Earlier quoted context omitted.
Here in Mexico, in theory every person record that is leaked without the holder permission can get the company a $5000 fine. Given that this leak has at least 50,000 records from Mexicans, Facebook could be fined up to $250,000,000. I don't understand why the government doesn't go for these type of things. On one side... it is easy money for the federation. On the other side, in a "personal" level for the bureaucrats…
When I think about a small, bootstrapped operation, that kind of fine would bankrupt them. When I think about Facebook, that kind of fine wouldn’t even bother them. Not sure what the answer there is. At some level a very harsh fine says, no matter the value of the product, if you screw up we shut you down, unless you’re big enough to not care at all.
Facebook does not plan to notify half-billion users affected by data leak
261–270 of 315 posts
Re: Facebook does not plan to notify half-billion users affected by data leak
#262Re: Facebook does not plan to notify half-billion users affected by data leak
#263Earlier quoted context omitted.
> If customers do not care enough to stop using the product then there is no harm. Facebook users (notably not customers) are the ones being harmed here, and they don't exactly have free reign to choose the platform their communities talk and organize on. If I choose not to use Facebook then I'm isolating myself from my community.
Relying on one irresponsible for-profit organization for your communications is a disaster waiting to happen. By using that service, you enable them to continue. It takes two to tango.
Re: Facebook does not plan to notify half-billion users affected by data leak
#264This leak is putting people's lives at risk. What is truly damaging about this breach is that it allows for bidirectional mapping of phone ⭤ name (and often location, since the data can include town/employer). The risk is much bigger than "I'm going to get more phone spam." Examples: - An abusive ex/stalker type can now search by name and find his ex's phone number and maybe even city/town. - Have you ever dealt with…
>The creation of a standardized & subsidized token/OTP platform. In the US for example, you should be able to go to the post office and get a NIST approved token generator, which should be mandated to be used by all banks and replace SMS and SSN as authentication.
DeID
>A pseudonimity middle-layer (ie, Stripe for Privacy). For example, when I buy a t-shirt online, I should be able to simply give the merchant my pseudonym, and they shouldn't store my actual name & address. If they want to store that there should be much much higher data protection requirements.
Deid, paired with the fact that i don't give them anything. I send them the money instead of giving away my information. This is a key distinction. When i pay for things with my credit card, I am swiping my card, they are saving my information and running my card. Sending them money, with some DeID to acknowledge receipt is entirely different. Instead of them 'Taking', I am 'Giving'.
Also, the Deid can come with a parsing function that 'Shares' the keys to your address and name, without the ability to capture your information. It works directly with the EDI to provide the 'keys' to your address but never allows them to store it.
>This infrastructure should be free market but with a "public option" in order to prevent oligopolization of these services.
Polkadot and many other cryptos with governance is also solving this problem.
Re: Facebook does not plan to notify half-billion users affected by data leak
#265Earlier quoted context omitted.
Don’t store data you can’t protect. Because something is ‘hard’ doesn’t mean it shouldn’t be done.
That's a great line for a stump speech, but try building this system yourself.
Re: Facebook does not plan to notify half-billion users affected by data leak
#266Earlier quoted context omitted.
The way your comment is structured, it is not obvious that it is a question. > They could (and must) notify the ones they still have data about. I agree strongly. For what it's worth, this is absolutely not what I took away from your other comment.
The question mark at the end of their original comment is a strong indicator that it is indeed a question.
The sentence structure is a strong indicator that this is something other than a question.
This could easily be interpreted as:
"They no longer have an obligation to notify the rest, because they might have deleted some of the accounts...duh"
The commenter's clarification removed the ambiguity, but let's not pretend the original statement was crystal clear. I think the difficulty interpreting the comment is also partially a result of just how passive-aggressive many comment threads have become. After clarification, I understand the original intent. Without that clarification, there are two interpretations.
A different way to say this would be:
> "Are you saying they no longer have an obligation to notify the rest just because some of the accounts might have been deleted?"
Re: Facebook does not plan to notify half-billion users affected by data leak
#267Question: is it legal to download these files to see what data is leaked about yourself? My issue with haveibeenpwned is that I don't know what's leaked. Note, I'm super happy with the fact that the service exist because I'm happy with the fact to know who of my social circle is in it, so I can notify them. But I don't know exactly what's leaked. Are passwords leaked, for example? What about my social info is on ther…
Assume these columns are compromised. As a general rule it probably doesn't hurt to change the password and any you've reused.
Re: Facebook does not plan to notify half-billion users affected by data leak
#268Earlier quoted context omitted.
Here in Mexico, in theory every person record that is leaked without the holder permission can get the company a $5000 fine. Given that this leak has at least 50,000 records from Mexicans, Facebook could be fined up to $250,000,000. I don't understand why the government doesn't go for these type of things. On one side... it is easy money for the federation. On the other side, in a "personal" level for the bureaucrats…
When I think about a small, bootstrapped operation, that kind of fine would bankrupt them. When I think about Facebook, that kind of fine wouldn’t even bother them. Not sure what the answer there is. At some level a very harsh fine says, no matter the value of the product, if you screw up we shut you down, unless you’re big enough to not care at all.
One thing I will tell you, when I was in charge of the data of a FinTech in Mexico, we were VERY aware of those fines and took a lot of care regarding our security.
Re: Facebook does not plan to notify half-billion users affected by data leak
#269Earlier quoted context omitted.
That's a great line for a stump speech, but try building this system yourself.
Your argument doesn't hold water - lots of systems have users without collecting their phone numbers.
Re: Facebook does not plan to notify half-billion users affected by data leak
#270I’ve said it before and I’ll say it again, unless and until, companies like Facebook are fined appropriate amounts they’ll never stop. Quite literally, every business school on the fucking planet will tell you do something if it’s cheaper. It is cheaper for them to not give a fuck, than to give one. Unless they are fined upwards of $20-50bn it’ll never stop because it’s always going to benefit their bottom line. Full…
If customers do not care enough to stop using the product then there is no harm. Put in another way: the people you are trying to protect don't want your protection, because they don't care enough about the breach to stop using the product. They shouldn't be learning about the breaches from the company that has been breached because that gives the company too much power. Instead we should empower watchdog organizatio…
Likewise we shouldn't expect people to all be computer security experts, but we should expect regulators to keep us safe by creating standards and enforcing penalties for companies failing to meet them. I'm not saying we need a new regulatory agency, but we do need enforced regulation with scalable teeth.