Live data from Hacker News

Facebook does not plan to notify half-billion users affected by data leak

reuters.com

221–230 of 315 posts

Re: Facebook does not plan to notify half-billion users affected by data leak

#221
post #87

For years companies have been steadily asking, mandating or even trickling users to give them their phone numbers under the excuse of security (while the real reasons were different), now what? How can they be trusted anymore? This also strikes a great point about the data sharing between Facebook and WhatsApp. Linking data between services augments the dangers and the consequences are not obvious to the end user. I…

Facebook should also offer complete opt out from any tracking. Their model where they offer their service for "free", but harvest tonnes of personal data and then use them for targeted advertising, should be regulated. If your family is on Facebook and you want to maintain contact with them, it is next to impossible to move everyone on a platform that respects privacy. I think an option where you pay monthly and in e…

I agree with much of what you say here and I think it would be an improvement. Personally, I still wouldn't use a tracking-less Facebook because:

1. I don't trust Facebook to not track me. When I left Facebook for good in 2014 it was because, for the second time after setting all my settings as private as I could (show photos only to friends, etc.), Facebook somehow reverted everything to "public".

2. Their algorithm is still aimed at generating controversy rather than truth, and that's enough for me to not use it.

Re: Facebook does not plan to notify half-billion users affected by data leak

#222
post #96

I suppose a well meaning spammer could just SMS everyone pretending to be Facebook.

Let me just drop a note here that I happen to have two "unlimited" SMS subscriptions (i.e. could at least notify a few thousand people) in different European countries and that contact info is in my profile in case anyone has... ideas... :-)

Can't edit anymore, but this was not exactly an invitation to email me names and phone numbers to text. I don't know the legal implications of sending mass unsolicited messages to people whose phone number I obtained through downloading questionable data.

If you really want to warn people and you have a plausible explanation for the legal basis on which we're doing this, then I would definitely be able to contribute resources to your cause.

But also, frankly, they put this info there and configured it to be public themselves. Doesn't mean they don't need to be warned about this misconfiguration, but it's quite different from if there had been a data leak caused by facebook that facebook isn't telling the users about. I don't feel the need to drop what I'm doing and spend a couple days looking into the legal status, coming up with a good narrative / what to text them, gathering other people, figuring out how a regular human being can send hundreds of text messages without doing custom app development (if avoidable), dealing with the aftermath...

TL;DR: if you cleared the list of todos in the previous sentence, then my resources you shall have.

Re: Facebook does not plan to notify half-billion users affected by data leak

#223

"The Facebook spokesman said the social media company *was not confident it had full visibility on which users would need to be notified*." @Facebook here you go: https://haveibeenpwned.com

I think Facebook (rightfully, IMO) would argue the existence of that data dump is no proof that data came from Facebook’s servers. They can’t assume that, or trolls or unscrupulous competitors would start creating ‘Facebook’ data dumps left and right. I do wonder what EU regulators will say about their viewpoint that they do not have to inform their users, though.

If they can't measure the scope of the breach they must notify all customers that they might have been affected.

Re: Facebook does not plan to notify half-billion users affected by data leak

#224

Earlier quoted context omitted.

A company that employs dozes of data scientists and has petabytes of data is now supposedly unable to compare and match two datasets? Come on, this is beyond ridiculous.

Clearly they technically can. It's that the GDPR doesn't allow it. Think about it... If you asked a company to delete your data, are you giving them permission to go refind that data on the dark web, cross reference it with records they should have deleted, and use it to send you email? Clearly not.

> It's that the GDPR doesn't allow it.

Source? Nothing prevents Facebook from making a public announcement that anyone that had an account on Facebook between dates X and Y might have been affected.

Re: Facebook does not plan to notify half-billion users affected by data leak

#225
post #205
post #204

Earlier quoted context omitted.

I have a strong suspicion that, if a government tried to fine a company in billions, that company would simply leave the country forever. I'm not saying that this is a good thing or a bad thing. It's just an intuition that I have.

What do you mean? Companies have been fined multi-billion dollar amounts in the past. Withdrawing from the US market is simply not an option for many companies. I strongly suspect it wouldn’t be a realistic option for Facebook. That said, I think the parent comment that suggests “20-50B” fines is dramatically overestimating what it would take to promote more depositor behaviour here. Even much smaller fines with the…

On top of that, withdrawing from the country after breaking the law and being fined is like fleeing the country after being convicted of a crime. It's not a legal cover.

The first move is usually to legally object to the fine if it's more than the cost of doing business, leading to years of back and forth. Look at the fine the EU imposed on Intel in 2009 which keeps getting contested and reexamined. Increasing the cost and friction for the ones trying to recoup the fine makes them more willing to negotiate a faster settlement (usually better deal for the company). It's a good bargaining chip for the company if they have very few assets under that jurisdiction or it's a market they can afford to lose. So the company pays some of the fine and then sees much stricter controls applied to them in particular, not via law but via the settlement.

Finally the company is represented by a CEO and/or board and those are the people ultimately responsible for disregarding a court decision. There could be attempts to hold them responsible but the US is famous for protecting any CEO from prison time (inside or outside of US borders). The US has a history of refusing to extradite CEOs convicted simply because they can purchase their way out of any trouble, it's only a matter of price. So this last step is mostly symbolic, the CEO is convicted because justice has to be served in the accusing jurisdiction.

Re: Facebook does not plan to notify half-billion users affected by data leak

#226

Earlier quoted context omitted.

Can anyone on HN please explain why, why, WHY are we still using SMS/telephony which has exactly 0 encryption wh---I guess that's the reason? It's insane. I've heard banks using SMS!!!! To send a code. We have TOTP for that! Or even perhaps a push notification or something better than bloody SMS. I refuse to use the networking system altogether. No phones, no calls. Of course you do 'need' a number so I keep one hand…

It's because SMS works without data. I doubt that most of the people that complain about SMS live in rural areas. It seems to be more of a US thing. The country is so large that unless you live in a city you just won't be able to get data reliably. This leaves SMS as the only form of phone communication that isn't a voice call.

Agree, SMS just work, everywhere and always, with every mobile phone.

Re: Facebook does not plan to notify half-billion users affected by data leak

#227
This leak is putting people's lives at risk.

What is truly damaging about this breach is that it allows for bidirectional mapping of phone ⭤ name (and often location, since the data can include town/employer).

The risk is much bigger than "I'm going to get more phone spam."

Examples:

- An abusive ex/stalker type can now search by name and find his ex's phone number and maybe even city/town.

- Have you ever dealt with an irate person via phone? (craigslist deal gone wrong/creepy, for example). This person can now know your name and even photo since the leak includes your fb id.

I am certain that both of these things will happen in the next few months or years. If privacy changes are to happen at the legislative/personal responsibility level, it would behoove an organization like the EFF to find one such case and use it to sue the living daylights out of FB. I think it's also worth mentioning these sorts of risks instead of focusing on "spam".

Unfortunately, even if that were to happen, we'd end up with a moral panic, which almost always ends up punishing the wrong people. What we really need is a change in the kinds of data that are allowed to be kept, and a change in data/identification infrastructure.

Things like:

- The creation of a standardized & subsidized token/OTP platform. In the US for example, you should be able to go to the post office and get a NIST approved token generator, which should be mandated to be used by all banks and replace SMS and SSN as authentication.

- A pseudonimity middle-layer (ie, Stripe for Privacy). For example, when I buy a t-shirt online, I should be able to simply give the merchant my pseudonym, and they shouldn't store my actual name & address. If they want to store that there should be much much higher data protection requirements.

This infrastructure should be free market but with a "public option" in order to prevent oligopolization of these services.

Re: Facebook does not plan to notify half-billion users affected by data leak

#228

The "real names" myth was the biggest scam played against people in the past 15 years. The media are also wholesale responsible for perpetuating that damaging trend. Historians of the future will look at the past 2 decades with disbelief.

Yeah, it’s fine to have some public facing content online, but the first thing a child used to learn before going online was to never use your real name and to never give out any personal information like your address and telephone number. At least that’s how it was where I grew up. I remember when Facebook launched I had a visceral reaction after seeing all the content being shared out in the open. My dad didn’t eve…

My first online social experience was Usenet in the 1980s. It was very common for people to use their real names (though certainly not everyone did). My university encouraged real names, the rationale was that if you use your real name you will be more courteous, and only say things that you would want to be associated with. It's much easier to troll and engage in flamewars and generally be an asshole if you do it anonymously.

Re: Facebook does not plan to notify half-billion users affected by data leak

#229
post #204

I’ve said it before and I’ll say it again, unless and until, companies like Facebook are fined appropriate amounts they’ll never stop. Quite literally, every business school on the fucking planet will tell you do something if it’s cheaper. It is cheaper for them to not give a fuck, than to give one. Unless they are fined upwards of $20-50bn it’ll never stop because it’s always going to benefit their bottom line. Full…

I have a strong suspicion that, if a government tried to fine a company in billions, that company would simply leave the country forever. I'm not saying that this is a good thing or a bad thing. It's just an intuition that I have.

And go... where?

Re: Facebook does not plan to notify half-billion users affected by data leak

#230
post #66
post #22

Why notifiy? Victims got notified everyday with many spam-sms. Thanks Facebook!

Because I would really like to know if I'm affected. According to "Have I Been Pwned" my phone number is not in the list, but about one or two weeks ago I noticed that my spam folder was unusually full, which led me to believe that something new must have happened. Shortly thereafter Facebook's leak hit the news. From my point of view it is their obligation to notify all the affected users. It's morally the right thi…

Just assume the answer is yes. If you are active online at all, you're in a breach somewhere. In fact, you are likely in a breach even if you are not active online (in a state/federal government data breach for example)
Post reply on HN