Live data from Hacker News

Facebook Says Hackers Stole Detailed Personal Data from 14M People

bloomberg.com

161–170 of 217 posts

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#161

Facebook posting: https://newsroom.fb.com/news/2018/10/update-on-security-issu... Check if you are affected here: https://www.facebook.com/help/securitynotice (posting because it took 10+ mins to find it - many media outlets are not linking directly to it)

How do I check if I've deleted Facebook?

Does deleting Facebook mean I no longer have a right to know if my data was breached while I was a member?

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#162
post #135

I'm one of the unlucky 400,000 who had the most information stolen. Complete notification: Is my Facebook account impacted by this security issue? Yes. Based on what we've learned so far in our investigation, attackers accessed the following Facebook account information: * Name. * Primary email address. * Most recently added phone number. Additionally, the attackers also accessed other account information, including:…

> The 15 most recent searches you've entered into the Facebook search bar.

I can see how the attacker can use this to blackmail somebody.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#163

If I type my full name on google, I can find my home and cell phone number, age, all family members, home address, my last home address, and my google + (fb and LinkedIn I changed settings so not searchable). And it’s a pain to ask them to delete the info. It’s obscure and time consuming and no guarantees. That in my mind is worse than anything here. I didn’t allow that info to be public, we need more privacy laws.

1. The problem isn't Google. It's those companies that make your details available on internet.

2. Your personal data is already collected meticulously by companies like Acxiom and Equifax for anyone who is ready to pay. You would be amazed how much information they have on you already. What are you going to do about it?

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#164
post #134

Earlier quoted context omitted.

Well, let's see. A feature used to view profile information had a vulnerability that allowed an attacker to get my phone number. My phone number isn't even listed on my profile. This means the credentials from the original implementation of said feature weren't locked down to only data available from your viewable profile. While my phone number may be available elsewhere outside of FB, I only have it tied to my accou…

> This means the credentials from the original implementation of said feature weren't locked down to only data available from your viewable profile. Yeah, that's the entire security incident. So are you saying you expect software companies to never have security incidents? Now that's ridiculous.

Why is that ridiculous?

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#167
post #164
post #134

Earlier quoted context omitted.

> This means the credentials from the original implementation of said feature weren't locked down to only data available from your viewable profile. Yeah, that's the entire security incident. So are you saying you expect software companies to never have security incidents? Now that's ridiculous.

Why is that ridiculous?

It's only possible with a very different set of tradeoffs around risk and innovation than are the norm in software. It takes NASA-grade layers of slow development processes to be 100% certain that there will never be any incidents.

Most companies, most developers, and most consumers would not be happy with the cost and speed this would result in.

In short: it's not that it's impossible. We know how to do it. It just comes with a cost attached that nobody wants to pay.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#168

Earlier quoted context omitted.

When LastPass was hacked, the way they stored data helped protect users: https://blog.lastpass.com/2015/06/lastpass-security-notice.h...

It's funny that in a topic complaining about a company who spies on it's users someone brings up Last Pass which says right in it'a TOS they spy on all your browser traffic and share that info with marketing partners https://www.logmeininc.com/legal/privacy it basically says they collect everything possible to collect and will use it for anything they want including sharing with 3rd parties

So that's why they want me to change my password (I've had the same one since pre-acquisition days.)

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#169

Facebook posting: https://newsroom.fb.com/news/2018/10/update-on-security-issu... Check if you are affected here: https://www.facebook.com/help/securitynotice (posting because it took 10+ mins to find it - many media outlets are not linking directly to it)

It's such bullshit that they put the info into a card that disappears street the first time you read it.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#170

Earlier quoted context omitted.

I use KeePass for password management and the way I handle this is I generate a random string for each security question answer, then just include it in the Notes field of the entry.

People are social engineering a random string when talking to customer care. The attacker says “Ah, a bunch of random characters, do I have to say it?” or even worse I have had a customer service rep look at it, laugh and say never mind. I use “batteryhorsestaple” type of passwords stored in a password manager for the security questions. Those are easy to say over the phone and more resistant to social engineering.

You can get a fair amount of entropy out of names, and there are often multiple name type questions (somebody's maiden, friend's nickname, favorite teacher). Luckily it's hard to hammer customer service reps with repeated attempts, at least until the AI for voice personal assistants get a little better.
Post reply on HN