Earlier quoted context omitted.
Not clickbait in the slightest. This is not about Facebook per se about persistence of their shared data - my information - once it's made public. HIPAA, by comparison has all sorts of statements about PII and business associates. But apparently FB can share with whoever has a pulse and I can find out about it later via Shodan. I wrote this even with the original link and version of the headline.
"Millions of Facebook Records Found on Amazon Cloud Servers" was the original headline. That headline the first thing you would likely think is Facebook was using AWS and left some data open somewhere. It 100% implied Facebook was doing more wrong now, instead of the companies that already had the data from the previous issues were not handling the data correctly. Yes this news is still notable. But the headline gave…
Two More Cases of Third-Party Facebook App Data Exposure
11–20 of 48 posts
Re: Two More Cases of Third-Party Facebook App Data Exposure
#12Earlier quoted context omitted.
Not clickbait in the slightest. This is not about Facebook per se about persistence of their shared data - my information - once it's made public. HIPAA, by comparison has all sorts of statements about PII and business associates. But apparently FB can share with whoever has a pulse and I can find out about it later via Shodan. I wrote this even with the original link and version of the headline.
"Millions of Facebook Records Found on Amazon Cloud Servers" was the original headline. That headline the first thing you would likely think is Facebook was using AWS and left some data open somewhere. It 100% implied Facebook was doing more wrong now, instead of the companies that already had the data from the previous issues were not handling the data correctly. Yes this news is still notable. But the headline gave…
Ok, that's an exaggeration.
And when the comments are good, they are really good. Makes the entire HN experience worthwhile.
Re: Two More Cases of Third-Party Facebook App Data Exposure
#13Earlier quoted context omitted.
"Millions of Facebook Records Found on Amazon Cloud Servers" was the original headline. That headline the first thing you would likely think is Facebook was using AWS and left some data open somewhere. It 100% implied Facebook was doing more wrong now, instead of the companies that already had the data from the previous issues were not handling the data correctly. Yes this news is still notable. But the headline gave…
I swear, every HN article, you get 10% of the comments are about the article being discussed, and the other 90% are people quibbling over the headline. Ok, that's an exaggeration. And when the comments are good, they are really good. Makes the entire HN experience worthwhile.
Re: Two More Cases of Third-Party Facebook App Data Exposure
#14Earlier quoted context omitted.
"Millions of Facebook Records Found on Amazon Cloud Servers" was the original headline. That headline the first thing you would likely think is Facebook was using AWS and left some data open somewhere. It 100% implied Facebook was doing more wrong now, instead of the companies that already had the data from the previous issues were not handling the data correctly. Yes this news is still notable. But the headline gave…
I swear, every HN article, you get 10% of the comments are about the article being discussed, and the other 90% are people quibbling over the headline. Ok, that's an exaggeration. And when the comments are good, they are really good. Makes the entire HN experience worthwhile.
Re: Two More Cases of Third-Party Facebook App Data Exposure
#15Earlier quoted context omitted.
Not clickbait in the slightest. This is not about Facebook per se about persistence of their shared data - my information - once it's made public. HIPAA, by comparison has all sorts of statements about PII and business associates. But apparently FB can share with whoever has a pulse and I can find out about it later via Shodan. I wrote this even with the original link and version of the headline.
"Millions of Facebook Records Found on Amazon Cloud Servers" was the original headline. That headline the first thing you would likely think is Facebook was using AWS and left some data open somewhere. It 100% implied Facebook was doing more wrong now, instead of the companies that already had the data from the previous issues were not handling the data correctly. Yes this news is still notable. But the headline gave…
Re: Two More Cases of Third-Party Facebook App Data Exposure
#16A couple of local startups were talking about how to leverage the "login with facebook" button. It was a big thing...
Most people I talked to, told me: "The very first thing I do is to save all the email of their friends" or stuff like that.
So yeah, this was years ago. I'm failing to see how this is a surprise at all.
Re: Two More Cases of Third-Party Facebook App Data Exposure
#17If it's earth-shatteringly bad for your users if their private data is leaked by a third-party, you cannot exfiltrate that data to a thrid-party. Full stop. No amount of policy un-leaks data, and "You cannot continue to operate as a Facebook service" is an empty threat the moment it becomes more valuable for the third-party to violate the agreement than to continue to operate as a Facebook service.
The takeaway: if you are responsible for user privacy, you must do the computations on the user's data. Have partners ship you the computations they wish to do, vet them, and then ship them results compliant with your users' expectations. Don't hand third-parties a subset of the keys to the kingdom and expect an honor system to preserve user privacy.
Re: Two More Cases of Third-Party Facebook App Data Exposure
#18Unfortunately, Facebook had a fundamental misunderstanding of how privacy has to work, and their users will be paying for their error for years. If it's earth-shatteringly bad for your users if their private data is leaked by a third-party, you cannot exfiltrate that data to a thrid-party. Full stop. No amount of policy un-leaks data, and "You cannot continue to operate as a Facebook service" is an empty threat the m…
Re: Two More Cases of Third-Party Facebook App Data Exposure
#19Re: Two More Cases of Third-Party Facebook App Data Exposure
#20Unfortunately, Facebook had a fundamental misunderstanding of how privacy has to work, and their users will be paying for their error for years. If it's earth-shatteringly bad for your users if their private data is leaked by a third-party, you cannot exfiltrate that data to a thrid-party. Full stop. No amount of policy un-leaks data, and "You cannot continue to operate as a Facebook service" is an empty threat the m…