Live data from Hacker News

Facebook does not plan to notify half-billion users affected by data leak

reuters.com

251–260 of 315 posts

Re: Facebook does not plan to notify half-billion users affected by data leak

#251

Earlier quoted context omitted.

My only issues with this are that it's impractically hard to protect data to the extent necessary, and large fines become a lever for disgruntled employees to cause massive damage.

Don’t store data you can’t protect. Because something is ‘hard’ doesn’t mean it shouldn’t be done.

That's a great line for a stump speech, but try building this system yourself.

Re: Facebook does not plan to notify half-billion users affected by data leak

#252
post #234
post #92

Earlier quoted context omitted.

Birthday is a form of identity verification too, for password reset.

None of the birthdays I enter are real. :P

and no one should put real birthday lol. Birthday is mostly used for targeting ads.

This is why facebook can say to advertisers, "We mostly have young people using our service. So please put your money on our company"

And yes using account of 60-70 year old always receives less ads :D

Re: Facebook does not plan to notify half-billion users affected by data leak

#253

I’ve said it before and I’ll say it again, unless and until, companies like Facebook are fined appropriate amounts they’ll never stop. Quite literally, every business school on the fucking planet will tell you do something if it’s cheaper. It is cheaper for them to not give a fuck, than to give one. Unless they are fined upwards of $20-50bn it’ll never stop because it’s always going to benefit their bottom line. Full…

Here in Mexico, in theory every person record that is leaked without the holder permission can get the company a $5000 fine. Given that this leak has at least 50,000 records from Mexicans, Facebook could be fined up to $250,000,000.

I don't understand why the government doesn't go for these type of things. On one side... it is easy money for the federation. On the other side, in a "personal" level for the bureaucrats, it is at least some good money they can keep corruptly.

Re: Facebook does not plan to notify half-billion users affected by data leak

#254

I’ve said it before and I’ll say it again, unless and until, companies like Facebook are fined appropriate amounts they’ll never stop. Quite literally, every business school on the fucking planet will tell you do something if it’s cheaper. It is cheaper for them to not give a fuck, than to give one. Unless they are fined upwards of $20-50bn it’ll never stop because it’s always going to benefit their bottom line. Full…

Here in Mexico, in theory every person record that is leaked without the holder permission can get the company a $5000 fine. Given that this leak has at least 50,000 records from Mexicans, Facebook could be fined up to $250,000,000. I don't understand why the government doesn't go for these type of things. On one side... it is easy money for the federation. On the other side, in a "personal" level for the bureaucrats…

When I think about a small, bootstrapped operation, that kind of fine would bankrupt them. When I think about Facebook, that kind of fine wouldn’t even bother them. Not sure what the answer there is. At some level a very harsh fine says, no matter the value of the product, if you screw up we shut you down, unless you’re big enough to not care at all.

Re: Facebook does not plan to notify half-billion users affected by data leak

#255
post #79

Earlier quoted context omitted.

Presumably your birth name given to you by your parents. Describing it as "state given" seems intentionally misleading...

It should be called "state-recognized". The state does not give you name, but it registers it and uses it to recognize you in various situations. Usually the name is not enough to identify a person (and fun/disaster ensues when this is attempted) so, usually, more information is needed to identify a person.

It should probably be "legal" name. https://en.wikipedia.org/wiki/Legal_name

Re: Facebook does not plan to notify half-billion users affected by data leak

#256

"The Facebook spokesman said the social media company *was not confident it had full visibility on which users would need to be notified*." @Facebook here you go: https://haveibeenpwned.com

I use yourdomain@mydomain to sign up for accounts. name@mydomain is something I try to only give to friends.

According to that site, my personal email has been leaked by Adobe, and by a bunch of shady database firms I've never heard of.

(On further reflection, I probably used my Google account to log into Adobe, which leaks my personal email to the site I'm logging into.)

Re: Facebook does not plan to notify half-billion users affected by data leak

#257

I’ve said it before and I’ll say it again, unless and until, companies like Facebook are fined appropriate amounts they’ll never stop. Quite literally, every business school on the fucking planet will tell you do something if it’s cheaper. It is cheaper for them to not give a fuck, than to give one. Unless they are fined upwards of $20-50bn it’ll never stop because it’s always going to benefit their bottom line. Full…

I agree but where would the money go?

In this period? Helping business and people hit by lockdowns. Vaccines. The list is too long to fit in this page. If there ever was a time for governments to go after megacorps money, this is it.

Re: Facebook does not plan to notify half-billion users affected by data leak

#258

Earlier quoted context omitted.

I'd never seen or heard of it being used for payments before, which is why I asked - I'd heard of phone numbers being used as account names (effectively) in some payment systems, but being involved in the workflow of making payments is entirely novel to me. I'm aware it's not your login, but it feels the same as asking someone for publicly searchable information to "verify your identity" - an additional "security" st…

What better options are there that have approximately the same ease of use? SMS works with every conceivable phone, even most landlines if need be, users don't have to install a separate authenticator app, which may require a Google/iCloud password (now where did I put that post-it note?), that takes up space that may be scarce on low-end phones and that may not even be compatible with very old phones, leaving affect…

> users don't have to install a separate authenticator app, which may require a Google/iCloud password

If they wish to use Apple then that is their own choice, but on Android it's quite trivial to download Red Hat's open source authenticator app[1] from f-droid (the website, you don't even have to install the store if you don't want that). It's quite bare bones on graphics and features, doing only what you need it to (the f-droid build is 0.5MB, frankly still large for what it does but consider that it's like half of a single photo).

And if people don't have a phone with support for apps, then you can still fall back to SMS. Doesn't mean you need to force everyone down to that level.

Fun fact: my grandpa can't use SMS either, your solution is not as universal as you make it seem. He never has been able to due to sight issues (it's not an age thing, though it doesn't help if you're close to illiterate and now need to start to learn how to use solutions for sight-impaired people due to this information age having onset). Does that mean we cannot support anything better than sending a letter, which is accessible to him as well? Can't we have the better solution as well as the accessible one?

[1] https://f-droid.org/en/packages/org.fedorahosted.freeotp/

> With SMS, all the user needs is a phone number.

No no, you got that backwards. All Facebook needs is your phone number, or whoever it is that pinky promises to only use your phone number for security. I get what you're saying about everyone having a phone number that you can identify them by, but that is also the issue: everyone has typically a very very limited amount of phone numbers (and typically linked to a government ID) whereas a throwaway email is easy to make and each TOTP code is throwaway by design. I think there's something to say for supporting this.

Re: Facebook does not plan to notify half-billion users affected by data leak

#259

I’ve said it before and I’ll say it again, unless and until, companies like Facebook are fined appropriate amounts they’ll never stop. Quite literally, every business school on the fucking planet will tell you do something if it’s cheaper. It is cheaper for them to not give a fuck, than to give one. Unless they are fined upwards of $20-50bn it’ll never stop because it’s always going to benefit their bottom line. Full…

Or just break them up? Both parties in the US have spoken about breaking the "Big Tech" monopolies for a while now. Maybe some grass roots activism could finally get it some traction?

We have a three strikes law in CA. I haven't done any research to find out how effective its been in reducing crime - but something similar for big companies like Facebook might be a way of dealing with this nonsense?

Re: Facebook does not plan to notify half-billion users affected by data leak

#260
post #190

Earlier quoted context omitted.

Fine. Slippery slope perhaps.- Make it a "third sector", properly audited NGO (watchdog, thinktank, foundation ...), with ties to some appropriate umbrella (UN, ICJ), that uses some sort of blockchain solution to fine as needed, and then allocate compensation from this to aggrieved parties, or social programs, compensating not only for loss of privacy, but for the other nasty effects (fake news, emotional distress, p…

Now it makes more sense. Going a bit further you could perform it within the already existing framework: apply criminal penalties where sufficient threshold of harm have been reached. Perhaps even judicial doctrine a bit to better handle cases of large number of small, or statistical, harms - there are parallels to how we already tackle health hazards and other stochastic, broad harms. The key consideration is avoidi…

> there are parallels to how we already tackle health hazards and other stochastic, broad harms.

I like your approach to these damages as stochastic, broad, ergo "actuarially" manageable ...

Post reply on HN