Live data from Hacker News

Ex-WhatsApp cybersecurity head says Meta endangered billions of users

theguardian.com

121–130 of 192 posts

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#121
post #56

Earlier quoted context omitted.

> outside of the West you probably mean outside of the USA, it's huge in Europe/UK (which doesn't contradict your main point)

It is huge in Latin America. USA is special because it is the (only?) country where iPhone has more users than Android.

https://worldpopulationreview.com/country-rankings/iphone-ma...

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#122
post #48

Didn't Hacker News feature an article on their home page at some point (10 years ago?) that at that time Facebook misconfigured something and users could observe their data being fed directly to some Israeli intelligence company? That was the day I deleted my FB account and never looked at anything they offer anymore.

Are you thinking of Cambridge Analytica? That was a British company, not Israeli.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#123

That's rather surprising about the accessing user data bit. When I was at Meta, the quickest way to get fired as an engineer was to access user data/accounts without permission or business reason. Everything was logged/audited down to the database level. Can't imagine that changing and the rules are taught very early on in the onboarding/bootcamp process.

But the crucial bit to know here would be if that data was readable in anyway in case it was accessed?

Personally it doesn't matter if there are auditing systems in place, if the data is readable in any way, shape or form.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#124
post #88

That's rather surprising about the accessing user data bit. When I was at Meta, the quickest way to get fired as an engineer was to access user data/accounts without permission or business reason. Everything was logged/audited down to the database level. Can't imagine that changing and the rules are taught very early on in the onboarding/bootcamp process.

Do you have proof?

Does Attaullah Baig?

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#126
post #56

Earlier quoted context omitted.

It is huge in Latin America. USA is special because it is the (only?) country where iPhone has more users than Android.

It's crazy how an US company dominates the world's messaging market but not in the US

Well, FB didnt build up the initial user base, just purchased it and grew it from there.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#127

That's rather surprising about the accessing user data bit. When I was at Meta, the quickest way to get fired as an engineer was to access user data/accounts without permission or business reason. Everything was logged/audited down to the database level. Can't imagine that changing and the rules are taught very early on in the onboarding/bootcamp process.

Everything is logged, but no one really cares, and the "business reasons" are many and extremely generic.

That being said, maybe I'm dumb but I guess I don't see the huge risk here? I could certainly believe that 1500 employees had basically complete access with little oversight (logging and not caring isn't oversight imo). But how is that a safety risk to users? User information is often very important in the day to day work of certain engineering orgs (esp. the large number of eng who are fixing things based off user reports). So that access exists, what's the security risk? That employees will abuse that access? That's always going to be possible I think?

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#128

That's rather surprising about the accessing user data bit. When I was at Meta, the quickest way to get fired as an engineer was to access user data/accounts without permission or business reason. Everything was logged/audited down to the database level. Can't imagine that changing and the rules are taught very early on in the onboarding/bootcamp process.

But the crucial bit to know here would be if that data was readable in anyway in case it was accessed? Personally it doesn't matter if there are auditing systems in place, if the data is readable in any way, shape or form.

is that really true?

I haven’t touched a lot of these cyber security parts of industry: especially policies for awhile…

… but I do recall that auditing was a stronger motivator than preventing. There were policies around checking the audit logs, not being able to alter audit logs and ensuring that nobody really knew exactly what was audited. (Except for a handful of individuals of course.)

I could be wrong, but “observe and report” felt like it was the strongest possible security guarantee available inside the policies we followed (PCI-DSS Tier 1). and that prevention was a nice to have on top.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#129
post #104

> Attaullah Baig, who served as head of security for WhatsApp from 2021 to 2025, claims that approximately 1,500 engineers had unrestricted access to user data without proper oversight, potentially violating a US government order that imposed a $5bn penalty on the company in 2020. If it results in a new billion-dollar penalty, maybe it would've saved money to move him quietly to a cushy rest-and-vest advisory positio…

You ask to be reinstated so that the financial settelment is higher (it includes the cost of sacking him).

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#130

Given how WhatsApp is the de-facto way to communicate outside of the West and China, these security/data-handling "weaknesses" are most likely a feature, not a bug. An absolute bonanza for the certain intelligence services. Remember, kids: End to end encryption is useless if the "ends" are fully controlled by an (untrustworthy) third party.

> End to end encryption is useless if the "ends" are fully controlled by a (..) third party.

YES!

Post reply on HN