Live data from Hacker News

Facebook says new bug allowed apps access to private photos of up to 6.8M users

washingtonpost.com

191–200 of 280 posts

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#191

Earlier quoted context omitted.

HIPAA only carries criminal penalties when someone knowingly discloses covered information This is false. Source: Works for a company that has mandatory HIPAA training for every employee every six months.

> This is false. citation please. Here's mine: > Criminal penalties > > Covered entities and specified individuals, as explained below, who "knowingly" obtain or disclose individually identifiable health information, in violation of the Administrative Simplification Regulations, face a fine of up to $50,000, as well as imprisonment up to 1 year. > > Offenses committed under false pretenses allow penalties to be incre…

My company's lawyers disagree. I'll go with my company's lawyers' judgement over a group that exists solely to protect the interests of its member doctors.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#192

Earlier quoted context omitted.

Absolutely. Fine everyone into the ground. Doesn't look like there is any other way to make people take security seriously. I'm not a fan of the overregulation of industries like aviation, but consumer software has gone too far in the other direction and is long overdue for an adjustment.

The end result of this is that the number of software companies drops by 99.99%. Does your company run anything on Linux? Too bad, there are vulns in the kernel and now you are fined into the ground.

I would hope for 100.

We deserve it. Though of course others deserve it more.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#193
post #57

Earlier quoted context omitted.

> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.

> Sounds like you're suggesting that we criminalize software bugs. When there is irreparable damage I believe it should be criminalized. You cannot regain privacy after an incident such as this, it is irrevocably taken from you against your will.

Suppose there is a bug in the Linux kernel. Some business runs their webservers on Linux. They have user email addresses (PII). Is Linus responsible for breaches? If so, then OSS dies. If not, then how do you intend to prove that their are no vulns in any of your dependencies for the rest of time?

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#194
post #70

Earlier quoted context omitted.

Yes, I am suggesting that. I don't necessarily think jail time is the right thing, but I do think something like meaningful fines are more than reasonable for major software bugs that cause these kinds of breaches of privacy. It will make larger companies like this be much more careful when money is on the table for them to lose. To me, if we can criminalize something like a major oil spill such as BP/Deepwater Horiz…

It's not unprecedented either. Under HIPAA, the Department of Health and Human Services has fined organizations millions of dollars for data breaches resulting from unpatched software and inadequate security practices.

And on that note, you see a lot less (though not zero) breaches of healthcare data and most HIPAA violations are due to analog errors rather than digital exposure.

The government does a good job in this area forgiving innocuous violations, as long as all parties disclose it immediately and follow procedure.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#195

Earlier quoted context omitted.

Going to play the devil’s advocate. If you fine Facebook, you have to fine the small companies too, and even individual developers developing OSS, since the law should apply to everyone equally. Of course the fines have to be proportional to the number of affected users. So would you like a fine for your bugs? And note that contrary to other professions, software development doesn’t have generally agreed recipes for…

> If you fine Facebook, you have to fine the small companies too... Absolutely nothing wrong with that. If a small trucking company has a driver that speeds, that driver gets fined the same way a driver for a large trucking company does. > Of course the fines have to be proportional to the number of affected users. Of course.

Personally I hate analogies.

The recipe for how a driver should not go over the speed limit is well known. Nowadays you even have the GPS apps alerting you and many trucks get monitored in real time from the dispatch center, drivers risking to be fired if not exactly on schedule.

Most software projects are greenfield ... people reuse previous work when available and for a good price, but all custom changes are greenfield.

Do you really think that the guy responsible for Heartbleed [1] was aware when he introduced that bug, just like a truck driver going over the speed limit?

It's really not the same thing, lets not pretend that it is and regulation in this field would have a chilling effect for open source or startups, because only big companies like Facebook will still be willing to develop critical software, which is definitely not what we want.

[1] http://heartbleed.com/

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#196

Earlier quoted context omitted.

Jail time for bugs? Have people here every worked on products? Bugs and security vulns are literally inevitable. Security is important but it this was the standard I'm not sure that any company would still exist.

Nobody said jail time for bugs, and phrasing that way is intentionally obscuring the debate. Gross negligence is an entirely different standard than just software bugs.

Lots of people in this thread are explicitly saying jail time for bugs.

What evidence is there that this was gross negligence?

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#197
post #21

Earlier quoted context omitted.

my response to this is always in the vein of, "how exactly should customers show they care?" "Well, leave!" isn't an option. They can't leave. Quitting Facebook when you're an active user means you lose a huge amount of social contact. I can think of a dozen people I know who are there because it's how they send baby pics and the like to family. They're non-technical and don't care about federated mastodons, they jus…

Most people I know are getting off of Facebook, or were never on it. The only people I know who are really still active are people using it to market themselves/their business, and are not there because they care about Facebook, but because they want to be findable there (and everywhere). I guess I'm old, but I find that email is great for sending baby pics to friends and family, and for planning things.

Email is such a failure for sending family pictures. My relatives keep changing their addresses without telling anyone, and many email providers have small message size limits so if you attach several pictures then the message may bounce or just not get delivered. For all its faults, Facebook is a much more reliable and usable delivery channel.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#198
post #29

“Private” photos that people uploaded to Facebook. Sounds like a good time to reiterate the advice: Don’t upload things to the internet that you don’t want to be on the internet. That way there won’t be any of your things on the internet that you didn’t want to be there.

Except that your friends, family, and others can upload private photos with you in them.

Just stop having a face. And friends, or family. Become an unperson. The solution is so obvious.

It's always hilarious how people try to pretend that it's easy to just drop out of society and the systems that people use to keep in touch. Sure, you can live like the unabomber in a shed in Montana with no phone service, but having that be the only option to keep your personal data safe from leaks is a bit much of an ask. People should be able to live their lives and take reasonable but not extraordinary precautions to safeguard their privacy and be able to have some expectation of privacy as a result. Unfortunately, there is so much data being collected on everyone, so many intrusions to our private lives, and so little care being taken by the stewards of that private data that it is not, it turns out, a reasonable expectation. And the onus for solving that problem shouldn't be on individuals. We shouldn't be forced to live our lives in fear of digital representations of our appearance being leaked onto the internet as someone might have once feared an ordinary photograph could steal a soul. Rather, those who are going to great efforts to destroy the boundaries of personal privacy should be heavily regulated to prevent them from doing so and heavily incentivized to safeguard private data whenever they are in possession of it.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#199

Earlier quoted context omitted.

Jail time for bugs? Have people here every worked on products? Bugs and security vulns are literally inevitable. Security is important but it this was the standard I'm not sure that any company would still exist.

Jail time for bugs that should have been preventible and caused harm to users. Mistakes and bugs happen, but we also have methods of mitigating them. Standards, quality controls, tests, analysis, and other care. I specifically said jail time for gross negligence because that means not taking care and allowing harm to users. If you had an error that leaked private information, it's worth an investigation. If it made i…

What is "should have been preventable"? Mandatory continuous fuzzing of all apis? Interprocedural static analysis to detect all of the owasp top ten? Manual audits of all dependencies and transitive dependencies on every update? Hire world class auditors to manually inspect code?

I'm a huge security person. It's my job. But its unbelievably difficult to secure programs even if there are clear steps in hindsight that could have prevented a bug.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#200

Facebook is a global database of political dissidents, queer persons, apostates, and other categories of people whose physical safety is put in peril when their personal lives are leaked. Facebook surely must be heavily fined and regulated for their misbehavior, because to fail to keep Facebook data safe is to put lives at risk.

Going to play the devil’s advocate. If you fine Facebook, you have to fine the small companies too, and even individual developers developing OSS, since the law should apply to everyone equally. Of course the fines have to be proportional to the number of affected users. So would you like a fine for your bugs? And note that contrary to other professions, software development doesn’t have generally agreed recipes for…

> Being fined for a contribution to an OSS project would be terrible, wouldn’t it?

Not if your contribution causes harm. A fine would be a more than welcome addition to consumer protections.

Post reply on HN