Live data from Hacker News

Facebook says new bug allowed apps access to private photos of up to 6.8M users

washingtonpost.com

141–150 of 280 posts

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#141

Earlier quoted context omitted.

Yes, I am suggesting that. I don't necessarily think jail time is the right thing, but I do think something like meaningful fines are more than reasonable for major software bugs that cause these kinds of breaches of privacy. It will make larger companies like this be much more careful when money is on the table for them to lose. To me, if we can criminalize something like a major oil spill such as BP/Deepwater Horiz…

Canada recently passed a law that adds fines to data breach incidents iirc. A professor mentioned it and its why I'm researching auth on my winter break. Come to think of it, does anyone know of good auth resources for a mean stack that isn't a copy paste blog? I'm trying the udacity auth course as a starting point (uses oauth2)

I just spent som time going through this.

The relevant rfc and drafts perhaps? https://tools.ietf.org/wg/oauth/

Also checkout OWASP https://www.owasp.org/

If your implementing openid connect, use a certified lib https://openid.net/developers/certified/

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#143

Earlier quoted context omitted.

There's a crowd here on HN that hates regulation but this is exactly why regulation exists. Massive, wealthy, powerful industries just aren't held accountable by average consumers or markets. There's no serious competitor that benefits if your data isn't safe at Facebook. And average people not only aren't powerful but have their own lives to look after. Without regulation massive companies are entirely unchecked, th…

As one aside on this, the main issue people have with regulations is not regulations in and of themselves, but the negative effect they have on small businesses and competition/entrepreneurship more generally. I think you'd find extremely few genuine voices against regulations that only start to apply once a company (and all associated entities) grosses in excess of e.g. $100 million annual revenue. By that point com…

So basically regulation that impacts them directly or materially?

The ideal of some arbitrary cut off point has been tried in lots of scenarios, and is gamed by all parties.

Example: Copyright will protect new works for x years, at which point Disney lobbies for the arbitrary goal posts to be moved.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#144

Earlier quoted context omitted.

"Skin in the Game": If a social media company leaks private photos of its users, the company's executives and senior staff shall have its photos leaked. I would love something like that. Nobody protects anyone else's interests in this modern world unless there's Skin in the Game. Would highly recommend reading Nassim Taleb's book of the same name; he is popularizing this term, and its implications to society.

the same "eye for an eye" goes for "if you have nothing to hide" - well then, you first

the same "eye for an eye" goes for "if you have nothing to hide" - well then, you first

You misunderstand what "eye for an eye" means.

"Eye for an eye" means let the punishment fit the crime.

Before "eye for an eye" was established by religious texts, the common retaliation for poking someone's eye out was death.

"Eye for an eye" was a step towards a more civilized justice system.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#145

> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…

> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.

Sounds like you're suggesting we take no action when law violations happen.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#146
post #21

Earlier quoted context omitted.

Most people I know are getting off of Facebook, or were never on it. The only people I know who are really still active are people using it to market themselves/their business, and are not there because they care about Facebook, but because they want to be findable there (and everywhere). I guess I'm old, but I find that email is great for sending baby pics to friends and family, and for planning things.

Well anecdotally in your small social group that may be true. But Facebook has 2.27 Billion active users...

...for a certain value of 'active' (do they say how it's defined?) My experience of internet companies has generally been that user figures are somewhat exaggerated (to put it politely).

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#147
post #11

Does it fall under GDPR violation?

No. Unless they didn't report it to the regulators.

What? You get fined under GDPR for a breach. If you don’t report it, the fine will be a lot higher if they find out.

We will see how this plays out, but there should be a fine nevertheless (because others have been fined and they reported it).

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#148

Why is anyone still using FB/Whatsapp/Instagram? It seems the vast majority just don't care at all about privacy.

WhatsApp: Because the market share outside the US is insane. Germany has 70% Android users and they don’t use iMessage. Nor any of the other ones unfortunately.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#149
post #146

Earlier quoted context omitted.

Well anecdotally in your small social group that may be true. But Facebook has 2.27 Billion active users...

...for a certain value of 'active' (do they say how it's defined?) My experience of internet companies has generally been that user figures are somewhat exaggerated (to put it politely).

No matter how you define “active”, there is no indication that in the aggregate people are fleeing Facebook - no matter if a few anecdotes are posted on HN.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#150

Earlier quoted context omitted.

HIPAA only carries criminal penalties when someone knowingly discloses covered information - not a software bug. Until the bug is identified at least. For the most part HIPAA is enforced with civil penalties. And your "nightmare" scenario of (civil) liability flowing from programming bugs already exists in the investment world and it hasn't come apart at the seams. Google Axa Rosenberg. A coding error in their tradin…

HIPAA only carries criminal penalties when someone knowingly discloses covered information This is false. Source: Works for a company that has mandatory HIPAA training for every employee every six months.

> This is false.

citation please. Here's mine:

> Criminal penalties

>

> Covered entities and specified individuals, as explained below, who "knowingly" obtain or disclose individually identifiable health information, in violation of the Administrative Simplification Regulations, face a fine of up to $50,000, as well as imprisonment up to 1 year.

>

> Offenses committed under false pretenses allow penalties to be increased to a $100,000 fine, with up to 5 years in prison.

>

> Finally, offenses committed with the intent to sell, transfer or use individually identifiable health information for commercial advantage, personal gain or malicious harm permit fines of $250,000 and imprisonment up to 10 years.

Source: American Medical Association

https://www.ama-assn.org/practice-management/hipaa/hipaa-vio...

Post reply on HN