Live data from Hacker News

Facebook says new bug allowed apps access to private photos of up to 6.8M users

washingtonpost.com

221–230 of 280 posts

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#221

Earlier quoted context omitted.

> This is false. citation please. Here's mine: > Criminal penalties > > Covered entities and specified individuals, as explained below, who "knowingly" obtain or disclose individually identifiable health information, in violation of the Administrative Simplification Regulations, face a fine of up to $50,000, as well as imprisonment up to 1 year. > > Offenses committed under false pretenses allow penalties to be incre…

My company's lawyers disagree. I'll go with my company's lawyers' judgement over a group that exists solely to protect the interests of its member doctors.

Are these lawyers you have talked to and gotten meaningful and nuanced advice from, or are they lawyers your bosses have talked to and derived maximally avoidant policies from? I'm not saying that you shouldn't have policies that fit your risk profile, but I ask because I have been in those former conversations (and I have done a nontrivial amount of auditing+compliance work in this space) and have never come away with such an impression, while at the same time the level of perceived risk that your bosses derive from those conversations can be entirely untethered from the level of risk that actually exists. (This space is full of people saying "oh, HIPAA means we can't do that" as shorthand for "I don't want to do that," after all.)

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#222
post #57

Earlier quoted context omitted.

> Sounds like you're suggesting that we criminalize software bugs. When there is irreparable damage I believe it should be criminalized. You cannot regain privacy after an incident such as this, it is irrevocably taken from you against your will.

Suppose there is a bug in the Linux kernel. Some business runs their webservers on Linux. They have user email addresses (PII). Is Linus responsible for breaches? If so, then OSS dies. If not, then how do you intend to prove that their are no vulns in any of your dependencies for the rest of time?

This is silly. If I build my bridge with equations I find on mathoverflow, the forum is not responsible for my bridge collapsing.

If you’re using OSS for mission-critical software you must either ensure that it’s fit for purpose or pay someone to do it for you. Nothing in the Linux Kernel documentation suggests that it can/should be used for flying airplanes of securing PII without doing additional due diligence.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#223
Remember when Facebook wanted you to upload nudes so they could help keep them off of Facebook and the internet...yeahhh hopefully no one trusted them with that. Also are there even any safeguards preventing private photos like these or even nudes from not being able to be viewed by any admin? I hope there is...

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#224
post #29

“Private” photos that people uploaded to Facebook. Sounds like a good time to reiterate the advice: Don’t upload things to the internet that you don’t want to be on the internet. That way there won’t be any of your things on the internet that you didn’t want to be there.

Except that your friends, family, and others can upload private photos with you in them.

Sadly, this is the moment that those photos stop being private. I get that this is hard for the general public to understand - but at this point, uploading anything to Facebook = obfuscated, maybe, but not private.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#225

Earlier quoted context omitted.

Jail time for bugs that should have been preventible and caused harm to users. Mistakes and bugs happen, but we also have methods of mitigating them. Standards, quality controls, tests, analysis, and other care. I specifically said jail time for gross negligence because that means not taking care and allowing harm to users. If you had an error that leaked private information, it's worth an investigation. If it made i…

What is "should have been preventable"? Mandatory continuous fuzzing of all apis? Interprocedural static analysis to detect all of the owasp top ten? Manual audits of all dependencies and transitive dependencies on every update? Hire world class auditors to manually inspect code? I'm a huge security person. It's my job. But its unbelievably difficult to secure programs even if there are clear steps in hindsight that…

> What is "should have been preventable"? Mandatory continuous fuzzing of all apis? Interprocedural static analysis to detect all of the owasp top ten? ...

All of the above, possibly. Other engineering disciplines seem to have defined what constitutes due diligence just fine. This isn’t a novel problem.

It’s obviously not possible to make anything perfectly safe or perfectly secure. But it’s certainly possible to define a minimum amount of effort that must be put towards these goals in the form of best practices, required oversight, and paper trails.

Edit: Even “fuzzy” disciplines like law have standards for what constitutes malpractice or negligence when representing a client.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#226

“Private” photos that people uploaded to Facebook. Sounds like a good time to reiterate the advice: Don’t upload things to the internet that you don’t want to be on the internet. That way there won’t be any of your things on the internet that you didn’t want to be there.

This ship hasn’t just sailed, but its masts are no longer even visible over the horizon. Both major phone operating systems actively encourage synchronizing all photos with a server on the internet.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#227

Earlier quoted context omitted.

Going to play the devil’s advocate. If you fine Facebook, you have to fine the small companies too, and even individual developers developing OSS, since the law should apply to everyone equally. Of course the fines have to be proportional to the number of affected users. So would you like a fine for your bugs? And note that contrary to other professions, software development doesn’t have generally agreed recipes for…

Absolutely. Fine everyone into the ground. Doesn't look like there is any other way to make people take security seriously. I'm not a fan of the overregulation of industries like aviation, but consumer software has gone too far in the other direction and is long overdue for an adjustment.

Fine everyone? Oh look, data breaches stop being reported. I guess we succeeded in reducing them?

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#228
post #93

> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…

Nothing bad ever comes to companies as a consequence of these leaks, so what is their incentive to stop them? It happens so often that it goes down the memory hole after maybe a week or two, so even that isn't much of an incentive. We shouldn't be surprised about this.

>Nothing bad ever comes to companies as a consequence of these leaks, so what is their incentive to stop them?

I could probably get away with murder, but for some reason I'm not out on the town strangling prostitutes.

Why do companies always need an "incentive" to not be anti-social? Why can't CEOs simply derive pleasure from delivering a quality service in exchange for some advertising eyeballs?

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#229
post #53

Earlier quoted context omitted.

I left FB when they made reverted a policy that let you opt to confirm all tags before they showed up in searches for you. This means anyone in the world can upload an image, tag you in it, and it will show up in searches for you. It still won’t show up on your profile if you have confirmations for that enabled, but still.

No need to tag, just facial recognition will get you from previous tags and other metadata

Will it show up in searches from just facial recognition? That would be very bad for anyone trying to live in a way incongruent with their culture’s standards. (I personally left in solidarity with a Muslim friend who no longer wears Hijab, but would prefer her family didn’t know that; pictures of her without Hijab started showing up in searches without her approval suddenly and without warning when they removed the old “confirm before search results” option)

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#230

> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…

Whoops soz .... lol, l8erz.

Kerching

Post reply on HN