Live data from Hacker News

Facebook says new bug allowed apps access to private photos of up to 6.8M users

washingtonpost.com

201–210 of 280 posts

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#201

Earlier quoted context omitted.

Going to play the devil’s advocate. If you fine Facebook, you have to fine the small companies too, and even individual developers developing OSS, since the law should apply to everyone equally. Of course the fines have to be proportional to the number of affected users. So would you like a fine for your bugs? And note that contrary to other professions, software development doesn’t have generally agreed recipes for…

Absolutely. Fine everyone into the ground. Doesn't look like there is any other way to make people take security seriously. I'm not a fan of the overregulation of industries like aviation, but consumer software has gone too far in the other direction and is long overdue for an adjustment.

Really? How has "consumer software gone too far in the other direction"?

Does it ... kill people? Does it enforce bad policies like the healthcare industry did for the past couple of decades, causing an epidemic of obesity, diabetes and heart disease, which are the top causes of death?

Yeah, regulation there definitely helped /s

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#202

Earlier quoted context omitted.

Really, so does Mastodon qualify? https://joinmastodon.org/ How about a blog commenting system that leaks emails due to a bug, something like Isso: https://posativ.org/isso/ Basically I don't like these arguments because it's about the company's size. Facebook should be punished because they are big, have a lot of data and we don't like them, right? No matter how you look at it, it's a Pandora's box.

Maybe there should be a general regulatory framework which all data-storing entities should be subjected to, with stiff penalties for the largest violators, as they can shoulder the burden of the biggest burdens. Is this not how it works for every other industry? Up until the 2008 bank bailouts, that is.

That does not answer my questions.

So what should the penalty be for a 14 year old that contributes a bug into a project like Mastodon or OpenSSH or whatever, which then leaks the data of tens of millions of people?

All this would do is to have a chilling effect on the industry such that only big companies like Facebook will be able to develop critical software, due to being able to afford it. And yes, this happens in all the industries you're talking about. And it did not stop the market from crashing, it did not stop malpractice.

Also this regulation will probably not stop Facebook from lawfully violating privacy.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#203

Earlier quoted context omitted.

Maybe there should be a general regulatory framework which all data-storing entities should be subjected to, with stiff penalties for the largest violators, as they can shoulder the burden of the biggest burdens. Is this not how it works for every other industry? Up until the 2008 bank bailouts, that is.

That does not answer my questions. So what should the penalty be for a 14 year old that contributes a bug into a project like Mastodon or OpenSSH or whatever, which then leaks the data of tens of millions of people? All this would do is to have a chilling effect on the industry such that only big companies like Facebook will be able to develop critical software, due to being able to afford it. And yes, this happens i…

Maybe there should be a chilling effect on the industry, and the drive to consume ever more personal data is harmful to society and wrong.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#205

Earlier quoted context omitted.

> If you fine Facebook, you have to fine the small companies too... Absolutely nothing wrong with that. If a small trucking company has a driver that speeds, that driver gets fined the same way a driver for a large trucking company does. > Of course the fines have to be proportional to the number of affected users. Of course.

Personally I hate analogies. The recipe for how a driver should not go over the speed limit is well known. Nowadays you even have the GPS apps alerting you and many trucks get monitored in real time from the dispatch center, drivers risking to be fired if not exactly on schedule. Most software projects are greenfield ... people reuse previous work when available and for a good price, but all custom changes are greenf…

> It's really not the same thing, lets not pretend that it is...

You're right. Look, software is complicated, and there's no way, yet, to make it bug free for any meaningful system. I get that. But at the same time, let's stop calling ourselves engineers if we keep hiding behind 'bugs happen'. We need to be a LOT more responsible than that. Does that mean regulation? If we keep going down the road we're on, yes. Because I gotta be honest, I'm tired of hearing, 'bugs happen' and I, the consumer, am the one who suffers.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#206
post #200

Earlier quoted context omitted.

Going to play the devil’s advocate. If you fine Facebook, you have to fine the small companies too, and even individual developers developing OSS, since the law should apply to everyone equally. Of course the fines have to be proportional to the number of affected users. So would you like a fine for your bugs? And note that contrary to other professions, software development doesn’t have generally agreed recipes for…

> Being fined for a contribution to an OSS project would be terrible, wouldn’t it? Not if your contribution causes harm. A fine would be a more than welcome addition to consumer protections.

In other words you'd rather have companies like Facebook develop critical software, because that's exactly what would happen, because only companies with big pockets would be able to afford it, is that right?

Funny, because community-driven open source is the only hope for replacing Facebook with something that is privacy oriented.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#207
post #15

Earlier quoted context omitted.

If they aren't actually deleting accounts then they are going to end up with a hefty fine under the GPDR one day...

Given that it's known that Facebook builds shadow profiles of non-users it seems hard to believe that they would give up the data of ex-users. https://www.bustle.com/p/what-are-shadow-profiles-facebook-c...

"Oh yeah we deleted the account, you can't log in with that same email and password anymore so it's as good as gone!"

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#208

Earlier quoted context omitted.

Absolutely. Fine everyone into the ground. Doesn't look like there is any other way to make people take security seriously. I'm not a fan of the overregulation of industries like aviation, but consumer software has gone too far in the other direction and is long overdue for an adjustment.

Really? How has " consumer software gone too far in the other direction "? Does it ... kill people? Does it enforce bad policies like the healthcare industry did for the past couple of decades, causing an epidemic of obesity, diabetes and heart disease, which are the top causes of death? Yeah, regulation there definitely helped /s

> Does it ... kill people?

Facebook asked users to upload nude photos. what if those get leaked and users commit suicide because of it? Would you (partially) blame facebook for their death?

> Does it enforce bad policies like the healthcare industry did for the past couple of decades, causing an epidemic of obesity, diabetes and heart disease, which are the top causes of death?

Genuine question but what policies are the reasons for the epidemic of the three death causes you just mentioned?

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#209

Earlier quoted context omitted.

> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.

Yes, I am suggesting that. I don't necessarily think jail time is the right thing, but I do think something like meaningful fines are more than reasonable for major software bugs that cause these kinds of breaches of privacy. It will make larger companies like this be much more careful when money is on the table for them to lose. To me, if we can criminalize something like a major oil spill such as BP/Deepwater Horiz…

Jail would be full of WordPress devs

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#210

Earlier quoted context omitted.

That does not answer my questions. So what should the penalty be for a 14 year old that contributes a bug into a project like Mastodon or OpenSSH or whatever, which then leaks the data of tens of millions of people? All this would do is to have a chilling effect on the industry such that only big companies like Facebook will be able to develop critical software, due to being able to afford it. And yes, this happens i…

Maybe there should be a chilling effect on the industry, and the drive to consume ever more personal data is harmful to society and wrong.

Oh, but that's the thing, there's no regulation that can stop the consumption of personal data. Let's be clear, we are talking about bugs. The consumption of personal data will continue, because:

1. consumers want it

2. governments want it

The only thing regulation will accomplish is that only companies like Facebook will be able to do it. Yeah, big win.

Post reply on HN