Facebook security hole allows viewing of private photos
51–60 of 143 posts
Re: Facebook security hole allows viewing of private photos
#52This isn't even a security hole, it's a complete security disaster. Did they even think through the process for five minutes before they built that? I mean, there aren't even any hacks involved. Nice find.
> there aren't even any hacks involved I doubt law enforcement would see it that way. Downloading photos with this method is not much different than guessing somebody's email or voicemail password; you're accessing something you're not supposed to. See 18 U.S.C. § 1030(a)(2)(C) and § 2701.
Re: Facebook security hole allows viewing of private photos
#53Earlier quoted context omitted.
I'm downvoting you for saying I think it's a stretch to call this a mistake If it wasn't on purpose, it was a mistake. Period. It might be inexcusable, as you later pointed out, but it was still unintentional. Everyone likes to hate on Facebook. If this was a YC startup, I suspect people would be more forgiving.
That's true, if it was a group of three young people starting a new business, I would be more forgiving than about a multi billion dollar corporation with hundreds of engineers and millions in resources. It was a mistake, but another word for a mistake is 'negligence'. The fact that something like this can happen illustrates systemic shortcomings at the company. Millions of people are depending on them to enforce the…
No it isn't.
Re: Facebook security hole allows viewing of private photos
#54someone [1] pulled this trick on Zuck's account [2] 1. http://twitter.com/#!/flyosity/status/144065873743839233 2. http://imgur.com/a/PrLrB
Re: Facebook security hole allows viewing of private photos
#55Earlier quoted context omitted.
> there aren't even any hacks involved I doubt law enforcement would see it that way. Downloading photos with this method is not much different than guessing somebody's email or voicemail password; you're accessing something you're not supposed to. See 18 U.S.C. § 1030(a)(2)(C) and § 2701.
This is probably closer to guessing someone's phone number than their password.
Re: Facebook security hole allows viewing of private photos
#56someone [1] pulled this trick on Zuck's account [2] 1. http://twitter.com/#!/flyosity/status/144065873743839233 2. http://imgur.com/a/PrLrB
edit: imgur album was also created 4 hrs ago
Re: Facebook security hole allows viewing of private photos
#57Funny how something like this is originally posted on a body building forum. I think the first reports of the recent Penn State scandal were posted there too (around a year ago.) Who would have thought that's where you'd first find such things?
Re: Facebook security hole allows viewing of private photos
#58Funny how something like this is originally posted on a body building forum. I think the first reports of the recent Penn State scandal were posted there too (around a year ago.) Who would have thought that's where you'd first find such things?
As pud mentioned, they're basically /b/tards.
Re: Facebook security hole allows viewing of private photos
#59Earlier quoted context omitted.
I think it's a stretch to call this "just" a mistake. First of all, there isn't any malicious code that has to be run to execute it, it's a simple as clicking a few buttons in the UI. Secondly, Facebook is a site with hundreds of millions of users managing billions of private photos. With the amount of revenue & number of developers they have, it's inexcusable that they can't think through a simple process like this…
I'm downvoting you for saying I think it's a stretch to call this a mistake If it wasn't on purpose, it was a mistake. Period. It might be inexcusable, as you later pointed out, but it was still unintentional. Everyone likes to hate on Facebook. If this was a YC startup, I suspect people would be more forgiving.
'a mistake' puts this at the same level of seriousness as other problems. This is at least a big mistake.
Re: Facebook security hole allows viewing of private photos
#60If that doesn't prove that FB's developers aren't thinking about security, I don't know what would. Nobody who is in a culture of protecting security would even consider building this.
That's why their philosophy is 'Move fast and break stuff'. The alternative might be a slow moving bureaucracy that never iterates new features.