Live data from Hacker News

Facebook says new bug allowed apps access to private photos of up to 6.8M users

washingtonpost.com

11–20 of 280 posts

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#13

> The bug also impacted photos that people uploaded to Facebook but chose not to post. What about, for example, pictures sent in a private message? I'm so very glad I deleted my account months ago.

In so much that they let you delete your account.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#14

> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…

Useless, repeatedly broken promises. It is time to see how much teeth the GDPR really has.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#15
post #13

> The bug also impacted photos that people uploaded to Facebook but chose not to post. What about, for example, pictures sent in a private message? I'm so very glad I deleted my account months ago.

In so much that they let you delete your account.

If they aren't actually deleting accounts then they are going to end up with a hefty fine under the GPDR one day...

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#16
“Private” photos that people uploaded to Facebook.

Sounds like a good time to reiterate the advice: Don’t upload things to the internet that you don’t want to be on the internet. That way there won’t be any of your things on the internet that you didn’t want to be there.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#17
As usual, I'd like to point out how scummy this site really is.

The paywall advertises a "Premium EU Ad-Free Subscription" which is more expensive than the standard subscription and explicitly states "No on-site advertising or third-party ad tracking" as one of the perks.

Trying to buy it has the following:

> By subscribing, you agree to the above terms, the Terms of Service, Digital Products Terms of Sale & Privacy Policy.

On the privacy policy, we have this:

> hen you use our Services, third parties may collect or receive certain information about you and/or your use of the Services (e.g., hashed data, click stream information, browser type, time and date, information about your interactions with advertisements and other content), including through the use of cookies, beacons, mobile ad identifiers, and similar technologies, in order to provide content, advertising, or functionality or to measure and analyze ad performance, on our Services or other websites or platforms. This information may be combined with information collected across different websites, online services, and other linked or associated devices. These third parties may use your information to improve their own services and consistent with their own privacy policies.

There is absolutely no mention of the "Premium" ad-free subscription in the privacy policy at all, so they are still granting themselves the right to stalk you all over the place even with the premium, more expensive subscription.

Not to mention, the privacy policy page itself loads a handful of different trackers before any kind of consent was even granted. I can see Google Analytics, something from "c.go-mpulse.net", something else from "bam.nr-data.net" explicitly sending my user-agent in the URL (why? They'd get it in the headers anyway), Google News JS, Google Pay and the New Relic JS agent.

My only response to this is a big "fuck you" and this link: https://outline.com/zd5du7 so you can read the content without any of that garbage and without paying them since they don't even deserve a single penny.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#18
post #12

I think it should be clear to everyone at this point that nothing on Facebook is private. Don't put anything there you wouldn't post publicly.

Any company that talks about their old "move fast and break things" motto as if it's a good idea should be treated this way (or not used at all).

In industry perspective: We call ourselves "engineers", but real engineers are held accountable when they sign off on using an untested metal alloy in bridge joists and then people die when the bridge collapses. Facebook's constant bad engineering may not kill people directly, but it does lead to a lot of really important information stolen, peoples financial future being ruined, and who knows what other consequences for their users. If you still work for Facebook in this day and age you should be ashamed of yourself; I know people can justify just about anything while claiming that they'll "make it better from the inside" or because they just need to collect a fat paycheck and are comfortable and don't want to look for something new, but we need to fight these impulses anywhere we work.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#19

> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…

Until consumers reveal that they care this is how it will be unless governments regulate/punish.

my response to this is always in the vein of, "how exactly should customers show they care?"

"Well, leave!" isn't an option. They can't leave. Quitting Facebook when you're an active user means you lose a huge amount of social contact. I can think of a dozen people I know who are there because it's how they send baby pics and the like to family. They're non-technical and don't care about federated mastodons, they just want to see their niece and go to their high school reunion.

So yeah they get really mad at this stuff but the network effect is so strong, you can't simultaneously convince the entire graduating class of whatever to plan reunions via some new thing when 1)everyone's already on facebook and 2)they've been using it for so long it's part of their workflow.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#20
post #11

Does it fall under GDPR violation?

No. Unless they didn't report it to the regulators.

Article 34 clearly states that the breached organization must inform the data subject "without undue delay". Given that the event occurred in September, and it is now December, I would characterize that as an undue delay.

There should be GDPR consequences of this - it's time that law got properly put to the test.

Post reply on HN