Live data from Hacker News

A Facebook engineer abused access to user data to track down woman

businessinsider.com.au

11–20 of 108 posts

Re: A Facebook engineer abused access to user data to track down woman

#11

> At the time, more than 16,000 employees had access to users’ private data, according to the book. > Stamos suggested tightening access to fewer than 5,000 employees and fewer than 100 for particularly sensitive information like passwords. I'm sorry, what? I can tell you the number of legitimate engineers that should have access to user's passwords. It's a nice, round number. It's zero.

Perhaps they mean access to reset a user password.

I have a hard time believing that Facebook would store user passwords without at least hash + salt which makes it virtually unrecoverable.

Re: A Facebook engineer abused access to user data to track down woman

#12
post #9

> At the time, more than 16,000 employees had access to users’ private data, according to the book. > Stamos suggested tightening access to fewer than 5,000 employees and fewer than 100 for particularly sensitive information like passwords. I'm sorry, what? I can tell you the number of legitimate engineers that should have access to user's passwords. It's a nice, round number. It's zero.

Is it not possible to only have the hashes or does it have to get persisted somewhere in the process?

Only the hashed versions should ever be stored. Like the OP said there is Zero reason to store plaintext user passwords.

Re: A Facebook engineer abused access to user data to track down woman

#14
post #6
post #3

> from 2014 to August 2015. Everyone here is unsurprised by this and at this point I expect the social networks to just abuse my user data anyway. They won't change and they will never stop this. Who is to say that this is already happening with the other social networks that are scooping up our data but in 5 years time will only admit their actions afterwards. Maybe they are all doing this as we type. To Downvoters:…

Company i used to work for gave almost every employee full access to the db through phpmyadmin.

"Almost every employee" could just mean 1 of 2 which is not a big deal, or 99 of 100 which is a big deal.

Re: A Facebook engineer abused access to user data to track down woman

#15
I worked at Facebook for most of 2017 and 2018. In the first week, they made it clear that you would be fired instantly for any improper access of user data.

They further said that if you need to access any sensitive personal data, or if you need to log in as a user in order to debug a problem, you need to have approval from your manager _before_ the access, not after.

Also, you are not allowed to access the data of anyone you know personally for any reason whatsoever. You have to find someone else to do that if it needs to be done.

Finally, they really do audit every single access of personal data. I had every reason to believe that if I accessed any data improperly, I would be fired within the week if not the day.

I don’t know how much abuse still exists despite all of the above, but I don’t think this article does a good job of explaining how seriously Facebook takes this.

Re: A Facebook engineer abused access to user data to track down woman

#16
Totally unsurprised by this.

Where I used to work, user activity/transactions data sent to us would be stored on a single giant nfs volume. If you were added to a Linux group you can full, unaudited access to everything. Whenever someone tried to build anything that would restrict and audit access there would be a ton of pushback from engineers and customer support who loved being able to ssh into a machine and have full access to everything.

Re: A Facebook engineer abused access to user data to track down woman

#18
post #15

I worked at Facebook for most of 2017 and 2018. In the first week, they made it clear that you would be fired instantly for any improper access of user data. They further said that if you need to access any sensitive personal data, or if you need to log in as a user in order to debug a problem, you need to have approval from your manager _before_ the access, not after. Also, you are not allowed to access the data of…

There’s a difference between having an audit trail and actually using it. I would be interested to know how often Facebook analyzes this data and actually fires people for improper usage.

Re: A Facebook engineer abused access to user data to track down woman

#19
post #12
post #9

Earlier quoted context omitted.

Is it not possible to only have the hashes or does it have to get persisted somewhere in the process?

Only the hashed versions should ever be stored. Like the OP said there is Zero reason to store plaintext user passwords.

IMO, it's likely that the article was confusing "passwords" with "hashes" here. No company the size of Facebook is going to be storing plain-text passwords in 2021.

Re: A Facebook engineer abused access to user data to track down woman

#20
At this point, why not just make any of this social media information public? What’s the difference to more than 16 000 people knowing with whom you cheated vs. the whole world knowing?

By 6 degrees of Kevin Bacon there surely is a connection to one of these 16000 people in your bubble, hence the secrets are theoretically out, too. Why should they have the advantage over you and potentially blackmail you?

/s

Post reply on HN