Live data from Hacker News

Facebook Says Hackers Stole Detailed Personal Data from 14M People

bloomberg.com

41–50 of 217 posts

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#41
post #18
post #9

Earlier quoted context omitted.

I doubt other payment or ecommerce platforms are any more secure. Given its size, I assume Facebook has a lot of smart people working on security. And they still screw it up. How are smaller platforms, who can't attract or pay for the very best talent, going to do any better (other than by being smaller targets, I guess)?

Visa and MasterCard seems to handle security ok.

Centrally, perhaps. As a payment "platform" (i.e. including the merchants, POS terminals, etc.) that is very much not the case.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#42
As with any breach it is always interesting to see how the scope gets broadened day by day. Tomorrow there might be some headline like "Hackers actually took all of your location data, a timestamp of every breath you took in the last week, and 4K video of everything you looked at through your eyes for the last ten years."

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#43
If Facebook could go back in time and choose between:

a) Paying out a $1m USD bug bounty, or

b) Accepting the reputational hit from a successful exploit

I wonder which they would choose with perfect hindsight?

Facebook runs a great bug bounty program, but given Facebook's size, data footprint, and profitability, perhaps it's worth increasing the rewards.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#44
post #21
post #11

I'm among the hacked people. I'm feeling so disappointed.

Don't feel bad... everyone, everywhere has been compromised. The corporations that say they have not are either ignorant or lying.

That's where I've ended up. I just assume that anything I enter on any website or app is potentially public. I've seen no real evidence that we as technologists and tech companies are able to do better.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#45
post #6

This is why I hate not having custom security questions from Banks. What is my fathers middle name? Well, if you have facebook and he puts it up there you can find out. I have no control over that. I could start using fake answers but trying to remember the fake answers vs real answers is tough. Whereas when I get a custom question I have a custom answer that I will always remember. Such as made up on the spot Name o…

I use random strings of length 32 for every security question. So it's like

Q: What's the name of your first pet?

A: pVp5TxN7htNC3B3Tae3RaPLndpLj5LeV

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#46

Earlier quoted context omitted.

Good point. Looking at my database it seems that most of the time I just choose fake answers, and sometimes use words that don't relate to the question (e.g., "Favorite food: Manchester").

I used to use real answers but then wised up and switched to random 16-character responses. I wish there was a way to find out which services I’m vulnerable on due to my stupidly using real data, without attempting to do a password reset on all of my online accounts.

> wised up and switched to random 16-character responses

As an earlier comment pointed out [1], random responses to security questions are a bad idea. I've personally tested this by entering a random security answer, calling the service, saying I forgot my password and entered gibberish as my security answer, and being let through. I presume technically-savvy people think this is more secure; if I can guess that, an attacker can too.

[1] https://news.ycombinator.com/item?id=18203907

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#47
post #3

Should it not be "Hackers Stole Detailed Personal Data of 14 Million People from Facebook" ?

Exactly. If it’s “hackers stole my data from [insert company here]” then it should really be my data. In which case, I want those companies to either delete it or pay me for it.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#48

If Facebook could go back in time and choose between: a) Paying out a $1m USD bug bounty, or b) Accepting the reputational hit from a successful exploit I wonder which they would choose with perfect hindsight? Facebook runs a great bug bounty program, but given Facebook's size, data footprint, and profitability, perhaps it's worth increasing the rewards.

Perhaps any vulnerability reported that can lead to the compromise of user data at a scale should be automatically paid out $1M.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#49

Earlier quoted context omitted.

> name, email address and phone number I kind of work on the assumption that those things are largely public. I mean, phone books were a thing for a very long time. Don't get me wrong, leak bad, very bad, but they didn't leak my bank accounts or a list of my worst fears.

Did you read the article? "For 14 million people, the attackers accessed the same two sets of information, as well as other details people had on their profiles. This included username, gender, locale/language, relationship status, religion, hometown, self-reported current city, birthdate, device types used to access Facebook, education, work, the last 10 places they checked into or were tagged in, website, people or…

FYI people will downvote you for suggesting someone hasn't read the post. (And I don't think it was necessary to make your point.)

HN guidelines:

https://news.ycombinator.com/newsguidelines.html

>Please don't insinuate that someone hasn't read an article.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#50
post #9

Earlier quoted context omitted.

I doubt other payment or ecommerce platforms are any more secure. Given its size, I assume Facebook has a lot of smart people working on security. And they still screw it up. How are smaller platforms, who can't attract or pay for the very best talent, going to do any better (other than by being smaller targets, I guess)?

> I assume Facebook has a lot of smart people working on security. I am not willing to roll the dice on that assumption.

I am. I know a bunch of them personally. They are definitely the some of the best security people I know. They just have a really hard problem to solve.

If you think about it, a breach of 30 million accounts out of 2 billion ain’t that bad.

Post reply on HN