Live data from Hacker News

Facebook does not plan to notify half-billion users affected by data leak

reuters.com

61–70 of 315 posts

Re: Facebook does not plan to notify half-billion users affected by data leak

#62

The "real names" myth was the biggest scam played against people in the past 15 years. The media are also wholesale responsible for perpetuating that damaging trend. Historians of the future will look at the past 2 decades with disbelief.

What's the 'real names' myth?

The idea that using your state-given name online is beneficial.

Re: Facebook does not plan to notify half-billion users affected by data leak

#64

This is probably illegal in Europe. They have 72h to notify their users after noticing a breach according to GDPR's article 33: https://gdpr-info.eu/art-33-gdpr/ Edit: My bad, only notify the authorities.

Except they're not claiming 'breach' they're claiming 'scraping'. Not sure semantic acrobatics is going to fly with the regulator however.

Re: Facebook does not plan to notify half-billion users affected by data leak

#65

This is probably illegal in Europe. They have 72h to notify their users after noticing a breach according to GDPR's article 33: https://gdpr-info.eu/art-33-gdpr/ Edit: My bad, only notify the authorities.

> Notification of a personal data breach to the supervisory authority.

Not users. FB had probably done that already.

Re: Facebook does not plan to notify half-billion users affected by data leak

#66
post #22

Why notifiy? Victims got notified everyday with many spam-sms. Thanks Facebook!

Because I would really like to know if I'm affected. According to "Have I Been Pwned" my phone number is not in the list, but about one or two weeks ago I noticed that my spam folder was unusually full, which led me to believe that something new must have happened. Shortly thereafter Facebook's leak hit the news.

From my point of view it is their obligation to notify all the affected users. It's morally the right thing to do, and legally, well, I don't know, but maybe the GDPR says that yes, that it's their obligation to do so.

And with notification I mean to send a notification email, since I haven't logged in for months and don't intend to this year.

Re: Facebook does not plan to notify half-billion users affected by data leak

#68
post #7
post #2

Guess it's too hard to notify users that their information got leaked. I hope they reported to all the different institutions in Europe though. The article suggests they didn't even report it to the Ireland one!

Are you seriously claiming it's too hard? They could send out emails, Facebook messages or show some banner in the profile page. This is Facebook ffs, they almost have a monopoly on communication.

> too hard to notify users

Legally seen.

The way privacy protection laws are, especially in Germany, is kinda stupid. On one side they often doesn't protect you in practice, on the other side they effectively hinder and sometimes prevent reasonable usage.

Just a view examples:

- A local government couldn't properly inform elder people that they now can get Vaccinated for free because the interplay of various privacy protection law (and stupidity/inflexibility in other areas tbh.).

- Germany has a privacy respecting anonymized blutooth based contact tracing app (wrt. Covid). But if you do a test you first have to physical sign of that other people are anonymized informed that someone they likely had contact with has covid, then when you get the result you still need to agree again to share this information. And even this was only possible after changing regulations. (I.e. why is one initial agreement not good enough?)

- The government most likely not being able to inform the victims of such data breaches.

- ...

Re: Facebook does not plan to notify half-billion users affected by data leak

#69
post #39

Earlier quoted context omitted.

> Is this worldwide or US? Worldwide. SMS is just like e-mail, you can put anything you want in the sender field. You should absolutely not trust SMS.

Any idea on the extra security measures? In Turkey for example, when you change your SIM card the 2FA from the banks will stop working and you need to call your bank to re-activate it. That of course seems like a measure to prevent SIM cloning but maybe there are some security protections against spoofing. In many places SMS is a popular way to do payments and 2FA for high security applications.

Where does SMS get used to do payments? (...and how?)

SMS for 2FA is known to be a very bad idea, and some security experts have been shouting about the need to stop doing that for a while.

I also can't see any country managing to implement more restrictions on SMS without either breaking a lot of "legitimate" sources of SMS or being ineffective outside of a very narrow window (e.g. only blocking forged SMS for numbers originating within one country)

Post reply on HN