Seems like they should add another 0 to the fine after the recent hat trick: 1) Prompting users to give Facebook their email passwords.[0] 2) Using that email access to "inadvertently" upload the information of their email contacts.[1] 3) Storing said passwords and others in plaintext. [2] It's pretty impressive that a company could do something so brazenly malevolent and be confident that they will escape with no mo…
I'm ashamed to say that up until now, when I saw Facebook (or similar) acting evil I thought about the quote, "Never attribute to malice that which is adequately explained by stupidity". Well, fuck that and fuck me, those people are not idiots, they're criminals.
Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues
111–120 of 331 posts
Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues
#112Seems like they should add another 0 to the fine after the recent hat trick: 1) Prompting users to give Facebook their email passwords.[0] 2) Using that email access to "inadvertently" upload the information of their email contacts.[1] 3) Storing said passwords and others in plaintext. [2] It's pretty impressive that a company could do something so brazenly malevolent and be confident that they will escape with no mo…
I'm ashamed to say that up until now, when I saw Facebook (or similar) acting evil I thought about the quote, "Never attribute to malice that which is adequately explained by stupidity". Well, fuck that and fuck me, those people are not idiots, they're criminals.
Like, if someone treads dog poo into my house on their shoes, it doesn't really matter if they did it by mistake, or spent ages walking around town trying to find some dog poo to step in before coming to my house; the effect is that there is now dog poo on my carpet.
We need to be more dispassionate when discussing these issues because otherwise threads like this descend into analysis of whether Zuckerberg/Bezos/whoever is a moral person. Which is a)probably unknowable and b)besides the point.
There is a problem here with a very big company that has more power than it knows how to handle, which can probably only be mitigated by breaking it up. That's all there is to it, really.
[edit] Just as an addendum, that's not to say that if the company has done something illegal, the people responsible shouldn't be prosecuted- they should.
Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues
#113Seems like they should add another 0 to the fine after the recent hat trick: 1) Prompting users to give Facebook their email passwords.[0] 2) Using that email access to "inadvertently" upload the information of their email contacts.[1] 3) Storing said passwords and others in plaintext. [2] It's pretty impressive that a company could do something so brazenly malevolent and be confident that they will escape with no mo…
I'm ashamed to say that up until now, when I saw Facebook (or similar) acting evil I thought about the quote, "Never attribute to malice that which is adequately explained by stupidity". Well, fuck that and fuck me, those people are not idiots, they're criminals.
Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues
#114https://finance.yahoo.com/quote/FB/key-statistics?p=FB $55 Billion in revenue and EBITDA 29.23B and they get a $5 Billion fine for doing a lot of scummy, but profitable stuff. The best part for FB? Two years from now FB will say to FTC, "you already fined us once...the largest fine ever blah blah blah"
How is that good? Next time they will fine them more.
Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues
#115Earlier quoted context omitted.
I'm not arguing this wasn't a bad thing but comment made it sound like they were storing plaintext passwords in the database circa 2002.
Storing them in logs is the same thing IMO. Logs are usually more easily accessible than a user database.
I think it would be way worse if we found out they were storing passwords were plaintext in the database in 2019. Even if the security implications are the same/worse, the policy/decision making of such a revelation would be beyond terrible.
edit: To put it another way, remote code execution flaws are terrible but they can happen. However it would be way worse if someone put in a static username/password backdoor. The security outcome may be the same but one is beyond terrible policy/decision making.
Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues
#116Seems like they should add another 0 to the fine after the recent hat trick: 1) Prompting users to give Facebook their email passwords.[0] 2) Using that email access to "inadvertently" upload the information of their email contacts.[1] 3) Storing said passwords and others in plaintext. [2] It's pretty impressive that a company could do something so brazenly malevolent and be confident that they will escape with no mo…
I'm ashamed to say that up until now, when I saw Facebook (or similar) acting evil I thought about the quote, "Never attribute to malice that which is adequately explained by stupidity". Well, fuck that and fuck me, those people are not idiots, they're criminals.
Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues
#117A fine is not enough in this situation ...
Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues
#118Before this thread becomes a Facebook bashing session, please keep in mind that Equifax leaked all your SSN data along with names and addresses and got away with no fines.
So what are you saying exactly? We can’t set our eyes on Facebook because someone else is worse?
Also, people use FB by choice today while something like Equifax is forced upon us given institutional structures. So it is unclear why Facebook is more wrong than Equifax.
Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues
#119Earlier quoted context omitted.
If you're a small business - I get it, it's good to whitelist whatever information you're logging explicitly, but for smaller teams a hard to diagnose issue might lead the team to "log everything so we can sort it out later". Facebook is Facebook, whether this decision was the product of the corporation as a whole, a small dev team, or a highly paid consultant/third party, Facebook is a big enough company that they d…
Seems like a pretty trivial automated test for so many PHD's to miss: create_user('Bob', 'BobPassword123') assert "BobPassword123" not in logfile
Of course we (and they) should do it anyway, but it does often take an investment in making things testable.
Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues
#120Seems like they should add another 0 to the fine after the recent hat trick: 1) Prompting users to give Facebook their email passwords.[0] 2) Using that email access to "inadvertently" upload the information of their email contacts.[1] 3) Storing said passwords and others in plaintext. [2] It's pretty impressive that a company could do something so brazenly malevolent and be confident that they will escape with no mo…
I'm ashamed to say that up until now, when I saw Facebook (or similar) acting evil I thought about the quote, "Never attribute to malice that which is adequately explained by stupidity". Well, fuck that and fuck me, those people are not idiots, they're criminals.
People are realizing that social validation is becoming less validated by social media. (Lets remove the likes on IG!!). The people coming around now are sheep looking for the next wave of validation.