Live data from Hacker News

Meta fined $102M for storing passwords in plain text

engadget.com

131–136 of 136 posts

Re: Meta fined $102M for storing passwords in plain text

#131
post #118

Earlier quoted context omitted.

The $18349 Billion GDP. What did you think I was referring to? Were you trying to be daft?

I said the EU is not that big of a market. It’s less than 1/3 of the global GDP. We seem to have different definitions of a big market.

Clearly but whatever definition you have that doesn’t include $18349 Billion is ridiculous

Re: Meta fined $102M for storing passwords in plain text

#132
post #28

It's mentioned in nested comments, but (as you'd probably expect) meta does not intend to store passwords in plaintext. There was a bug where they were logging plaintext passwords for some period of time e.g., when someone tried to log in etc.,.

Sanitize your outputs?

Re: Meta fined $102M for storing passwords in plain text

#133
post #74

Earlier quoted context omitted.

How long has that even been a regulation and in which countries does it apply? Software engineers are trained to view these kinds of things as bugs. Legal isn't trained to monitor bug trackers.

It’s part of GDPR. I’ve been given training on it at all (3) companies I’ve worked for and training has always included what constitutes a breach and what to do. I would hope any company would treat it as an incident rather than just a bug where senior enough folks would be involved to know what their responsibilities are.

Can't blame a rogue junior engineer if that happens.

Re: Meta fined $102M for storing passwords in plain text

#134
post #84

Earlier quoted context omitted.

“lots” not really as most companies want accesss to european market. Also no you dont need to consult lawyers when writing code. You just dont track and save data and do questionable stuff with it. Saving passwords in logs is surely security issue first before its GDPR issue.

yes it's a security issue but you wouldn't "expect" to get fined millions of dollars. Do I think we should punish companies for storing passwords in plaintext? Yes. Would I expect that a bug and devs untrained in GDPR best practices could lead to fines? No. Usually in software engineering you don't get your company fined for making terrible mistakes unless you're in a field like finance. This was just passwords which…

>yes it's a security issue but you wouldn't "expect" to get fined millions of dollars.

The penalties are based on percentage of turnover.

Re: Meta fined $102M for storing passwords in plain text

#135
post #93

Earlier quoted context omitted.

it's GDPR from the subheader > The Irish Data Protection Commission found that the company violated several GDPR rules. this is why lots of websites block the EU from accessing. You basically need to consult with lawyers to make sure you're not accidentally breaking the law when writing a codebase.

I see this comment pop up here often in these threads about EU fines and regulations. "Apple/company should just call the EUs bluff and stop selling in the EU!". Apple's a good example because they're such an incredibly global brand, who should be less reliant on EU customers. Yet Europe is responsible for >20% of their revenue. Shareholders would eat you alive for just "nope"ing away from that. Yes, US GDP/capita is…

see Apple's 14 billion tax troubles in Ireland. For years these companies have been using the European operations as part of the tax avoidance schemes.

Don't mess with the Flemish has been good advice for 600 of the last thousand years.

Re: Meta fined $102M for storing passwords in plain text

#136
post #93

Earlier quoted context omitted.

I see this comment pop up here often in these threads about EU fines and regulations. "Apple/company should just call the EUs bluff and stop selling in the EU!". Apple's a good example because they're such an incredibly global brand, who should be less reliant on EU customers. Yet Europe is responsible for >20% of their revenue. Shareholders would eat you alive for just "nope"ing away from that. Yes, US GDP/capita is…

Noping out of europe would create a vacuum that would be filled by a competitor who would fully comply with the consumer protecting EU rules. Rules that many consumers in other nations would love to have themselves but don't because of regulatory capture and regular corruption. Those consumer friendly products would become popular outside of Europe. Big-US-monopoly-company would lose dominance. They would either have…

The company with a board of directors responsible to shareholders noping out of anywhere isn't a choice.
Post reply on HN