Live data from Hacker News

Facebook does not plan to notify half-billion users affected by data leak

reuters.com

181–190 of 315 posts

Re: Facebook does not plan to notify half-billion users affected by data leak

#181

I’ve said it before and I’ll say it again, unless and until, companies like Facebook are fined appropriate amounts they’ll never stop. Quite literally, every business school on the fucking planet will tell you do something if it’s cheaper. It is cheaper for them to not give a fuck, than to give one. Unless they are fined upwards of $20-50bn it’ll never stop because it’s always going to benefit their bottom line. Full…

If the value of data protection is that high then civil suit reform (lower overhead filing, improved class actions) should accomplish the same thing, and give the money to the owners of the data, without creating a massive defensive moat around the few companies that can afford the risk.

Re: Facebook does not plan to notify half-billion users affected by data leak

#182
post #102

Earlier quoted context omitted.

My university is known to offer the option payment of tuition through a popular online system. This option is done by sending each student, at the start of the year, an SMS with a link to a payment option. Suppose you can get a list of people studying there, their names, and their phone-numbers. Faking this SMS and putting a payment that goes to you instead of uni would be a nice way to earn about 2000 euros per stud…

> My university is known to offer the option payment of tuition through a popular online system. This option is done by sending each student, at the start of the year, an SMS with a link to a payment option. They don't email this information? They don't put it on an online notification system? I have no idea why SMS seems like the logical option for this.

I do not know why they do this. I really wish they would stop.

I have considered faking the SMS message, with the payment link saying "imagine this wasn't a warning message but an actual payment request, please tell the university this is unsafe". But sending that kind of mass SMS is not easy, nor is finding the correct phone numbers.

Re: Facebook does not plan to notify half-billion users affected by data leak

#183

Earlier quoted context omitted.

It isn't true, that was the point of my question. They could (and must) notify the ones they still have data about.

The way your comment is structured, it is not obvious that it is a question. > They could (and must) notify the ones they still have data about. I agree strongly. For what it's worth, this is absolutely not what I took away from your other comment.

The question mark at the end of their original comment is a strong indicator that it is indeed a question.

Re: Facebook does not plan to notify half-billion users affected by data leak

#184
post #155
post #87

For years companies have been steadily asking, mandating or even trickling users to give them their phone numbers under the excuse of security (while the real reasons were different), now what? How can they be trusted anymore? This also strikes a great point about the data sharing between Facebook and WhatsApp. Linking data between services augments the dangers and the consequences are not obvious to the end user. I…

> I think Facebook should offer their users the option to remove their phone numbers with a real deletion. Man sometimes I think people forget phone books existed for a long time.

I had the same feeling. It seems the two things here in question is my phone number (which luckily I never gave fb), and my email which it seems every spammer in the world already seems to have?

I noticed this even back when phonebooks were a thing that a 'private' number was not something random people should call. Yet the reality is that number is kind of public but not. If you did accidently call one you would get 'how did you get this number' from the person you called.

Judging by the amount of phone calls I get these days. They have also already correlated a huge number of these. Short of me changing my number every few years there is not much I can do. I am getting cold calls on property I bought 20+ years ago and them asking if I want to sell.

At the bottom of this though is the 'data' these companies are scouring on us. Then cross correlating it. I have for the past few years come to the conclusion data is harmful to keep for both the end users and the companies that do it. Companies like google and fb seem to be of a very different opinion. Companies should be going into collecting data with 'how do we get rid of it after some period of time', not lets buy more HD to keep it on.

Re: Facebook does not plan to notify half-billion users affected by data leak

#185
post #102

Earlier quoted context omitted.

My university is known to offer the option payment of tuition through a popular online system. This option is done by sending each student, at the start of the year, an SMS with a link to a payment option. Suppose you can get a list of people studying there, their names, and their phone-numbers. Faking this SMS and putting a payment that goes to you instead of uni would be a nice way to earn about 2000 euros per stud…

> My university is known to offer the option payment of tuition through a popular online system. This option is done by sending each student, at the start of the year, an SMS with a link to a payment option. They don't email this information? They don't put it on an online notification system? I have no idea why SMS seems like the logical option for this.

The email option is arguably an easier (cheaper) attack vector than the SMS messages would be.

Re: Facebook does not plan to notify half-billion users affected by data leak

#186
post #94

Oh, facebook will pay for this breach. A lot. One thing is breach, the second part is hiding and not notifying "natural persons". They have basically violated (ignoring data collection methods etc.) what GDPR is about. But probably they wont notify non EU users. As they are not obliged so they don't care. Article 33. "In the case of a personal data breach, the controller shall without undue delay and, where feasible,…

True in theory but Facebook is one big GDPR breach and nobody with the power to fine them seems to give a shit...

Re: Facebook does not plan to notify half-billion users affected by data leak

#187
post #176
post #158

Earlier quoted context omitted.

If GDPR prevents people from being notified that their data was breached, then the GDPR needs revision.

GDPR mandates notifying affected users, so there's no reason to change it. Unfortunately there's a lot a misinformation around GDPR spreading online.

The post I was replying to was claiming the GDPR prevented it. If that is incorrect, then so be it. I'm American, so it largely doesn't directly affect me.

Re: Facebook does not plan to notify half-billion users affected by data leak

#188
post #87

For years companies have been steadily asking, mandating or even trickling users to give them their phone numbers under the excuse of security (while the real reasons were different), now what? How can they be trusted anymore? This also strikes a great point about the data sharing between Facebook and WhatsApp. Linking data between services augments the dangers and the consequences are not obvious to the end user. I…

> ... Linking data between services augments the dangers and the consequences are not obvious to the end user.

Or the end user's friends and family who's privacy was also affected by being in the user's contact list.

Re: Facebook does not plan to notify half-billion users affected by data leak

#189
post #10

This huge leak has definitely killed the SMS text messaging service. Sender can be spoofed and spam/scam/phishing have reached an intolerable level. The fact that they can cross reference you and then produce a more personalized content is huge. Changing password is easy (ok less easy if you recycle it) but changing phone number is something that I am not even relaxed to do.

Can anyone on HN please explain why, why, WHY are we still using SMS/telephony which has exactly 0 encryption wh---I guess that's the reason? It's insane. I've heard banks using SMS!!!! To send a code. We have TOTP for that! Or even perhaps a push notification or something better than bloody SMS. I refuse to use the networking system altogether. No phones, no calls. Of course you do 'need' a number so I keep one hand…

It's because SMS works without data.

I doubt that most of the people that complain about SMS live in rural areas. It seems to be more of a US thing. The country is so large that unless you live in a city you just won't be able to get data reliably. This leaves SMS as the only form of phone communication that isn't a voice call.

Re: Facebook does not plan to notify half-billion users affected by data leak

#190
post #175

Earlier quoted context omitted.

You are advocating creating perverse incentives. A specific branch of government, a select agency, to become a profit center through continuous finding and fining of ever more wrongdoings. All morally excused because the victims are faceless multinational corps. We all know how badly that goes with speed traps and red light cameras - instead of improving, the road conditions and sometimes even local rules are tweaked…

Fine. Slippery slope perhaps.- Make it a "third sector", properly audited NGO (watchdog, thinktank, foundation ...), with ties to some appropriate umbrella (UN, ICJ), that uses some sort of blockchain solution to fine as needed, and then allocate compensation from this to aggrieved parties, or social programs, compensating not only for loss of privacy, but for the other nasty effects (fake news, emotional distress, p…

Now it makes more sense. Going a bit further you could perform it within the already existing framework: apply criminal penalties where sufficient threshold of harm have been reached. Perhaps even judicial doctrine a bit to better handle cases of large number of small, or statistical, harms - there are parallels to how we already tackle health hazards and other stochastic, broad harms.

The key consideration is avoiding perverse incentives. A stellar example is how the GDPR disaster is unfolding: the smaller websites are still plastered with "cookie warnings" making them less usable, while the larger platforms - Youtube, Google - already pivoted the warning dialog into nagging for logging in, making anonymous browsing incrementally less practical. The difference in power lets the larger players use as a moat the regulation that's prima facie about privacy.

Post reply on HN