Earlier quoted context omitted.
> This is false. citation please. Here's mine: > Criminal penalties > > Covered entities and specified individuals, as explained below, who "knowingly" obtain or disclose individually identifiable health information, in violation of the Administrative Simplification Regulations, face a fine of up to $50,000, as well as imprisonment up to 1 year. > > Offenses committed under false pretenses allow penalties to be incre…
My company's lawyers disagree. I'll go with my company's lawyers' judgement over a group that exists solely to protect the interests of its member doctors.
Facebook says new bug allowed apps access to private photos of up to 6.8M users
221–230 of 280 posts
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#222Earlier quoted context omitted.
> Sounds like you're suggesting that we criminalize software bugs. When there is irreparable damage I believe it should be criminalized. You cannot regain privacy after an incident such as this, it is irrevocably taken from you against your will.
Suppose there is a bug in the Linux kernel. Some business runs their webservers on Linux. They have user email addresses (PII). Is Linus responsible for breaches? If so, then OSS dies. If not, then how do you intend to prove that their are no vulns in any of your dependencies for the rest of time?
If you’re using OSS for mission-critical software you must either ensure that it’s fit for purpose or pay someone to do it for you. Nothing in the Linux Kernel documentation suggests that it can/should be used for flying airplanes of securing PII without doing additional due diligence.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#223Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#224“Private” photos that people uploaded to Facebook. Sounds like a good time to reiterate the advice: Don’t upload things to the internet that you don’t want to be on the internet. That way there won’t be any of your things on the internet that you didn’t want to be there.
Except that your friends, family, and others can upload private photos with you in them.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#225Earlier quoted context omitted.
Jail time for bugs that should have been preventible and caused harm to users. Mistakes and bugs happen, but we also have methods of mitigating them. Standards, quality controls, tests, analysis, and other care. I specifically said jail time for gross negligence because that means not taking care and allowing harm to users. If you had an error that leaked private information, it's worth an investigation. If it made i…
What is "should have been preventable"? Mandatory continuous fuzzing of all apis? Interprocedural static analysis to detect all of the owasp top ten? Manual audits of all dependencies and transitive dependencies on every update? Hire world class auditors to manually inspect code? I'm a huge security person. It's my job. But its unbelievably difficult to secure programs even if there are clear steps in hindsight that…
All of the above, possibly. Other engineering disciplines seem to have defined what constitutes due diligence just fine. This isn’t a novel problem.
It’s obviously not possible to make anything perfectly safe or perfectly secure. But it’s certainly possible to define a minimum amount of effort that must be put towards these goals in the form of best practices, required oversight, and paper trails.
Edit: Even “fuzzy” disciplines like law have standards for what constitutes malpractice or negligence when representing a client.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#226“Private” photos that people uploaded to Facebook. Sounds like a good time to reiterate the advice: Don’t upload things to the internet that you don’t want to be on the internet. That way there won’t be any of your things on the internet that you didn’t want to be there.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#227Earlier quoted context omitted.
Going to play the devil’s advocate. If you fine Facebook, you have to fine the small companies too, and even individual developers developing OSS, since the law should apply to everyone equally. Of course the fines have to be proportional to the number of affected users. So would you like a fine for your bugs? And note that contrary to other professions, software development doesn’t have generally agreed recipes for…
Absolutely. Fine everyone into the ground. Doesn't look like there is any other way to make people take security seriously. I'm not a fan of the overregulation of industries like aviation, but consumer software has gone too far in the other direction and is long overdue for an adjustment.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#228> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…
Nothing bad ever comes to companies as a consequence of these leaks, so what is their incentive to stop them? It happens so often that it goes down the memory hole after maybe a week or two, so even that isn't much of an incentive. We shouldn't be surprised about this.
I could probably get away with murder, but for some reason I'm not out on the town strangling prostitutes.
Why do companies always need an "incentive" to not be anti-social? Why can't CEOs simply derive pleasure from delivering a quality service in exchange for some advertising eyeballs?
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#229Earlier quoted context omitted.
I left FB when they made reverted a policy that let you opt to confirm all tags before they showed up in searches for you. This means anyone in the world can upload an image, tag you in it, and it will show up in searches for you. It still won’t show up on your profile if you have confirmations for that enabled, but still.
No need to tag, just facial recognition will get you from previous tags and other metadata
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#230> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…
Kerching