Live data from Hacker News

Facebook says new bug allowed apps access to private photos of up to 6.8M users

washingtonpost.com

111–120 of 280 posts

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#111

> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…

This may change when lives are actually lost. Self crashing cars have the potential to destroy the potential saving of life by intentional or accidental software bugs and security vulnerabilities. A congressman I was speaking with rephrased my statement and said that I was suggesting that self driving cars be treated as medical devices. I wholeheartedly agreed with his wording.

That said, the same changes won't likely occur with sites like FB unless it can be proven that the data leaked lead to loss of life or physical harm. They create incentive's for people to happily be the product. How do we prove that damage has occurred to the product? Have any forums popped up where people share stories of harm to their family as a result of data leaked from FB?

I can imagine GDPR being useful in the EU for corporate FB accounts. Wasn't FB working on a work-specific version of their site? If so, corporate legal teams would get involved in leaks, I would imagine.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#112
post #109

Most of the comments below are echoing the statement "jail time for bugs!!!!!" and similar sentiments, and therein lies the problem. "bugs" is a catch all word, it covers everything from a pesky typo in UI to bugs like this, severe security issues, meltdown/spectre, VW bugs, and so and so forth. Of course no jail time for a typo, but why not a jail time or severe financial and career consequences for severe bugs espe…

Who would be held responsible? Coder? QA? Code reviewer? PM? person putting pressure on PM?

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#113

> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…

This may change when lives are actually lost. Self crashing cars have the potential to destroy the potential saving of life by intentional or accidental software bugs and security vulnerabilities. A congressman I was speaking with rephrased my statement and said that I was suggesting that self driving cars be treated as medical devices. I wholeheartedly agreed with his wording. That said, the same changes won't likel…

> I can imagine GDPR being useful in the EU for corporate FB accounts. Wasn't FB working on a work-specific version of their site? If so, corporate legal teams would get involved in leaks, I would imagine.

I can imagine GDPR working very well for consumers as well, and it seems we are up for some real legal entertainment in the next few months/years :-)

Edit: It also wouldn't surprise me if it gets worse before it gets better. If I was a publisher right now I'd seriously consider blocking access from EU countries. (But that would of course be an invitation for a small, agile publisher who'd succeed either with a micropayments based approach or a context based ads approach.)

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#114

> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…

This may change when lives are actually lost. Self crashing cars have the potential to destroy the potential saving of life by intentional or accidental software bugs and security vulnerabilities. A congressman I was speaking with rephrased my statement and said that I was suggesting that self driving cars be treated as medical devices. I wholeheartedly agreed with his wording. That said, the same changes won't likel…

It will happen if FB have to suffer financial consequences. GDPR will help, but we need companies to understand that personal data is not an asset, they are also liabilities.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#115
post #109

Most of the comments below are echoing the statement "jail time for bugs!!!!!" and similar sentiments, and therein lies the problem. "bugs" is a catch all word, it covers everything from a pesky typo in UI to bugs like this, severe security issues, meltdown/spectre, VW bugs, and so and so forth. Of course no jail time for a typo, but why not a jail time or severe financial and career consequences for severe bugs espe…

Who would be held responsible? Coder? QA? Code reviewer? PM? person putting pressure on PM?

Depends...

If malicious intent, most likely the business owners, PM or engineering management, but in some cases software engineers.

If due to rushed product, certainly the management and not software engineers or QA.

and so on..

It depends..

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#116
post #69

Earlier quoted context omitted.

Yes, I am suggesting that. I don't necessarily think jail time is the right thing, but I do think something like meaningful fines are more than reasonable for major software bugs that cause these kinds of breaches of privacy. It will make larger companies like this be much more careful when money is on the table for them to lose. To me, if we can criminalize something like a major oil spill such as BP/Deepwater Horiz…

Just a quick question, do you write software? Do you have a legal or economic background? It seems pretty clear to me that anyone suggesting that software bugs in applications that have no risk of causing physical harm should have criminal liability has no idea what they are talking about and what damage such a law would cause. Case in point look at the quality of medical software today. Hospitals still use windows x…

Don't worry, most of these people suggesting liability for software bugs will soon be the same ones complaining about how everything is costly. The concept of second and higher order effects from adding liability to everything is alien to them.

It's also funny that most of these calls are basically motivated because it's facebook. What they're again not realizing is that while Facebook and other megacorps can weather this, small companies won't be able to. It's like magnified stupidity!!

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#119

Earlier quoted context omitted.

> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.

Hammurabi's code (~1700 BC) includes this about building: Building Code 229. If a builder builds a house for a man and does not make its construction sound, and the house which he has built collapses and causes the death of the owner of the house, the builder shall be put to death. 233. If a builder builds a house for a man and does not make its construction sound, and a wall cracks, that builder shall strengthen tha…

"Skin in the Game":

If a social media company leaks private photos of its users, the company's executives and senior staff shall have its photos leaked.

I would love something like that. Nobody protects anyone else's interests in this modern world unless there's Skin in the Game. Would highly recommend reading Nassim Taleb's book of the same name; he is popularizing this term, and its implications to society.

Post reply on HN