Live data from Hacker News

Facebook says new bug allowed apps access to private photos of up to 6.8M users

washingtonpost.com

101–110 of 280 posts

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#101
post #69

Earlier quoted context omitted.

Yes, I am suggesting that. I don't necessarily think jail time is the right thing, but I do think something like meaningful fines are more than reasonable for major software bugs that cause these kinds of breaches of privacy. It will make larger companies like this be much more careful when money is on the table for them to lose. To me, if we can criminalize something like a major oil spill such as BP/Deepwater Horiz…

Just a quick question, do you write software? Do you have a legal or economic background? It seems pretty clear to me that anyone suggesting that software bugs in applications that have no risk of causing physical harm should have criminal liability has no idea what they are talking about and what damage such a law would cause. Case in point look at the quality of medical software today. Hospitals still use windows x…

Hi. I've worked in medical software repeatedly. I totally want to deal with HIPAA. It's a good idea for clients (the people who actually matter) and it's not nearly as difficult a prospect to work with as people say. The set of demands it makes upon you are small and reasonably constrained and are nearly all process-based rather than technical. Where it is technical, plenty of folks will sign a BAA for you to take big chunks of the technical stack off your hands, too.

"But HIPAA" has never, in my experience, been employed except by people who find the idea of doing the right thing inconvenient or inconveniently expensive. (It is virtually never that hard and its benefits are clear.)

There are reasons for not modernizing tech stacks in the medical space. HIPAA is, in every case I've ever observed, not a meaningful one.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#102

> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…

> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.

When we're entering an era where everything will involve software, yes, bad software and careless bugs should be severely punished.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#103
post #27
post #12

I think it should be clear to everyone at this point that nothing on Facebook is private. Don't put anything there you wouldn't post publicly.

Beyond that, nothing online is private. And generally, nothing can be removed. There will always be bugs, mistakes, new vulnerabilities. Eventually it will get out.

Two can keep a secret if one of them is dead, sure. But that doesn't mean you have to assume that having something on the internet means it's going to leak all by itself. The advice we should be giving is not putting all of our eggs in centralized baskets

Especially if we know the baskets have goals not aligned with our own, despite it being oh-so-convenient, but also not centralized in the first place.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#104
post #74

Earlier quoted context omitted.

Google didn't shut down Google+ to preserve user privacy. Not sure if that's what you're implying with your comment-- I hope it's not.

> Google didn't shut down Google+ to preserve user privacy They accelerated the planned shutdown for exactly that reason.

They claim that, though, and that's the joke GGP was making.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#105

Earlier quoted context omitted.

If a plane crashed, and the company that manufactured the plane was fined because they had an engineering bug, no one would blink an eye.

The analogy doesn't work. Barring malicious intent or negligence leading to death I cannot imagine (or remember) a situation where the company would be fined for a software bug.

This analogy does work. Boeing's software caused a plane to crash:

https://www.reuters.com/article/us-indonesia-crash-boeing/bo...

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#106
post #84

Don't believe this BS. FB is selling your private info/photos. A planned breach to divulge your data to 3rd parties, then they cover it up "oh no, we got hacked!". Quit that lame ass platform long ago... MZ is not who you think he is.

Please don't come to HN with this garbage.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#107
post #93

> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…

Nothing bad ever comes to companies as a consequence of these leaks, so what is their incentive to stop them? It happens so often that it goes down the memory hole after maybe a week or two, so even that isn't much of an incentive. We shouldn't be surprised about this.

There's a crowd here on HN that hates regulation but this is exactly why regulation exists. Massive, wealthy, powerful industries just aren't held accountable by average consumers or markets. There's no serious competitor that benefits if your data isn't safe at Facebook. And average people not only aren't powerful but have their own lives to look after.

Without regulation massive companies are entirely unchecked, there is virtually never market pressure to fix problems like this.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#108

> The bug also impacted photos that people uploaded to Facebook but chose not to post. What about, for example, pictures sent in a private message? I'm so very glad I deleted my account months ago.

For pictures present on your phone which Facebook uploaded just in case you’d want to post them later. To hide latency essentially

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#109
Most of the comments below are echoing the statement "jail time for bugs!!!!!" and similar sentiments, and therein lies the problem.

"bugs" is a catch all word, it covers everything from a pesky typo in UI to bugs like this, severe security issues, meltdown/spectre, VW bugs, and so and so forth.

Of course no jail time for a typo, but why not a jail time or severe financial and career consequences for severe bugs especially when it can be shown that a bug was caused due to intentional decisions, malicious intents, sloppy testing, rushed product etc. and not due to genuine mistakes - similar to medical malpractices.

Of course lawyers will love it, but it can improve the overall situation.

And yes, I'm a software engineers and do know what I'm talking about.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#110
post #53
post #29

Earlier quoted context omitted.

Except that your friends, family, and others can upload private photos with you in them.

I left FB when they made reverted a policy that let you opt to confirm all tags before they showed up in searches for you. This means anyone in the world can upload an image, tag you in it, and it will show up in searches for you. It still won’t show up on your profile if you have confirmations for that enabled, but still.

No need to tag, just facial recognition will get you from previous tags and other metadata
Post reply on HN