Live data from Hacker News

Instagram kept deleted photos and messages on its servers for more than a year

theverge.com

51–60 of 205 posts

Re: Instagram kept deleted photos and messages on its servers for more than a year

#51
post #48

I don't know how many times this is going to have to happen before people understand this: when you put something online, assume it is essentially public. Forever. If you don't want it to be public forever, don't put it online.

This is victim blaming and only reinforces the status quo. The way things are isn't the way things have to be. We can change the rules if we work together. Or we can give up and blame the victims.

Re: Instagram kept deleted photos and messages on its servers for more than a year

#52
post #24

Few months ago I requested my data from Discord. Interestingly enough, it didn't include my messages from server that was deleted some time before that.

I remember seeing messages in channels that were deleted on the server so I am skeptical but it's been a long time since I requested a package. Maybe it's different for server deletion?

Let me test this.

Re: Instagram kept deleted photos and messages on its servers for more than a year

#53
post #10
post #9

We know that HN is visited by a fair share of Facebook employees. Can some of you weigh in (anonymously?) on this topic? Do you guys do hard deletes of user data instead of just soft deletes? If so, are logs or backups kept? For how long? In other words: if I'm a user of $POPULAR_SERVICE and I delete my account at time t0, is there a t1 > t0 after which every trace of my data is gone from the platform? My (cynical) g…

DELETED=TRUE

The problem with just a flag is it slows down queries. You can scrub it later, but that’s just kicking the can down the road and now you have to deal with the consequences of an actual hard delete.

I wonder when popular databases will have some first class support for soft deletion built in.

Re: Instagram kept deleted photos and messages on its servers for more than a year

#54

Earlier quoted context omitted.

Only that doesn't typically happen. It just sits there, for years or until the company goes bust. The typical reasoning is that marketing wants to hold on to the data, they will never ever say 'ok, enough, you may delete it' because there is this infinitely small chance that they can re-activate an account, market to it for some other product (no matter that that is against the GDPR) or to sell the data to some third…

[flagged]

Did I claim that Facebook never really deletes data?

I just answered the GP, maybe you have your threads mixed up?

But if I were to speculate I would say that if Instagram does what the article title says that you could already make that claim about Facebook since they are a part of it.

Re: Instagram kept deleted photos and messages on its servers for more than a year

#55
And here I am dreaming of a world where companies do real deletions of data when a user requests (and also deleting older transactional data that has outlived its utility, including regulatory requirements) and storage prices being lower with a slightly smaller (steady) market for it from the major companies.

On the other hand, storage prices seem to be low enough for all these companies with bulk, long term contracts that developers wouldn’t bother doing real deletes of data.

Re: Instagram kept deleted photos and messages on its servers for more than a year

#56

> "The researcher reported an issue where someone’s deleted Instagram images and messages would be included in a copy of their information (...) We’ve fixed the issue" This makes it sound like they consider "you could see it" the issue, not "we were still keeping it". In other words, the fix was to hide it, not to delete it. If I were the Irish DPA (and actually wanted to do my job and had the resources to, instead o…

Why small fines initially? I’d like to see privacy fines being used to make lots of money like traffic fines are used today. It’s a way to tax tech companies in your jurisdiction with the added benefit of improving privacy.

Initially it was almost certainly accidental, or in a system first implemented before data protection laws covered this sort of thing.

From the moment the problem is brought to their attention, then it becomes intentional and willful, so the fines should be much bigger.

Re: Instagram kept deleted photos and messages on its servers for more than a year

#57

Earlier quoted context omitted.

[flagged]

Did I claim that Facebook never really deletes data? I just answered the GP, maybe you have your threads mixed up? But if I were to speculate I would say that if Instagram does what the article title says that you could already make that claim about Facebook since they are a part of it.

We’re in a thread that specifically asks whether Facebook really does hard deletes, so I took your comment as claiming they don’t.

> We know that HN is visited by a fair share of Facebook employees. Can some of you weigh in (anonymously?) on this topic? Do you guys do hard deletes of user data instead of just soft deletes?

Re: Instagram kept deleted photos and messages on its servers for more than a year

#58

> "The researcher reported an issue where someone’s deleted Instagram images and messages would be included in a copy of their information (...) We’ve fixed the issue" This makes it sound like they consider "you could see it" the issue, not "we were still keeping it". In other words, the fix was to hide it, not to delete it. If I were the Irish DPA (and actually wanted to do my job and had the resources to, instead o…

Why small fines initially? I’d like to see privacy fines being used to make lots of money like traffic fines are used today. It’s a way to tax tech companies in your jurisdiction with the added benefit of improving privacy.

Because the goal is compliance, not to put companies out of business. When the laws were first enacted everybody was screaming that it was just to put companies out of business. Now they are wondering why the small initial fines.

It's simple: change your ways and use the initial fines as a wake up call. If you then do not wake up and persist the fines will get heavier and heavier until you will pay attention.

A Dutch hospital managed to get to the third round of fines and they weren't all that happy afterwards. 460K Euro fine for a single instance of ignoring the regulators on a single individual.

Believe me when I tell you they have understood now.

The initial fine was zero, just a warning to improve.

The case revolved around a very minor dutch celebrity whose data was reviewed by hospital employees that should not have had that access.

Re: Instagram kept deleted photos and messages on its servers for more than a year

#59

This sort of practice is not limited to just Instagram. Plenty of places that do soft deletes when they should be doing hard deletes. Data life-cycles are about the poorest understood subject in startup land. Ingestion is usually top notch, friction free and heavily automated. Deletion - assuming it even exists - is semi automatic or even manual, full of friction and usually incomplete or broken. You see a similar pa…

I think just about everything should be a soft delete, however you need a time limit where you sweep those. Ideally you would even give the user an option to accelerate that (as much as technically possible) if they really want something gone.

Re: Instagram kept deleted photos and messages on its servers for more than a year

#60
post #51
post #48

I don't know how many times this is going to have to happen before people understand this: when you put something online, assume it is essentially public. Forever. If you don't want it to be public forever, don't put it online.

This is victim blaming and only reinforces the status quo. The way things are isn't the way things have to be. We can change the rules if we work together. Or we can give up and blame the victims.

We should hold both companies and people accountable for their actions. I treat privacy hygiene the same as body hygiene.
Post reply on HN