Live data from Hacker News

533M Facebook users' phone numbers and personal data have been leaked online

businessinsider.com

521–524 of 524 posts

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#521

Don’t worry, Facebook will soon put out a press release including the phrase “we need to do better.”

I work in the security field and let me tell you something I realized: nobody cares about security. If someone cares about security, it's because they've had many many incidents in the past. We humans are not a species that is good at preventing, we are good at reacting. the security handbook[^1] has a chapter on that actually, and they basically say that role playing is the only way of not getting burned. Humans are…

That site is a scam. The listed email address does not exist and I have not received a book.

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#522

Earlier quoted context omitted.

Why not FIX how an SSN can be used? It was not created for this purpose but that doesn't mean how we use it can't be fixed. Any time someone attempts to use your SSN to identify themselves as you, you should be notified and your authorization should be required for that use to be allowed. And the higher the value of the authorization, the more care should be required. Companies are able to do this already with 2 fact…

> Any time someone attempts to use your SSN to identify themselves as you, you should be notified and your authorization should be required for that use to be allowed. So now the government needs a way of contacting you. Suppose they have your address and phone number on file. Then you lose your way a while and become homeless for two years. You can't afford a phone and no longer have the same address, and have lost…

If a new account can never used to establish your identity for other purposes, there's no problem opening such an account without government identifying you.

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#523

Earlier quoted context omitted.

I think part of the problem is that many orgs see security as an overhead that engineers do to sleep well at night. A few more breaches, a few more fines and it will finally be seen as a feature to keep the CEO out of jail.

This is just it. I also work in the security industry, and the fact of the matter is that we (security professionals) can't give guarantees. I don't know what exotic exploit or bug will exist tomorrow. Security professions basically offer what (to me) seems like a crappy insurance policy. Depending on your orgs threat model, it is often just cheaper to deal with the breaches. --- I am not saying facebook falls into t…

Security is not a replacement for a data breach insurance. Security is basic hygiene for insurance to work at all.

To me, a good parallel is home insurance. If you get robbed, a good insurance will cover your losses. However, if said insurance determines that you were negligent -- say you never lock your front door -- you are on your own.

Do you have precious art at home that you want insured? No problem. Just make sure you add an alarm and sprinklers.

That is how I want discussions around security to be held. Are you a start-up with 10 users? It's okay to do minimal security. Are you a bank whose wires carry $1B? Make sure you throw sufficient "bodies" at the problem, from the top of the hierarchy to bottom.

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#524

Earlier quoted context omitted.

This. I don't trust in the government, but I think digital "personal data" should be only available for "confirmation" to companies that need it. Say, a government entity could have an API that allow you to send hashed personal data that they can verify is right. This way companies will ask the user for their data and hash it client-side. Then they can send the hashes (hashed with a custom provided salt to the entity…

It's probably not implemented as closely as what you described but check out Europe, this small continent across the pond and the tech scene in the smaller countries. For example Estonia has had famously and online identity stuff linked via a federal ID (in europe there are more republics then federations so it's easier to manage country-wise) [0] [1] Or more familiar to me with a bigger sample is a movement in Polan…

For many reasons, good or bad, the idea of mandated federal ID or national ID isn't quite accepted in the US.
Post reply on HN