"He also claimed the company failed to remedy the hacking and takeover of more than 100,000 accounts each day, ignoring his pleas and proposed fixes and choosing instead to prioritize user growth." There is no oversight of these monstrosities of any sort. I doubt anyone would have issues with the thesis that Meta would implement anything that might curb their user numbers unless it was mandated. Why would they? They…
Zuckerberg has a different class of shares And not every CEO begins life in their company with "if you need any info just ask, they trust me, dumb fucks"
Ex-WhatsApp cybersecurity head says Meta endangered billions of users
131–140 of 192 posts
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#132Earlier quoted context omitted.
> outside of the West you probably mean outside of the USA, it's huge in Europe/UK (which doesn't contradict your main point)
I would have thought he meant "inside of the West". Outside of the West you have other channels. Russia: Telegram Taiwan: Line Japan: Line By contrast, WhatsApp is best known to me for being used in Europe, Australia, and India.
For business comms drop instagram and move WhatsApp to first.
For Singapore it seems LinkedIn messages are the go to IM for business.
Europe p2p: telegram number one by a huge margin, then WhatsApp. B2b: WhatsApp, period.
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#133That's rather surprising about the accessing user data bit. When I was at Meta, the quickest way to get fired as an engineer was to access user data/accounts without permission or business reason. Everything was logged/audited down to the database level. Can't imagine that changing and the rules are taught very early on in the onboarding/bootcamp process.
Whatever Meta says publicly about this topic, and whatever its internal policies may be, directly contradicts its behavior. So any attempt to excuse this is nothing but virtue signalling and marketing. The privacy violations and complete disregard for user data are too numerous to mention. There's a Wikipedia article that summarizes the ones we publicly know about. Based on incentives alone, when the company's primar…
Your comment talks about incentives, but you haven’t actually made a rational argument tying actual incentives to behaviour.
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#134Given how WhatsApp is the de-facto way to communicate outside of the West and China, these security/data-handling "weaknesses" are most likely a feature, not a bug. An absolute bonanza for the certain intelligence services. Remember, kids: End to end encryption is useless if the "ends" are fully controlled by an (untrustworthy) third party.
> End to end encryption is useless if the "ends" are fully controlled by a (..) third party. YES!
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#135Earlier quoted context omitted.
Zuckerberg has a different class of shares And not every CEO begins life in their company with "if you need any info just ask, they trust me, dumb fucks"
Where is that quote from?
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#136That's rather surprising about the accessing user data bit. When I was at Meta, the quickest way to get fired as an engineer was to access user data/accounts without permission or business reason. Everything was logged/audited down to the database level. Can't imagine that changing and the rules are taught very early on in the onboarding/bootcamp process.
Everything is logged, but no one really cares, and the "business reasons" are many and extremely generic. That being said, maybe I'm dumb but I guess I don't see the huge risk here? I could certainly believe that 1500 employees had basically complete access with little oversight (logging and not caring isn't oversight imo). But how is that a safety risk to users? User information is often very important in the day to…
If you have a sister,imagine her being stalked by an employee?
If you have crypto, imagine an employee selling your information to a third party?
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#137Earlier quoted context omitted.
But the crucial bit to know here would be if that data was readable in anyway in case it was accessed? Personally it doesn't matter if there are auditing systems in place, if the data is readable in any way, shape or form.
is that really true? I haven’t touched a lot of these cyber security parts of industry: especially policies for awhile… … but I do recall that auditing was a stronger motivator than preventing. There were policies around checking the audit logs, not being able to alter audit logs and ensuring that nobody really knew exactly what was audited. (Except for a handful of individuals of course.) I could be wrong, but “obse…
That strategy doesn't help a victim who's being stalked by an employee, who can use your system to find their new home address. They often don't care if they get fired (or worse), so the motivator doesn't work because they aren't behaving rationally to begin with.
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#138As many holes as WhatsApp's "E2E" encryption has, this shows how valuable it still is. It's all metadata, not message content.
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#139Given how WhatsApp is the de-facto way to communicate outside of the West and China, these security/data-handling "weaknesses" are most likely a feature, not a bug. An absolute bonanza for the certain intelligence services. Remember, kids: End to end encryption is useless if the "ends" are fully controlled by an (untrustworthy) third party.
Ok, what do you suggest instead?
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#140Given how WhatsApp is the de-facto way to communicate outside of the West and China, these security/data-handling "weaknesses" are most likely a feature, not a bug. An absolute bonanza for the certain intelligence services. Remember, kids: End to end encryption is useless if the "ends" are fully controlled by an (untrustworthy) third party.