Live data from Hacker News

Facebook does not plan to notify half-billion users affected by data leak

reuters.com

241–250 of 315 posts

Re: Facebook does not plan to notify half-billion users affected by data leak

#241
post #160

Earlier quoted context omitted.

Can anyone on HN please explain why, why, WHY are we still using SMS/telephony which has exactly 0 encryption wh---I guess that's the reason? It's insane. I've heard banks using SMS!!!! To send a code. We have TOTP for that! Or even perhaps a push notification or something better than bloody SMS. I refuse to use the networking system altogether. No phones, no calls. Of course you do 'need' a number so I keep one hand…

I don't know anything about the technical details with this, but I wonder why mobile service providers don't just kill off regular SMS and calling, and start providing service exclusively through data connections? The infrastructure for that old stuff can't be free for them, there must be some significant costs associated with it. Maybe Starlink will be able to provide a mobile phone service that only offers a data c…

As far as I know, newer cell phone standards only define how to transmit data. Phone calls are simply layered on top of that.

Re: Facebook does not plan to notify half-billion users affected by data leak

#242

Earlier quoted context omitted.

Certainly I cannot be the only one who finds phone numbers, email addresses, and many other things quite inconsequential compared to name and address. In particular, there could easily be a postal system implemented where the sender would not need the actual physical address of the receiver. The receiver could easily ask the postal service to generate an arbitrary key which could either be single use, or multiple use…

So much of what is considered private "PII" today was considered public information only a generation ago. When I was a kid (1970s): - Names, addresses, and phone numbers were published by the phone company in a book and given to everyone. - Hospital admissions/discharges were published in the local newspaper. - Social Security Number was used for everything. Many people included it on their pre-printed checks. Engra…

> None of this was considered a real violation of privacy, or at least I never heard anyone really express any concerns about it. Unlisted phone numbers were a thing, but very few people had them and it cost extra to have one. Most people wanted to be in the phone book so others could contact them.

Yes, and I think it was wrong to do so.

I think it's ridiculous to be worried about websites tracking one's noncorporeal identity tied to an integer on the internet compared to that everyone in my sport's club can easily retrieve my physical place of residence.

Re: Facebook does not plan to notify half-billion users affected by data leak

#243

"The Facebook spokesman said the social media company *was not confident it had full visibility on which users would need to be notified*." @Facebook here you go: https://haveibeenpwned.com

I think Facebook (rightfully, IMO) would argue the existence of that data dump is no proof that data came from Facebook’s servers. They can’t assume that, or trolls or unscrupulous competitors would start creating ‘Facebook’ data dumps left and right. I do wonder what EU regulators will say about their viewpoint that they do not have to inform their users, though.

While I get what you mean, data has the profile links too. Matching the data to real facebook profiles would be near? impossible if the source was not Facebook.

Re: Facebook does not plan to notify half-billion users affected by data leak

#244

I’ve said it before and I’ll say it again, unless and until, companies like Facebook are fined appropriate amounts they’ll never stop. Quite literally, every business school on the fucking planet will tell you do something if it’s cheaper. It is cheaper for them to not give a fuck, than to give one. Unless they are fined upwards of $20-50bn it’ll never stop because it’s always going to benefit their bottom line. Full…

My only issues with this are that it's impractically hard to protect data to the extent necessary, and large fines become a lever for disgruntled employees to cause massive damage.

Don’t store data you can’t protect. Because something is ‘hard’ doesn’t mean it shouldn’t be done.

Re: Facebook does not plan to notify half-billion users affected by data leak

#245

I’ve said it before and I’ll say it again, unless and until, companies like Facebook are fined appropriate amounts they’ll never stop. Quite literally, every business school on the fucking planet will tell you do something if it’s cheaper. It is cheaper for them to not give a fuck, than to give one. Unless they are fined upwards of $20-50bn it’ll never stop because it’s always going to benefit their bottom line. Full…

I agree but where would the money go?

Re: Facebook does not plan to notify half-billion users affected by data leak

#246

I’ve said it before and I’ll say it again, unless and until, companies like Facebook are fined appropriate amounts they’ll never stop. Quite literally, every business school on the fucking planet will tell you do something if it’s cheaper. It is cheaper for them to not give a fuck, than to give one. Unless they are fined upwards of $20-50bn it’ll never stop because it’s always going to benefit their bottom line. Full…

I agree but where would the money go?

Keep the relevant enforcement agencies fed and watered for starters, and the rest goes to govt as a contribution towards the usual things that taxes pay for.

Re: Facebook does not plan to notify half-billion users affected by data leak

#247
post #179

Earlier quoted context omitted.

> If Facebook has since deleted some of those accounts or associated phone numbers, they may no longer have a way to contact those users That would totally defy logic. I don't think that Facebook deletes anything ever .

I deleted my account a few months ago and was pleasantly surprised to find that it didn't surface in the breach. It could just be hiding in a different datastore of course, but it's definitely more fucks than I thought they gave.

well i deleted mine in october 2019 and i’m in.....

Re: Facebook does not plan to notify half-billion users affected by data leak

#248
post #83

Earlier quoted context omitted.

"Where?!" Everywhere. It's being phased out in many places, but as a rule of thumb, mostly everywhere still. "known to be very bad ... been shouting ..." Right, yeah, to put it in some perspective remember that you're talking second factor here. This is not your login, this is a secondary confirmation and you still need some serious motivation to bypass it. It's definitely doable, I work in security and I know what k…

I'd never seen or heard of it being used for payments before, which is why I asked - I'd heard of phone numbers being used as account names (effectively) in some payment systems, but being involved in the workflow of making payments is entirely novel to me. I'm aware it's not your login, but it feels the same as asking someone for publicly searchable information to "verify your identity" - an additional "security" st…

> it's just frustrating to watch many companies deploy it and go home when there are better options

I do agree with you there. To be clear, while I think the problem is of a smaller magnitude, I do agree with your general point. Other alternatives like very simple TOTP tokens additionally don't require a phone number and so you don't have this stupid "add your phone number now, we'll use it only for security, pinky swear!" prompts.

Heck, there could even be an argument that SMS OTP is now illegal with GDPR unless the user gives explicit consent. You can't use user data (PII) if it's not with consent, for a legitimate purpose, to fulfill a contract, for the user's own good, to comply with law enforcement, and I'm probably forgetting one or two reasons. Now that it's clear that stuff like TOTP is a better alternative, there is no reason to process people's phone number anymore for this purpose, making it impossible for you to send that SMS OTP. (Of course, you'd have to convince a judge that TOTP is better than SMS before we actually get case law on this specific use of a phone number so... *mumbles something about nine-tenths of the law*.)

Re: Facebook does not plan to notify half-billion users affected by data leak

#249

"The Facebook spokesman said the social media company *was not confident it had full visibility on which users would need to be notified*." @Facebook here you go: https://haveibeenpwned.com

I think Facebook (rightfully, IMO) would argue the existence of that data dump is no proof that data came from Facebook’s servers. They can’t assume that, or trolls or unscrupulous competitors would start creating ‘Facebook’ data dumps left and right. I do wonder what EU regulators will say about their viewpoint that they do not have to inform their users, though.

>I think Facebook (rightfully, IMO) would argue the existence of that data dump is no proof that data came from Facebook’s servers.

Mark Zuckerbergs phone number was in the dataset. It came from Facebook.

Re: Facebook does not plan to notify half-billion users affected by data leak

#250
post #212

Earlier quoted context omitted.

If customers do not care enough to stop using the product then there is no harm. Put in another way: the people you are trying to protect don't want your protection, because they don't care enough about the breach to stop using the product. They shouldn't be learning about the breaches from the company that has been breached because that gives the company too much power. Instead we should empower watchdog organizatio…

> If customers do not care enough to stop using the product then there is no harm. Facebook users (notably not customers) are the ones being harmed here, and they don't exactly have free reign to choose the platform their communities talk and organize on. If I choose not to use Facebook then I'm isolating myself from my community.

Relying on one irresponsible for-profit organization for your communications is a disaster waiting to happen. By using that service, you enable them to continue. It takes two to tango.
Post reply on HN