Live data from Hacker News

Meta fined $102M for storing passwords in plain text

engadget.com

121–130 of 136 posts

Re: Meta fined $102M for storing passwords in plain text

#121
post #93

Earlier quoted context omitted.

I see this comment pop up here often in these threads about EU fines and regulations. "Apple/company should just call the EUs bluff and stop selling in the EU!". Apple's a good example because they're such an incredibly global brand, who should be less reliant on EU customers. Yet Europe is responsible for >20% of their revenue. Shareholders would eat you alive for just "nope"ing away from that. Yes, US GDP/capita is…

20% of revenue isn't that much. Would you rather focus on your core product and double your revenue, or focus on getting that 20%? Yes giant companies have the resources and experience less YoY growth so they will work with the EU market, but most companies would do better to ignore the EU.

> 20% of revenue isn't that much

It is in reality gigantic, especially at that scale. And in this specific example, Apple net profit is 24% of their revenue.

> Would you rather focus on your core product and double your revenue

Saying you no longer sell to people with blue eyes or wearing short is not in any way increasing your sales to other people.

I'm sorry to you your messages sound like you're not very knowledge about the subject matter.

Re: Meta fined $102M for storing passwords in plain text

#122

Earlier quoted context omitted.

the word you should use is carelessly, as in carelessly logging passwords. When working with data that you can reasonably expect to contain secrets, you should behave as if it does contain secrets. It worries me that you mention you're aware that server side crash dumps may contain sensitive data, but you also speak as if it's reasonable to not protect them knowing they do, or they might. I'd hope or expect anyone wo…

What you're saying makes sense for a small startup with 20 people. Have you worked in an org of 10000+ that's been around for 30 years? Where the people who built the systems no longer work there? Where the people who maintain them are 3+ career cycles removed? Things get so baked in "one doesn't simply make changes" because no one person understands how everything works, so you do your best and keep closing tickets.…

> Have you worked in an org of 10000+ that's been around for 30 years?

yes.

Would you still make this argument for something else known to be dangerous?

Hey this gigantic lathe doesn't have a safety shut off switch.

Ahh yeah the guy that did the wiring for that left years ago so we just don't touch it. It's fine as long as no one puts their hands near it when it's running.

Hey, isn't this freshly dug 20 foot hole supposed to have an escape route, and side wall reinforcements so it doesn't collapse on someone? lol ok new guy, let me know when you've finished pouring that concrete and then we'll look at that idea.

To go back to the example; Taking steps to protect them could be as simple as restricting who can access core dumps, enforcing they don't get stored unencrypted, and the only people who can copy and inspect them have are already in a trusted role where they can get root on that production server. Or an even better option would be restricting the service that can read clear text passwords. These machines don't crash, and when they do, we don't write a coredump. (but this trusted team can start if we see the system crashing suddenly)

> Things get so baked in "one doesn't simply make changes" because no one person understands how everything works, so you do your best and keep closing tickets.

This is a super disappointing attitude. It's hard, and it's the way we've always done it, so that means it's impossible, or not worth the effort? Yeah, I'm not likely to buy into that mentality. I believe I can fix things and have a positive impact. It's one thing to say it's impossible because you don't understand how to do it, that's wrong, but I guess if that's what you need to believe to sleep at night, I can pretend to understand.

It's another thing entirely if you don't have the autonomy at work to try to improve something you know to be broken, and a risk to users, and the company. If that's actually what you meant to describe, you might wanna consider if you can find another job. You're clearly not an idiot, and there's plenty of companies that wont treat you like a code monkey.

Re: Meta fined $102M for storing passwords in plain text

#123
post #74

Earlier quoted context omitted.

How long has that even been a regulation and in which countries does it apply? Software engineers are trained to view these kinds of things as bugs. Legal isn't trained to monitor bug trackers.

> Software engineers are trained to view these kinds of things as bugs Competent engineers —software or other— must have an education in safety standards and legal regulations. I had a pretty formal education in data protection at both A-Level and undergrad. I know real engineers get tetchy about us programmers edging in, so if you want any claim to an engineering title, ignoring the ramifications of your code in the…

I think the big difference is that engineers have had to care about people dying for the past 100 years. Today there are software developers that throw code out into the world that kills people without any repercussions. At some point this needs to change.

Re: Meta fined $102M for storing passwords in plain text

#124

Earlier quoted context omitted.

It's relatively common for publications to lazily only reference an action that resulted in a legal outcome, rather than the justification provided for the outcome. For instance, Bob imprisoned for car bomb rather than Bob imprisoned after judgement rules deaths unlawfully resulted from Bob's malicious car bombing. Had Bob's car bomb been on a film set and no one hurt, Bob would hopefully be fine. If you read coverag…

Even by the broadest possible definition of a breach, this is still just a control failure rather than a breach. The control that failed might have made it possible for Meta employees to perpetrate a breach, but the article makes no mention of that happening, or provides any suggestion that there is evidence that it might have happened. At at least one point in my career, I have also accidentally mishandled password…

I like to think of a breach as hole through into the hull... they don't mean the boat will sink or even ever will sink; just that the layers of security protections has been compromised.

In the case you mention it seems that happened too: internal actors could reach plaintext passwords and thus for safety the company responded by forcing password reset and disclosure (commendable as I know of companies that would not).

The term "personal data breach" is useful because it defines the range of breaches that the law focuses on (it's not interested in business data or incidents where the first layer of defence fell but the second kept it secure).

I feel it's a bit like having a determination for "road traffic incident". It helps the public, police, etc identify what is in scope... just because you have one doesn't mean you'll lose your licence or be fined - that depends on a range of factors regarding the lead up to the incident: what happened before, during and after. Similar with data breaches.

If a company has a breach it does not mean much in GDPR unless other factors are considered, so I wouldn't worry about being too focused on the term breach.

Re: Meta fined $102M for storing passwords in plain text

#125
post #74

Earlier quoted context omitted.

How long has that even been a regulation and in which countries does it apply? Software engineers are trained to view these kinds of things as bugs. Legal isn't trained to monitor bug trackers.

> Software engineers are trained to view these kinds of things as bugs Competent engineers —software or other— must have an education in safety standards and legal regulations. I had a pretty formal education in data protection at both A-Level and undergrad. I know real engineers get tetchy about us programmers edging in, so if you want any claim to an engineering title, ignoring the ramifications of your code in the…

An education in legal regulations teaches you the best solution is to make the fix and don't say anything.

Re: Meta fined $102M for storing passwords in plain text

#126
post #68

0.1 % of current revenue fine. If your company made a billion $ revenue per year, it'd have to pay $100k. Doesn't feel like a great incentive to do it right. If they improved debuggability by logging all requests to make the company more than 0.1 % efficient, it's a good deal for them.

It’s more like there’s a Director who gets paid $1 million to make sure the logging goes right and he fucked up his job so it’s like he should get fired because they could have replaced him 100x

Re: Meta fined $102M for storing passwords in plain text

#127

Earlier quoted context omitted.

> Meta does not intend Is an odd concept. Is the argument that nobody noticed? If somebody noticed, but the cleanup was deffered, them they did "intend to". It's like defending a bank robber by saying that he didn't intend to rob the bank, he just had a gun in his hand, and then he figured the damage was already done, so he may as well get some money.

I think the comment is the context of being a software developer. "Everyone" knows you shouldn't do that, so it would be a bit odd if the company of Facebook's size would. But if it was accidental, then it makes it clearer how it happened. It's still a grave mistake, but not unthinkable. I personally write bugs all the time.

"Everyone" does not know that. Avoiding plain text passwords is the commonest method used on the Internet, but if you get in to mobile telecoms, you find shared secrets stored in hardware-secure write-only enclaves in clear text. This is actually done because in that specific environment it increases security. It's not a general solution of course, but "only store encrypted passwords" and "only store password hashes" don't always apply either.

Re: Meta fined $102M for storing passwords in plain text

#129
post #113

Earlier quoted context omitted.

I think knowledge of them would absolutely be a breach, because you wouldn't be able to guarantee that person didn't remember and subsequently misuse them.

If the data was publicly leaked then this argument would have some merit. But it wasn’t, the only people who could have accessed these passwords were insiders, and those passwords were used to protect data that many of them would have access to anyway. There is no evidence any unauthorised party gained access to any private data as a result of this incident. There is no evidence that any authorised party misused data…

Given the frequency of customers reusing passwords across sites, the risk isn't specific to Meta data.

Re: Meta fined $102M for storing passwords in plain text

#130
post #118

Earlier quoted context omitted.

How so? Your source shows that Asia + North America make up like 67% of global GPD.

The $18349 Billion GDP. What did you think I was referring to? Were you trying to be daft?

I said the EU is not that big of a market. It’s less than 1/3 of the global GDP. We seem to have different definitions of a big market.
Post reply on HN