Live data from Hacker News

Backblaze Privacy Update: Third-Party Tracking

backblaze.com

61–70 of 72 posts

Re: Backblaze Privacy Update: Third-Party Tracking

#62
post #30

I've been a happy Backblaze B2 user for the past few months, but this and another recent event leaves me feeling like I'll have to abandon their service (or at least mirror everything to S3 just-in-case) soon. Recent event being when GoDaddy suspended their user-facing B2 domain a month ago because of abuse requests that were apparently not handled correctly. That and the fact that they still don't have a user-facing…

Yev from Backblaze here -> thanks for being a Backblaze customer. We've finished our root cause analysis and have updated that blog post with additional information. We also have moved domain registrars to make sure that behavior doesn't happen again. Sincere apologies for the issues you've experienced.

Re: Backblaze Privacy Update: Third-Party Tracking

#63
post #3

Firstly, this post does not even mention or describe what kind of information was exposed and makes it seem like some inadvertent tracking that's not serious in any way. You can continue with your root cause analysis, but you already know very well about what kind of information was exposed and shared with Facebook. The least you could do is own it and alert people about it. > We take the privacy of our customers’ da…

Yev from Backblaze here - with sincere apologies. After we removed the offending code on Sunday night we went into investigation mode and conducted a rca - we wanted to get some kind of blog post out there so that folks could see that we were working and investigating the issue. I will grant you that maybe our initial execution on that was lackluster, but we wanted to make sure we had a better handle on what we were talking about. We've since updated the blog with additional information, you can read those here: https://www.backblaze.com/blog/privacy-update-third-party-tr....

Re: Backblaze Privacy Update: Third-Party Tracking

#64
post #3

Firstly, this post does not even mention or describe what kind of information was exposed and makes it seem like some inadvertent tracking that's not serious in any way. You can continue with your root cause analysis, but you already know very well about what kind of information was exposed and shared with Facebook. The least you could do is own it and alert people about it. > We take the privacy of our customers’ da…

There will never be an apology. A corporate apology is an admission of guilt. An admission of guilt opens it up to lawsuits. Through its litigeous nature, the US has evolved a culture whereby apologies and human decency are antithetical to survival.

Yev from Backblaze here -> I apologize for this mistake. We've updated the post with additional information now that we have it and there's also an apology.

Re: Backblaze Privacy Update: Third-Party Tracking

#65
post #64

Earlier quoted context omitted.

There will never be an apology. A corporate apology is an admission of guilt. An admission of guilt opens it up to lawsuits. Through its litigeous nature, the US has evolved a culture whereby apologies and human decency are antithetical to survival.

Yev from Backblaze here -> I apologize for this mistake. We've updated the post with additional information now that we have it and there's also an apology.

On another note, have you contacted facebook to get the data removed from their servers?

Re: Backblaze Privacy Update: Third-Party Tracking

#66

Anyone got any alternatives?

I've started using rsync.net with the borg client (replacing b2 and rclone) and loving it so far. I'm also surprisingly finding borg/rsync.net is suiting my usecase (personal backups) better than b2 did which is a nice bonus. I am paying more but can't complain as the value I'm getting is still good.

Re: Backblaze Privacy Update: Third-Party Tracking

#67
post #63
post #3

Firstly, this post does not even mention or describe what kind of information was exposed and makes it seem like some inadvertent tracking that's not serious in any way. You can continue with your root cause analysis, but you already know very well about what kind of information was exposed and shared with Facebook. The least you could do is own it and alert people about it. > We take the privacy of our customers’ da…

Yev from Backblaze here - with sincere apologies. After we removed the offending code on Sunday night we went into investigation mode and conducted a rca - we wanted to get some kind of blog post out there so that folks could see that we were working and investigating the issue. I will grant you that maybe our initial execution on that was lackluster, but we wanted to make sure we had a better handle on what we were…

> We are also reviewing applicable third party code on the website.

This is very simple. On all dashboard and similar signed-in pages, there's exactly zero applicable third party code.

If you think otherwise you do not in any way take "the privacy of our customers’ data and personal information very seriously".

As such, you should be much more specific about what you mean with "we removed the offending code".

If you never intended for third party scripts to run on the dashboard page, well then you got some serious explaining to do as to how your deployment process let that slip.

Re: Backblaze Privacy Update: Third-Party Tracking

#68

Yeah. Backblaze are addressing this "blunder" only because they got caught. Not because they give 2 shits about their customer's privacy. The smug tone in this joke of a response to the issue proves this.

Man, your distrust seems toxic to me. The simplest explanation is they goofed as they admitted, if they were malicious, they'd upload those file names from their server straight to FB's, not through your god damned browser. And of course they only addressed it after they "got caught", they didn't know about their fuck up before that, if you want to sneer at them, sneer at them for not being careful enough to let this…

I agree with you in principle.

That said, this way of doing things gives so much plausible deniability that it must at least occur to people.

We've been burned on so many fronts by so many companies that it really is a learned behaviour to toxically distrust when things like this happen.

It starts with politics. They're never held accountable for lying, evwn brazenly.

Re: Backblaze Privacy Update: Third-Party Tracking

#70

Yeah. Backblaze are addressing this "blunder" only because they got caught. Not because they give 2 shits about their customer's privacy. The smug tone in this joke of a response to the issue proves this.

never attribute to malice that which is adequately explained by stupidity
Post reply on HN