Live data from Hacker News

Facebook says new bug allowed apps access to private photos of up to 6.8M users

washingtonpost.com

181–190 of 280 posts

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#181

Earlier quoted context omitted.

the same "eye for an eye" goes for "if you have nothing to hide" - well then, you first

the same "eye for an eye" goes for "if you have nothing to hide" - well then, you first You misunderstand what "eye for an eye" means. "Eye for an eye" means let the punishment fit the crime. Before "eye for an eye" was established by religious texts, the common retaliation for poking someone's eye out was death. "Eye for an eye" was a step towards a more civilized justice system.

I use it in the context of Taleb's book, mentioned in the parent, wherein he discusses this - symmetrical risk

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#182

Earlier quoted context omitted.

Going to play the devil’s advocate. If you fine Facebook, you have to fine the small companies too, and even individual developers developing OSS, since the law should apply to everyone equally. Of course the fines have to be proportional to the number of affected users. So would you like a fine for your bugs? And note that contrary to other professions, software development doesn’t have generally agreed recipes for…

Hoarding data is different from OSS. We’re talking about infra providers. IMO, they should be regulated like public utility companies.

Really, so does Mastodon qualify?

https://joinmastodon.org/

How about a blog commenting system that leaks emails due to a bug, something like Isso:

https://posativ.org/isso/

Basically I don't like these arguments because it's about the company's size. Facebook should be punished because they are big, have a lot of data and we don't like them, right? No matter how you look at it, it's a Pandora's box.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#183

Facebook is a global database of political dissidents, queer persons, apostates, and other categories of people whose physical safety is put in peril when their personal lives are leaked. Facebook surely must be heavily fined and regulated for their misbehavior, because to fail to keep Facebook data safe is to put lives at risk.

Going to play the devil’s advocate. If you fine Facebook, you have to fine the small companies too, and even individual developers developing OSS, since the law should apply to everyone equally. Of course the fines have to be proportional to the number of affected users. So would you like a fine for your bugs? And note that contrary to other professions, software development doesn’t have generally agreed recipes for…

Absolutely. Fine everyone into the ground. Doesn't look like there is any other way to make people take security seriously.

I'm not a fan of the overregulation of industries like aviation, but consumer software has gone too far in the other direction and is long overdue for an adjustment.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#184

Earlier quoted context omitted.

Yes, I am suggesting that. I don't necessarily think jail time is the right thing, but I do think something like meaningful fines are more than reasonable for major software bugs that cause these kinds of breaches of privacy. It will make larger companies like this be much more careful when money is on the table for them to lose. To me, if we can criminalize something like a major oil spill such as BP/Deepwater Horiz…

Canada recently passed a law that adds fines to data breach incidents iirc. A professor mentioned it and its why I'm researching auth on my winter break. Come to think of it, does anyone know of good auth resources for a mean stack that isn't a copy paste blog? I'm trying the udacity auth course as a starting point (uses oauth2)

Look into authorization as well as authentication.

Dex by coreos, Open Policy Agent, Kubernetes docs & code are all good examples, lots of frameworks have docs / code.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#185

Earlier quoted context omitted.

Hoarding data is different from OSS. We’re talking about infra providers. IMO, they should be regulated like public utility companies.

Really, so does Mastodon qualify? https://joinmastodon.org/ How about a blog commenting system that leaks emails due to a bug, something like Isso: https://posativ.org/isso/ Basically I don't like these arguments because it's about the company's size. Facebook should be punished because they are big, have a lot of data and we don't like them, right? No matter how you look at it, it's a Pandora's box.

Maybe there should be a general regulatory framework which all data-storing entities should be subjected to, with stiff penalties for the largest violators, as they can shoulder the burden of the biggest burdens.

Is this not how it works for every other industry? Up until the 2008 bank bailouts, that is.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#186

Earlier quoted context omitted.

There's a crowd here on HN that hates regulation but this is exactly why regulation exists. Massive, wealthy, powerful industries just aren't held accountable by average consumers or markets. There's no serious competitor that benefits if your data isn't safe at Facebook. And average people not only aren't powerful but have their own lives to look after. Without regulation massive companies are entirely unchecked, th…

As one aside on this, the main issue people have with regulations is not regulations in and of themselves, but the negative effect they have on small businesses and competition/entrepreneurship more generally. I think you'd find extremely few genuine voices against regulations that only start to apply once a company (and all associated entities) grosses in excess of e.g. $100 million annual revenue. By that point com…

Libertarian hackers always think of regulations as pesky pinpricks from the nanny state but in this case, in their domain of software, regulations would actually serve more of something along the lines of industry standards to ensure that software is created up to code. Hackers want good code, don't they?

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#187
post #25

> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…

Genuinely curious on your view: what is an appropriate response?

Execution. Facebook is big enough that it would serve as a useful warning.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#188

Facebook is a global database of political dissidents, queer persons, apostates, and other categories of people whose physical safety is put in peril when their personal lives are leaked. Facebook surely must be heavily fined and regulated for their misbehavior, because to fail to keep Facebook data safe is to put lives at risk.

Going to play the devil’s advocate. If you fine Facebook, you have to fine the small companies too, and even individual developers developing OSS, since the law should apply to everyone equally. Of course the fines have to be proportional to the number of affected users. So would you like a fine for your bugs? And note that contrary to other professions, software development doesn’t have generally agreed recipes for…

> If you fine Facebook, you have to fine the small companies too...

Absolutely nothing wrong with that. If a small trucking company has a driver that speeds, that driver gets fined the same way a driver for a large trucking company does.

> Of course the fines have to be proportional to the number of affected users.

Of course.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#189
post #60

Since Facebook is walking away all the time without any consequences, this will happen again and again. The long-term solution to this mess should come from users abandoning it which is happening gradually based on recent reports.

> The long-term solution to this mess should come from users abandoning it Where will the people go? If it's other software it might end being as bad or worse.

What’s the value of Facebook? Serious question as you think people should have alternative

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#190

Earlier quoted context omitted.

Going to play the devil’s advocate. If you fine Facebook, you have to fine the small companies too, and even individual developers developing OSS, since the law should apply to everyone equally. Of course the fines have to be proportional to the number of affected users. So would you like a fine for your bugs? And note that contrary to other professions, software development doesn’t have generally agreed recipes for…

Absolutely. Fine everyone into the ground. Doesn't look like there is any other way to make people take security seriously. I'm not a fan of the overregulation of industries like aviation, but consumer software has gone too far in the other direction and is long overdue for an adjustment.

The end result of this is that the number of software companies drops by 99.99%. Does your company run anything on Linux? Too bad, there are vulns in the kernel and now you are fined into the ground.
Post reply on HN