Earlier quoted context omitted.
> Google didn't shut down Google+ to preserve user privacy They accelerated the planned shutdown for exactly that reason.
They did that because cost of maintaining platform was higher than its ROI. If Google+ had like 300M-400M monthly active users I don't think they would have shut down Google+
Facebook says new bug allowed apps access to private photos of up to 6.8M users
131–140 of 280 posts
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#132How come Google never has had a breach? Do they do a better job with security? Is Facebook more of a target than Google?
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#133Earlier quoted context omitted.
Hammurabi's code (~1700 BC) includes this about building: Building Code 229. If a builder builds a house for a man and does not make its construction sound, and the house which he has built collapses and causes the death of the owner of the house, the builder shall be put to death. 233. If a builder builds a house for a man and does not make its construction sound, and a wall cracks, that builder shall strengthen tha…
But they aren’t. Most home sales in the US follow caveat emptor. If you buy a house from a private seller and then later discover mold in the walls or a crack in the foundation I wish you luck in getting the seller to pay for the repair.
[0]: https://www.angieslist.com/articles/hiring-contractor-whats-...
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#134Bright big popup right over main facebook.com (and peripheral webs/apps) dismissable only if you scrolled it all the way down, confirmed to have read it, saying "private photos of millions of users were leaked" in big bold letters, would go a long way.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#135Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#136Earlier quoted context omitted.
"Skin in the Game": If a social media company leaks private photos of its users, the company's executives and senior staff shall have its photos leaked. I would love something like that. Nobody protects anyone else's interests in this modern world unless there's Skin in the Game. Would highly recommend reading Nassim Taleb's book of the same name; he is popularizing this term, and its implications to society.
the same "eye for an eye" goes for "if you have nothing to hide" - well then, you first
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#137Earlier quoted context omitted.
There's a crowd here on HN that hates regulation but this is exactly why regulation exists. Massive, wealthy, powerful industries just aren't held accountable by average consumers or markets. There's no serious competitor that benefits if your data isn't safe at Facebook. And average people not only aren't powerful but have their own lives to look after. Without regulation massive companies are entirely unchecked, th…
As one aside on this, the main issue people have with regulations is not regulations in and of themselves, but the negative effect they have on small businesses and competition/entrepreneurship more generally. I think you'd find extremely few genuine voices against regulations that only start to apply once a company (and all associated entities) grosses in excess of e.g. $100 million annual revenue. By that point com…
Though in practice, enforcement of regulations in general is already handled this way.
For example a new startup in the valley doesn’t get a note from the gov because they launched without a privacy policy.
Same in the App Store, a minor app breaking App Store rules doesn’t get knocked out because the downloads are too small to bother.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#138Earlier quoted context omitted.
Just a quick question, do you write software? Do you have a legal or economic background? It seems pretty clear to me that anyone suggesting that software bugs in applications that have no risk of causing physical harm should have criminal liability has no idea what they are talking about and what damage such a law would cause. Case in point look at the quality of medical software today. Hospitals still use windows x…
Hi. I've worked in medical software repeatedly. I totally want to deal with HIPAA. It's a good idea for clients (the people who actually matter) and it's not nearly as difficult a prospect to work with as people say. The set of demands it makes upon you are small and reasonably constrained and are nearly all process-based rather than technical. Where it is technical, plenty of folks will sign a BAA for you to take bi…
Thank you for directly attacking my character without even addressing my actual argument.
I'm not arguing against HIPAA, I'm arguing against such regulations in spaces that don't require that kind of sensitivity. I think that medical data absolutely requires the protections it has. But it absolutely has had the unintended consequence of making current medical data more insecure and stifling innovation in the space. Most doctors don't even follow HIPAA compliance sending patient medical records over email.
I would estimate that 40% of doctors today are not compliant with HIPAA, sending X-rays and other similar patient information over email with providers that they haven't signed BAAs with.
>There are reasons for not modernizing tech stacks in the medical space. HIPAA is, in every case I've ever observed, not a meaningful one.
Then please enlighten us. Up until a few years ago (maybe even just a year) you couldn't use AWS to host medical data. Today you can't use Google Cloud to host medical data unless you are a large enough business to be able to get into contact with one of their sales reps. Can you even sign a business associate agreement with digital ocean? So up until a year ago you could not even have a small healthcare startup hosted on the cloud. Please explain to me how this hasn't stifled medical software innovation.
If it isn't HIPAA it's some other outdated regulation.
https://slate.com/technology/2018/06/why-doctors-offices-sti...
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#139Earlier quoted context omitted.
Just a quick question, do you write software? Do you have a legal or economic background? It seems pretty clear to me that anyone suggesting that software bugs in applications that have no risk of causing physical harm should have criminal liability has no idea what they are talking about and what damage such a law would cause. Case in point look at the quality of medical software today. Hospitals still use windows x…
> It seems pretty clear to me that anyone suggesting that software bugs in applications that have no risk of causing physical harm should have criminal liability has no idea what they are talking about and what damage such a law would cause. So you're fine with financial losses, loss of privacy, and the material harm that goes along with both? Disregarding the impact that data breaches imply is just naive. > Case in…
please, if there is provable material harm they can take it to civil court.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#140Earlier quoted context omitted.
Just a quick question, do you write software? Do you have a legal or economic background? It seems pretty clear to me that anyone suggesting that software bugs in applications that have no risk of causing physical harm should have criminal liability has no idea what they are talking about and what damage such a law would cause. Case in point look at the quality of medical software today. Hospitals still use windows x…
HIPAA only carries criminal penalties when someone knowingly discloses covered information - not a software bug. Until the bug is identified at least. For the most part HIPAA is enforced with civil penalties. And your "nightmare" scenario of (civil) liability flowing from programming bugs already exists in the investment world and it hasn't come apart at the seams. Google Axa Rosenberg. A coding error in their tradin…
This is false.
Source: Works for a company that has mandatory HIPAA training for every employee every six months.