very specific case, on certain types of posts that are encouraging people to post happy birthday greetings, it did show up. > The secon…

The "View as" feature has been the source of many security vulnerabilities. There was a time where you could read other peoples' chats using this feature.

It seems to warrant checking both the permissions of the true user and the view-as user. If either does not have permission, then the action should fail. Of course, lacking the middleware for this forces you to choose one or the other and hope you remember to check the remaining user in numerous pathways.

Re: Facebook Network Breach Impacts Up to 50M Users

#617

Earlier quoted context omitted.

Meanwhile I work for a major US IB. While I don't work on anything customer facing our internal SSO infrastructure basically consists of a single cookie that gets access to almost everything.. And its really not difficult to sniff one from another user (like say getting them to visit a link like http://mydesktop.companyname.com/.. ). Its so bad that for certain systems we check the origin of your connection and will…

Is the cookie not associated to a specific IP? SSO systems would normally flag the mismatch if you try to connect to a website and pass an SSO cookie issued for a different IP, so sniffing cookies wouldn’t help all that much.

In the mobile space the IP address changes all the time, isn't it?

Re: Facebook Network Breach Impacts Up to 50M Users

#618
post #434

Until they can provide some data that say the 50 million number is a fact, I don't believe it's that low. Every breach starts out on the low end, and miraculously ends up being double or triple as they do "more research" and the initial anger dies down.

I'm pretty sure they logged out more than <5% (90m of 2B) of their users, because of the people I talk to on a daily basis on Messenger like well over 2/3s got logged out. I could see if they meant 90m of American users or something.

I was logged out twice, once in the morning and again in the evening - I came back to this discussion to see if there was some explanation.

(No, it's not that it was just two devices - I had to log in four times just on my phone. Once for Messenger, once for FB itself; during each occurrence.)

Re: Facebook Network Breach Impacts Up to 50M Users

#619
post #452

Earlier quoted context omitted.

> So is working at Google, Amazon and probably 90% of the big corps of the world in many sectors While Google and Amazon both have their ethical problems and serious anti-trust issues, Facebook is in a league of its own. The complete, cavalier disregard for the consequences of its own actions as long as they get theirs is utterly unconscionable. Unlike Google or Amazon, they add nothing of real value to society to ba…

Facebook is just the first that stumbles over all the sh*t that they doing. Amazon with their slavery workforce isn't better and Google was pretty good as keeping everyone happy and creating services but they're as bad as everyone else. I think we will see Google running into similar problems soon. They have also the problem of not having enough guidance anymore, sergey and larry don't care at all and never really wa…

I'd class Google and Amazon as being analogous to an industry like coal, oil, or railroads back in the robber baron days. They bring horrible externalities and dodgy/corrupt influences on our politics, but we also need them to keep the modern world running and build the future. The problems with them are larger problems with how we manage our economy and our industrial and labor policies.

Facebook is more like Big Tobacco. They're purely malignant, continuing solely through adversarial relationships with their users meant to foster addiction or control the revenue streams of key industries like media and news. They're pirates. What benefits they provide, they have only ever made worse than other services and tools that predated them.

>but I'm also hoping that it breaks apart and we find a better way then invading peoples privacy to monetize platforms

Amen to that. Treating attention as a form of currency has been utterly corrosive to society.

Re: Facebook Network Breach Impacts Up to 50M Users

#620
post #538

Earlier quoted context omitted.

Dang, you're right and I'm sorry. I won't do it again and I'm gonna give myself a 24 cool-down period before I post on HN again (on any subject.) I let my passions get the better of me and I should have known better. Between you and me, I pulled a muscle in my neck/shoulder this morning and I've been in a devil of a mood all day. I'm not trying to make excuses, I shouldn't have taken out my bad mood here. Today's B.S…

It happens. I hope you feel better soon.

Cheers :)
Post reply on HN