Live data from Hacker News

Two More Cases of Third-Party Facebook App Data Exposure

upguard.com

11–20 of 48 posts

Re: Two More Cases of Third-Party Facebook App Data Exposure

#11
post #10

Earlier quoted context omitted.

Not clickbait in the slightest. This is not about Facebook per se about persistence of their shared data - my information - once it's made public. HIPAA, by comparison has all sorts of statements about PII and business associates. But apparently FB can share with whoever has a pulse and I can find out about it later via Shodan. I wrote this even with the original link and version of the headline.

"Millions of Facebook Records Found on Amazon Cloud Servers" was the original headline. That headline the first thing you would likely think is Facebook was using AWS and left some data open somewhere. It 100% implied Facebook was doing more wrong now, instead of the companies that already had the data from the previous issues were not handling the data correctly. Yes this news is still notable. But the headline gave…

[deleted]

Re: Two More Cases of Third-Party Facebook App Data Exposure

#12
post #10

Earlier quoted context omitted.

Not clickbait in the slightest. This is not about Facebook per se about persistence of their shared data - my information - once it's made public. HIPAA, by comparison has all sorts of statements about PII and business associates. But apparently FB can share with whoever has a pulse and I can find out about it later via Shodan. I wrote this even with the original link and version of the headline.

"Millions of Facebook Records Found on Amazon Cloud Servers" was the original headline. That headline the first thing you would likely think is Facebook was using AWS and left some data open somewhere. It 100% implied Facebook was doing more wrong now, instead of the companies that already had the data from the previous issues were not handling the data correctly. Yes this news is still notable. But the headline gave…

I swear, every HN article, you get 10% of the comments are about the article being discussed, and the other 90% are people quibbling over the headline.

Ok, that's an exaggeration.

And when the comments are good, they are really good. Makes the entire HN experience worthwhile.

Re: Two More Cases of Third-Party Facebook App Data Exposure

#13
post #10

Earlier quoted context omitted.

"Millions of Facebook Records Found on Amazon Cloud Servers" was the original headline. That headline the first thing you would likely think is Facebook was using AWS and left some data open somewhere. It 100% implied Facebook was doing more wrong now, instead of the companies that already had the data from the previous issues were not handling the data correctly. Yes this news is still notable. But the headline gave…

I swear, every HN article, you get 10% of the comments are about the article being discussed, and the other 90% are people quibbling over the headline. Ok, that's an exaggeration. And when the comments are good, they are really good. Makes the entire HN experience worthwhile.

Titles R Hard.

Re: Two More Cases of Third-Party Facebook App Data Exposure

#14
post #10

Earlier quoted context omitted.

"Millions of Facebook Records Found on Amazon Cloud Servers" was the original headline. That headline the first thing you would likely think is Facebook was using AWS and left some data open somewhere. It 100% implied Facebook was doing more wrong now, instead of the companies that already had the data from the previous issues were not handling the data correctly. Yes this news is still notable. But the headline gave…

I swear, every HN article, you get 10% of the comments are about the article being discussed, and the other 90% are people quibbling over the headline. Ok, that's an exaggeration. And when the comments are good, they are really good. Makes the entire HN experience worthwhile.

So sorry? I mentioned Shodan as a way of tying it to other leaks of negligence and I why I thought this was relevant, and not just a tossaway clickbait article. I think my disagreement is deeper in nature than semantic on the headline. I even dropped in HIPAA as a model for regulations of shared private info, as gross as it may be to think about in a regulatory sense.

Re: Two More Cases of Third-Party Facebook App Data Exposure

#15
post #10

Earlier quoted context omitted.

Not clickbait in the slightest. This is not about Facebook per se about persistence of their shared data - my information - once it's made public. HIPAA, by comparison has all sorts of statements about PII and business associates. But apparently FB can share with whoever has a pulse and I can find out about it later via Shodan. I wrote this even with the original link and version of the headline.

"Millions of Facebook Records Found on Amazon Cloud Servers" was the original headline. That headline the first thing you would likely think is Facebook was using AWS and left some data open somewhere. It 100% implied Facebook was doing more wrong now, instead of the companies that already had the data from the previous issues were not handling the data correctly. Yes this news is still notable. But the headline gave…

Eh, I don’t really care if it is a failure on the point of Facebook engineers or a failure on the point of Facebook data policy that allowed other engineers to post data about me in an insuecure manner. Seems like splitting hairs here.

Re: Two More Cases of Third-Party Facebook App Data Exposure

#16
Anecdata: A couple of years ago, I was at one of the very first (not sure if not the only one) FB connect meetings here in Dallas.

A couple of local startups were talking about how to leverage the "login with facebook" button. It was a big thing...

Most people I talked to, told me: "The very first thing I do is to save all the email of their friends" or stuff like that.

So yeah, this was years ago. I'm failing to see how this is a surprise at all.

Re: Two More Cases of Third-Party Facebook App Data Exposure

#17
Unfortunately, Facebook had a fundamental misunderstanding of how privacy has to work, and their users will be paying for their error for years.

If it's earth-shatteringly bad for your users if their private data is leaked by a third-party, you cannot exfiltrate that data to a thrid-party. Full stop. No amount of policy un-leaks data, and "You cannot continue to operate as a Facebook service" is an empty threat the moment it becomes more valuable for the third-party to violate the agreement than to continue to operate as a Facebook service.

The takeaway: if you are responsible for user privacy, you must do the computations on the user's data. Have partners ship you the computations they wish to do, vet them, and then ship them results compliant with your users' expectations. Don't hand third-parties a subset of the keys to the kingdom and expect an honor system to preserve user privacy.

Re: Two More Cases of Third-Party Facebook App Data Exposure

#18

Unfortunately, Facebook had a fundamental misunderstanding of how privacy has to work, and their users will be paying for their error for years. If it's earth-shatteringly bad for your users if their private data is leaked by a third-party, you cannot exfiltrate that data to a thrid-party. Full stop. No amount of policy un-leaks data, and "You cannot continue to operate as a Facebook service" is an empty threat the m…

How would this work in the case of data portability? If Facebook were to be forced to provide an API that allowed users to export all of their data to a competing social network would Facebook be responsible for ensuring that the competitor was using the data responsibly?

Re: Two More Cases of Third-Party Facebook App Data Exposure

#20

Unfortunately, Facebook had a fundamental misunderstanding of how privacy has to work, and their users will be paying for their error for years. If it's earth-shatteringly bad for your users if their private data is leaked by a third-party, you cannot exfiltrate that data to a thrid-party. Full stop. No amount of policy un-leaks data, and "You cannot continue to operate as a Facebook service" is an empty threat the m…

Facebook used to be much better at locking down third-party exfiltration. But back in the early 2010s, the zeitgeist was against it; there were countless articles in the genre of "I'm a random third party developer, and Facebook is trying to stop me from exfiltrating massive dumps of my user's data! How anticompetitive!" So they decided to start being more open.
Post reply on HN