Live data from Hacker News

The Facts on News Reports About Facebook Data

about.fb.com

41–50 of 60 posts

Re: The Facts on News Reports About Facebook Data

#41

I'm curious if the repeated negative press Facebook has received has impacted their hiring. Boots on ground perspectives appreciated, but I can share a data point of one: I'm a very average developer, and I get at least quarterly reach outs from Facebook-- a higher frequency than I've ever heard from any FANG (or any company in general). I used to get ads on the platform for FB Engineering jobs. After I deleted the a…

As long as they pay top of market (and they do), people will work for them. FB consistently beat Google and other top employers by non-inconsequential figures.

There's also the case of Google being ethically bankrupt as well (undisclosed DoubleClick tracking backdoor in Chrome).

I don't see the argument that FB is worse than Google. Google will snoop on your private messages for information that they can use to feed their advertising machine, and they have an entire browser dedicated to ad networks (they regularly implement insecure APIs that are immediately abused by DoubleClick customers, including on high profile sites).

Re: The Facts on News Reports About Facebook Data

#42
Don't really want to defend Facebook, but the amount of cynicism and bad faith here is too much. This article should be welcome, it gives us more information on what happened. It clarifies that this was not some sort of database leak (which is much more damaging), but a API abuse that allowed bad actors to figure out people's phone numbers. Overall article brings transparency to the situation, which is good.

Re: The Facts on News Reports About Facebook Data

#43

The attitude that this company (and many others) has towards the data they collect from billions of people is stunning. They claim that there was nothing they could do, even when one of their tools was misused to gather phone numbers. They don't take accountability for the fact that this likely already has and will continue to enable spammers and scammers to much more easily target their users. They refuse to send ou…

I can only speculate but what I think we are seeing here is a statement made in earnest by a corporate communication team, crafted with significant input from a product team. To admit that this was an intrusion would be severely career limiting. So they explain it in a hand-wavy fashion, enough to get the Comms people off their back. The end result is this unsatisfying explanation.

Just speculation. There has to be a method to the madness that is Facebook press releases.

Re: The Facts on News Reports About Facebook Data

#44

Facebook is using doublespeak here. > It is important to understand that malicious actors obtained this data not through hacking our systems but by scraping it from our platform prior to September 2019. .. a couple paragraphs later :: > We believe the data in question was scraped from people’s Facebook profiles by malicious actors using our contact importer prior to September 2019. Gee, that sounds a lot like someone…

> Gee, that sounds a lot like someone abused your contact importer tool to do something you didn't intend for it to do. From the article it appears that the contact importer is an API endpoint which returns a set of Facebook profiles given a set of phone numbers. In that sense, it did exactly what the developer intended. If I write a script to query google.com and get a response back you could say I'm not using googl…

At a certain level the question is academic, and lawyering over definitions only distracts from the bigger picture. I trusted Facebook with my mobile number. They permitted bad actors to mis-use their service, and now bad actors have that number. Facebook should be held accountable. Whether it was through SQL injection or a poorly-thought-out API is academic.

Re: The Facts on News Reports About Facebook Data

#45

Earlier quoted context omitted.

> Gee, that sounds a lot like someone abused your contact importer tool to do something you didn't intend for it to do. From the article it appears that the contact importer is an API endpoint which returns a set of Facebook profiles given a set of phone numbers. In that sense, it did exactly what the developer intended. If I write a script to query google.com and get a response back you could say I'm not using googl…

> In that sense, it did exactly what the developer intended. Not sure they envisioned someone enumerating phone numbers and pulling all data. But that would be hilarious if they claim that's what they intended and that was a feature.

There's a difference between an unintended use case and unintended behavior

Re: The Facts on News Reports About Facebook Data

#46

Earlier quoted context omitted.

right, they make it sound like it was publicly available data, but it was data unintentionally made public. Sort of like saying "people scraped publicly available information from our website" when someone grabs passwords from a public-facing MongoDB database without a password.

The data was from people’s public profiles, it’s not unintentionally public. the issue was making it scrapable.

This is incorrect. Private phone numbers not publicly shown on your profile via the UI are included.

Mark Zuckerberg's own phone number was included, and you can bet he would never intentionally release that nor is he likely to misconfigure his privacy settings and leak it due to user error

Re: The Facts on News Reports About Facebook Data

#47

Earlier quoted context omitted.

The data was from people’s public profiles, it’s not unintentionally public. the issue was making it scrapable.

No, the phone numbers and emails weren't publicly posted (globe icon), they were just meant to discover contacts.

You can choose to make your email on your profile public. Take a look at the number of emails exposed vs. the number of phone numbers exposed, there's a reason why it's a small portion, most people don't make that public.

This was just an attacker abusing "Who can look you up using the phone number you provided?" for users where this was set to the default of "Everyone" and then scraping the public details for the profile that popped up.

Re: The Facts on News Reports About Facebook Data

#48
post #44

Earlier quoted context omitted.

> Gee, that sounds a lot like someone abused your contact importer tool to do something you didn't intend for it to do. From the article it appears that the contact importer is an API endpoint which returns a set of Facebook profiles given a set of phone numbers. In that sense, it did exactly what the developer intended. If I write a script to query google.com and get a response back you could say I'm not using googl…

At a certain level the question is academic, and lawyering over definitions only distracts from the bigger picture. I trusted Facebook with my mobile number. They permitted bad actors to mis-use their service, and now bad actors have that number. Facebook should be held accountable. Whether it was through SQL injection or a poorly-thought-out API is academic.

SQL injection = Bug-in-computer-code poor API = Bug-in-thought-process

Bug owned by FB either way.

Re: The Facts on News Reports About Facebook Data

#49

Facebook is using doublespeak here. > It is important to understand that malicious actors obtained this data not through hacking our systems but by scraping it from our platform prior to September 2019. .. a couple paragraphs later :: > We believe the data in question was scraped from people’s Facebook profiles by malicious actors using our contact importer prior to September 2019. Gee, that sounds a lot like someone…

Yeah, seems like the definition of hacking what happened there. I mean Facebook could have at least rate limit or block this, but they had no mitigation. They even admit of having fixed it afterwards.

Re: The Facts on News Reports About Facebook Data

#50

Don't really want to defend Facebook, but the amount of cynicism and bad faith here is too much. This article should be welcome, it gives us more information on what happened. It clarifies that this was not some sort of database leak (which is much more damaging), but a API abuse that allowed bad actors to figure out people's phone numbers. Overall article brings transparency to the situation, which is good.

Good for what purpose exactly? They’re not really taking accountability so where is the good that you’re talking about?
Post reply on HN