Live data from Hacker News

Backblaze Privacy Update: Third-Party Tracking

backblaze.com

31–40 of 72 posts

Re: Backblaze Privacy Update: Third-Party Tracking

#31
post #26
post #22

> We take the privacy of our customers’ data and personal information very seriously [...] And yet, your blog/landing site wants me to opt into sharing my 'personal data' with 20 different 'advertisement partners'. Come on.

I would say that opt in is pretty Ok in terms of privacy of customers protection.

One does not protect one's customer privacy by asking if it can be violated, often using dark patterns.

Re: Backblaze Privacy Update: Third-Party Tracking

#32
post #29
post #3

Firstly, this post does not even mention or describe what kind of information was exposed and makes it seem like some inadvertent tracking that's not serious in any way. You can continue with your root cause analysis, but you already know very well about what kind of information was exposed and shared with Facebook. The least you could do is own it and alert people about it. > We take the privacy of our customers’ da…

on tv at least, they say that apology is the same as admitting guilt, so they might not want to do that for legal reason anyone know if that applies to the real world?

Could it be any more admitting guilt than

>a new Facebook campaign was created that started firing a Facebook advertising pixel, intended to only run on marketing web pages. However, it was inadvertently configured to run on signed-in pages.

"We take privacy very seriously" is a sign that they don't take your privacy seriously at all.

Re: Backblaze Privacy Update: Third-Party Tracking

#33
There are known mechanisms to prevent leaks/exploits of this sort by sending some additional headers[0], on most of the modern browsers. Apart from that, the cookies should be strict for such a service. I logged in to my friends account to find neither implemented.

They better act quick about "ensuring it doesn't happen" or I will distrust them completely.

[0]: Content-Security-Policy (setting at least connect-src) and X-XSS-Protection to start with. More here: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Co...

Re: Backblaze Privacy Update: Third-Party Tracking

#35
post #3

Firstly, this post does not even mention or describe what kind of information was exposed and makes it seem like some inadvertent tracking that's not serious in any way. You can continue with your root cause analysis, but you already know very well about what kind of information was exposed and shared with Facebook. The least you could do is own it and alert people about it. > We take the privacy of our customers’ da…

There will never be an apology. A corporate apology is an admission of guilt. An admission of guilt opens it up to lawsuits. Through its litigeous nature, the US has evolved a culture whereby apologies and human decency are antithetical to survival.

Re: Backblaze Privacy Update: Third-Party Tracking

#36
post #3

Firstly, this post does not even mention or describe what kind of information was exposed and makes it seem like some inadvertent tracking that's not serious in any way. You can continue with your root cause analysis, but you already know very well about what kind of information was exposed and shared with Facebook. The least you could do is own it and alert people about it. > We take the privacy of our customers’ da…

Yes, this is rather disappointing. It's probably also in breach of GDPR assuming backblaze haven't contacted customers directly, informing them about the nature and detail of leaked data (based on your use of backblaze on X, we see that the following filenames and Metadata was incorrectly handed over to a third party (Facebook)...).

Re: Backblaze Privacy Update: Third-Party Tracking

#39

There are known mechanisms to prevent leaks/exploits of this sort by sending some additional headers[0], on most of the modern browsers. Apart from that, the cookies should be strict for such a service. I logged in to my friends account to find neither implemented. They better act quick about "ensuring it doesn't happen" or I will distrust them completely. [0]: Content-Security-Policy (setting at least connect-src) a…

Wow! is crazy they don't have that implemented.

Re: Backblaze Privacy Update: Third-Party Tracking

#40
post #6

They literally sent file names and file sizes over to Facebook. That might very well include very personal or confidential data. The fact that they don't even mention this and make it sound like some random unimportant tracking happened without them noticing is completely ridiculous.

Yeah, like file names of say PDF's, files with unique identifiers that give insight to the users personal life, worse still profile names of PC backups etc. etc.
Post reply on HN