Live data from Hacker News

Backblaze Privacy Update: Third-Party Tracking

backblaze.com

41–50 of 72 posts

Re: Backblaze Privacy Update: Third-Party Tracking

#41
post #28
post #23

I wish I hadn't put my PII into the filenames of the files I was backing up. myname_myaddress.txt 4445-3333-2222-1213-0121-354.my.credit.number NW53342211A.my.national.insurance.number facebook_password_is_letmein.txt filename_are_now_storage.exe I_vote_for_trump.doc Now this is public I bet there's hundreds of facebook team members sifting through all of that log data to find this PII and manually transcribe it into…

In certain countries just possessing a file or app of a certain title could get you killed... edit: On further thought, would this have triggered China's firewall?

In this country I can think of a couple: RepublicanVoterRegistration.png

DemocratVoter Registration.png

Re: Backblaze Privacy Update: Third-Party Tracking

#42
post #36
post #3

Firstly, this post does not even mention or describe what kind of information was exposed and makes it seem like some inadvertent tracking that's not serious in any way. You can continue with your root cause analysis, but you already know very well about what kind of information was exposed and shared with Facebook. The least you could do is own it and alert people about it. > We take the privacy of our customers’ da…

Yes, this is rather disappointing. It's probably also in breach of GDPR assuming backblaze haven't contacted customers directly, informing them about the nature and detail of leaked data (based on your use of backblaze on X, we see that the following filenames and Metadata was incorrectly handed over to a third party (Facebook)...).

Wouldn't this also be a GPDR violation by Facebook as well?

Re: Backblaze Privacy Update: Third-Party Tracking

#43
oof, this blog post is even more cringy than their repeated replies on twitter "...we’ve looked into and verified the issue and have pushed out a fix. We will continue to investigate and will provide updates as we have them."

this is a perfect example of how NOT to handle a PR nightmare.

Re: Backblaze Privacy Update: Third-Party Tracking

#45
post #42
post #36

Earlier quoted context omitted.

Yes, this is rather disappointing. It's probably also in breach of GDPR assuming backblaze haven't contacted customers directly, informing them about the nature and detail of leaked data (based on your use of backblaze on X, we see that the following filenames and Metadata was incorrectly handed over to a third party (Facebook)...).

Wouldn't this also be a GPDR violation by Facebook as well?

Possibly. But Backblaze has an agreement with the user; and they have taken data they need / are justified in handling (filenames, sizes) and leaked them. Google docs wouldn't be liable if I stole your credit-card and put it in a Google doc.

It may be that fb is doing something illegal here too - eg the whole way tracking pixel work seems difficult to square with gdpr - but the tracking pixel/service looks a bit like the drill used to force a lock - another party (like BB) must deploy it. And arguably the purpose is not to "steal" data.

Re: Backblaze Privacy Update: Third-Party Tracking

#47
post #26

Earlier quoted context omitted.

I would say that opt in is pretty Ok in terms of privacy of customers protection.

One does not protect one's customer privacy by asking if it can be violated, often using dark patterns.

Well that's exactly how you do it. By definition.

Asking for consent means that you don't violate their privacy since they agreed to the data being collected and shared.

Using dark patterns is of course not Ok but also a different topic.

Re: Backblaze Privacy Update: Third-Party Tracking

#50
post #32
post #29

Earlier quoted context omitted.

on tv at least, they say that apology is the same as admitting guilt, so they might not want to do that for legal reason anyone know if that applies to the real world?

Could it be any more admitting guilt than >a new Facebook campaign was created that started firing a Facebook advertising pixel, intended to only run on marketing web pages. However, it was inadvertently configured to run on signed-in pages. "We take privacy very seriously" is a sign that they don't take your privacy seriously at all.

inadvertently is the operative word here - I.e. their position is that this was just an accident.
Post reply on HN