Live data from Hacker News

Facebook Says Hackers Stole Detailed Personal Data from 14M People

bloomberg.com

211–217 of 217 posts

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#211

Earlier quoted context omitted.

That is not the only thing you can get fined for under GDPR.

I’m fairly knowledgeable in the GDPR and I’m legitimately curious what you think the fine basis would be related to this breach.

A few things made me wonder

1) https://news.ycombinator.com/item?id=18203002

This comment suggests that they discovered the vulnerability and spent two days working out how to fix it, whilst leaving the site live for exploitation.

2) Did they report the breach in a timely manner. That is not clear to me yet

3) Until a detailed analysis is done we don't know if there was anything negligent about this.

4) If in other investigations into Facebook it is found that Facebook were storing data they had no right to, and it transpired that they had lost some in this attack, they would be culpable because they shouldn't have had the data to lose.

So nothing specific, but lots of maybees

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#212

Earlier quoted context omitted.

I’m fairly knowledgeable in the GDPR and I’m legitimately curious what you think the fine basis would be related to this breach.

A few things made me wonder 1) https://news.ycombinator.com/item?id=18203002 This comment suggests that they discovered the vulnerability and spent two days working out how to fix it, whilst leaving the site live for exploitation. 2) Did they report the breach in a timely manner. That is not clear to me yet 3) Until a detailed analysis is done we don't know if there was anything negligent about this. 4) If in other i…

We don’t have a lot of case law to go on but generally speaking most experts assume article 33 will be the easiest part of gdpr to conform to.

Even under the most harsh interpretations 3 days is the standard & that comes with all kinds of outs.

To the rest of your other points they largely are not at all covered by GDPR.

For instance I’ve never seen an interpretation of the GDPR that required a timeframe for remediation.

Further there is no requirement to allow a supervisory authority investigatory power after a breach.

In any case this appears to be a Facebook acting with extreme transparency. Exactly what the regulators want. It would be weird if this lead to negative ramifications.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#213

Earlier quoted context omitted.

Nah, it would go like this: Support: what is your fathers middle name? Hacker: Michael Support: sorry that is wrong Hacker: oh shoot, I forget I always put the incorrect information in this one... i can't remember, did I put a fake name or random characters? Or was this the one I put a bunch of words into? Support: yeah, it looks like random characters... let's move on

Proper training, required. That person presumably is legally liable as they've breeched the providers security by giving information; and maybe given away PII.

This is the point of failure. This never comes to fruition.

"Computers are hard, and I'm just not very good with them!"

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#214

If I type my full name on google, I can find my home and cell phone number, age, all family members, home address, my last home address, and my google + (fb and LinkedIn I changed settings so not searchable). And it’s a pain to ask them to delete the info. It’s obscure and time consuming and no guarantees. That in my mind is worse than anything here. I didn’t allow that info to be public, we need more privacy laws.

Sounds like a startup opportunity. For only $5, we'll file take down notices left and right for all the info that is available online about you.

Use the block chain to track it ??? Profit

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#217
post #93

Earlier quoted context omitted.

Did you read the article? "For 14 million people, the attackers accessed the same two sets of information, as well as other details people had on their profiles. This included username, gender, locale/language, relationship status, religion, hometown, self-reported current city, birthdate, device types used to access Facebook, education, work, the last 10 places they checked into or were tagged in, website, people or…

Can you have that information entered into Facebook without then showing to anyone but yourself? If so, why would you have the info in there? If not, and as is common, you allow friends to see it, then that information is basically public anyway unless you are very, very selective in who you accept as a friend. Even when being selective, there is no identity verification, so it is common for spammers or data collecto…

yes facebook forces you to put in phone number for example, for "backup authentication" "verification" purposes, and if you don't want to show that to your friends or the public you must set it to private. The default is something like "show to all friends"

There are many preferences in facebook that are like that - unavoidable/impassible fields that ask for info, and then you set it to "private/only yourself" to prevent information leakage, but are set default to world or friend visible.

It's a dark pattern that's all over facebook - you will see it if you install the facebook mobile apps - you can't proceed to surf your timeline without clicking through and answering questions sometimes - best thing is to fill in blank/gibberish info, but sometimes phone numbers, etc can't be avoided.

Post reply on HN