Live data from Hacker News

Facebook says new bug allowed apps access to private photos of up to 6.8M users

washingtonpost.com

161–170 of 280 posts

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#161

Earlier quoted context omitted.

Hammurabi's code (~1700 BC) includes this about building: Building Code 229. If a builder builds a house for a man and does not make its construction sound, and the house which he has built collapses and causes the death of the owner of the house, the builder shall be put to death. 233. If a builder builds a house for a man and does not make its construction sound, and a wall cracks, that builder shall strengthen tha…

When houses fall they fall they kill people. And houses are not free.

Need I remind you of the genocide in Myanmar organised to a large degree on social media, or the threat to political dissidents all over the world when authorities or malicious actors can get their hands on leaked, private data of individuals?

Are you seriously suggesting that information in this day and age does not have the power to directly cause harm, including lethal harm, to people?

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#162

Facebook is a global database of political dissidents, queer persons, apostates, and other categories of people whose physical safety is put in peril when their personal lives are leaked. Facebook surely must be heavily fined and regulated for their misbehavior, because to fail to keep Facebook data safe is to put lives at risk.

These people have an option to not use Facebook.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#163

As IT people, we owe it to our families to offer to self-host their social data on one of the many open-source platforms that are available. Maybe spend some time over the Xmas period having 'The Conversation' with our loved ones about their data safety?

Why do you think that self-hosting is safer?

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#164

As IT people, we owe it to our families to offer to self-host their social data on one of the many open-source platforms that are available. Maybe spend some time over the Xmas period having 'The Conversation' with our loved ones about their data safety?

You gotta be kidding me. How such conversation would go, and what would you expect to get out of it?

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#165

> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…

> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.

Why shouldnt we? If you are proven in court of law you knew about certain bugs or you underspend on engineering while your public outreach grew expenantially, how come you shouldnt be liable?

Anywhere else its a plain case of malpractice whether its law or medicine, etc.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#166

Facebook is a global database of political dissidents, queer persons, apostates, and other categories of people whose physical safety is put in peril when their personal lives are leaked. Facebook surely must be heavily fined and regulated for their misbehavior, because to fail to keep Facebook data safe is to put lives at risk.

These people have an option to not use Facebook.

You have an option not to use a ton of industries that are still heavily fined and regulated for their misbehavior. That logic doesn't matter in this context.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#167

Earlier quoted context omitted.

my response to this is always in the vein of, "how exactly should customers show they care?" "Well, leave!" isn't an option. They can't leave. Quitting Facebook when you're an active user means you lose a huge amount of social contact. I can think of a dozen people I know who are there because it's how they send baby pics and the like to family. They're non-technical and don't care about federated mastodons, they jus…

> my response to this is always in the vein of, "how exactly should customers show they care?" The answer is the same with any other foul business practice you oppose. The problem is not unique to digital businesses and I really hope those demanding justice don't request something more brash than they otherwise would in a non-digital situation. And yes they can leave. There are real things you can't leave like your o…

can't and won't are effectively the same thing in this context; you're picking nits about free will.

Yes, of course everyone can always leave. The only price - for more than a few of those 2 billion - is the complete disruption of their social lives. Telling someone they can never see cute pics of their lil cousin again is punishment, not a serious decision about consumer responsibility.

You can tell because a history of malfeasance and yet, 2 billion active users.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#169
post #147
post #11

Earlier quoted context omitted.

No. Unless they didn't report it to the regulators.

What? You get fined under GDPR for a breach. If you don’t report it, the fine will be a lot higher if they find out. We will see how this plays out, but there should be a fine nevertheless (because others have been fined and they reported it).

Based on what article?

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#170

Facebook is a global database of political dissidents, queer persons, apostates, and other categories of people whose physical safety is put in peril when their personal lives are leaked. Facebook surely must be heavily fined and regulated for their misbehavior, because to fail to keep Facebook data safe is to put lives at risk.

Going to play the devil’s advocate. If you fine Facebook, you have to fine the small companies too, and even individual developers developing OSS, since the law should apply to everyone equally. Of course the fines have to be proportional to the number of affected users.

So would you like a fine for your bugs? And note that contrary to other professions, software development doesn’t have generally agreed recipes for building bug-free software, so was that really negligence? Was it malpractice?

Being fined for a contribution to an OSS project would be terrible, wouldn’t it? And no, the size of the company doesn’t and shouldn’t matter in the eyes of the law, only the impact.

Also people uploading stuff on the Internet should really expect a best effort privacy. If you expect secrecy, then uploading shit on a platform meant for sharing is pretty dumb.

Note that I will blame Facebook for willful privacy violations. And I hope to see them suffer under GDPR. But a bug doesn’t fall in the same category.

Post reply on HN