Live data from Hacker News

Facebook says new bug allowed apps access to private photos of up to 6.8M users

washingtonpost.com

151–160 of 280 posts

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#151
post #125

Earlier quoted context omitted.

The parent was establishing precedent.

And I'm establishing that the precedent cited doesn't exist, not in modern times anyway. If the argument is that home sellers are punished if they don't protect the buyer and so data sellers should be punished if they don't protect the data, that doesn't really hold up because home sellers aren't typically punished.

Note that I (OP) am referring to builders, not sellers. With respect to the systems that hold FB's data, I'd argue they are more like builders than sellers.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#152
post #73
post #71

Earlier quoted context omitted.

It's just too bad that all crimes are punished by death. Awfully unfair and disproportionate in most cases.

Nice snarky response, I'm not the person that equated leaking photos to a plane crashing >It's just too bad that all crimes are punished by death. Awfully unfair and disproportionate in most cases. What are you even responding to? Explain this to me I'm too stupid to understand how your comment makes any sense in any context.

Would you please read the guidelines before commenting further?

https://news.ycombinator.com/newsguidelines.html

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#153

Earlier quoted context omitted.

> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.

Hammurabi's code (~1700 BC) includes this about building: Building Code 229. If a builder builds a house for a man and does not make its construction sound, and the house which he has built collapses and causes the death of the owner of the house, the builder shall be put to death. 233. If a builder builds a house for a man and does not make its construction sound, and a wall cracks, that builder shall strengthen tha…

When houses fall they fall they kill people.

And houses are not free.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#154
I needed to change my phone number for an online account for a major well known transportation company. The app offers a way to do this, and receive a text message containing a verification code. Upon receipt the code is autoentered into the app, but immediately got an error that said I had to open a support ticket which can only be done with a web browser, not in app.

Customer support by email says I have to provide a copy of my driver's license or passport to "secure the account". I said that's not reasonable, companies leak too much personal data so you can't have anymore of mine, I'll just open a new account. They replied they'd just change the phone number (now no longer requiring the required photo ID). They did and the end.

- No explanation why the verification code process would not work.

- None of my ID's have either my email address, account number, or phone number, and the account doesn't even have my name on it. Giving them photo ID does jack shit for the purpose claimed.

- If the account security is questionable, you should not only require text verification of the new phone number, but they should have removed my stored payment accounts, requiring me to reenter them. AFAIK the credit card verification requires CVV and phone number matching the credit card account. That seems like the right way to secure the account rather than bullshit photo IDs.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#155
post #99

Earlier quoted context omitted.

> It seems pretty clear to me that anyone suggesting that software bugs in applications that have no risk of causing physical harm should have criminal liability has no idea what they are talking about and what damage such a law would cause. So you're fine with financial losses, loss of privacy, and the material harm that goes along with both? Disregarding the impact that data breaches imply is just naive. > Case in…

> and the material harm please, if there is provable material harm they can take it to civil court.

Uh huh, I'm sure it's just that easy, right? I mean, I'm certain it's an even playing field even for someone like me who has the money to hire an attorney. Hell, why regulate these industries at all? We can just file civil suits, right? Even if you win it costs less for them to settle than it does to change the way the do business/security.

We regulate the finance industry not because of a risk of physical harm, but because financial harm can be equally serious and civil suits do not act as a sufficient deterrent to bad behavior by the powerful. Why do you feel this sort of thing is different? I believe the only real difference is that this sort of thing is new, not well understood by most, and we just haven't caught up.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#156
Facebook is a global database of political dissidents, queer persons, apostates, and other categories of people whose physical safety is put in peril when their personal lives are leaked.

Facebook surely must be heavily fined and regulated for their misbehavior, because to fail to keep Facebook data safe is to put lives at risk.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#157
post #83

Earlier quoted context omitted.

If a plane crashed, and the company that manufactured the plane was fined because they had an engineering bug, no one would blink an eye.

Many programmers like to insist that they're engineers and at the same time come up with excuses for why they shouldn't be held to the same standards as other types of engineers.

Software development is more like a craft rather than engineering. If you are willing to pay for an app the same money you pay for a bridge than you will get the same quality and rigorous checking. But even then, there are less than 10 types of bridges in the world comparing to software which has to simulate every human activity and sometimes imaginary activities like games, all that in much higher levels of complications, constant changes of requirements and infinitely open for later changes through the life time of the application. Do you really think you can compare those two things?

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#158

Earlier quoted context omitted.

Hi. I've worked in medical software repeatedly. I totally want to deal with HIPAA. It's a good idea for clients (the people who actually matter) and it's not nearly as difficult a prospect to work with as people say. The set of demands it makes upon you are small and reasonably constrained and are nearly all process-based rather than technical. Where it is technical, plenty of folks will sign a BAA for you to take bi…

>"But HIPAA" has never, in my experience, been employed except by people who find the idea of doing the right thing inconvenient or inconveniently expensive. (It is virtually never that hard and its benefits are clear.) Thank you for directly attacking my character without even addressing my actual argument. I'm not arguing against HIPAA, I'm arguing against such regulations in spaces that don't require that kind of…

> Thank you for directly attacking my character without even addressing my actual argument.

"But it's hard, for no actual reason I will define" is not a meaningful argument. So--when one hears hoofbeats, think horses, not zebras.

> I would estimate that 40% of doctors today are not compliant with HIPAA, sending X-rays and other similar patient information over email with providers that they haven't signed BAAs with.

Probably true! But that's their own damned fault. Medical has Artesys and similar, dental has Apteryx and similar. This problem is largely solved but for hands-on unwillingness to use them.

Those providers should be nailed to the wall, the wall should not be torn down for them.

> Up until a few years ago (maybe even just a year) you couldn't use AWS to host medical data.

AWS has been signing BAAs since at least...2013? I believe the first time I looked into it was 2014. But, regardless--if your innovation was so tremendously stifled by this, I'm not particularly sympathetic. I've been running my own services and writing them too for at least a decade and you can do thou likewise, I promise. I am, however, saying that today it's very easy to do so 'cause Amazon is all-too-happy to sign one.

Also, I haven't had to use GCP for HIPAA-covered entities--found their BAA pretty easily though!--but even assuming you're correct the idea that you have to, hiss, talk to somebody before getting them to take some legal responsibility for your held PHI, I don't find that to be a particularly nasty requirement. I still find it odd that AWS will just let you sign right through with AWS Artifact.

Azure's all-too-happy to sign one, too. Not that I'd recommend it.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#159
As IT people, we owe it to our families to offer to self-host their social data on one of the many open-source platforms that are available.

Maybe spend some time over the Xmas period having 'The Conversation' with our loved ones about their data safety?

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#160
post #132

How come Google never has had a breach? Do they do a better job with security? Is Facebook more of a target than Google?

https://www.theverge.com/2018/10/8/17951914/google-plus-data... https://www.theverge.com/2018/12/10/18134541/google-plus-pri...

Technically, these aren't breaches or leaks, they're vulnerabilities.

Whether you believe data was exfiltrated is essentially a reflection of how much you trust or distrust Google.

Post reply on HN