Earlier quoted context omitted.
Going to play the devil’s advocate. If you fine Facebook, you have to fine the small companies too, and even individual developers developing OSS, since the law should apply to everyone equally. Of course the fines have to be proportional to the number of affected users. So would you like a fine for your bugs? And note that contrary to other professions, software development doesn’t have generally agreed recipes for…
> If you fine Facebook, you have to fine the small companies too, and even individual developers developing OSS, since the law should apply to everyone equally. I would agree regarding small companies, but I wouldn't put oss developers in the same boat, fining the entity that provides a service makes more sense. It doesn't matter if that service relies on OSS or not. It's the company providing the service to the cons…
Facebook says new bug allowed apps access to private photos of up to 6.8M users
231–240 of 280 posts
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#232Earlier quoted context omitted.
> If you fine Facebook, you have to fine the small companies too, and even individual developers developing OSS, since the law should apply to everyone equally. I would agree regarding small companies, but I wouldn't put oss developers in the same boat, fining the entity that provides a service makes more sense. It doesn't matter if that service relies on OSS or not. It's the company providing the service to the cons…
Plus OSS software is often provided with not liability or warranty, which should protect developers from legislation.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#233Earlier quoted context omitted.
Just a quick question, do you write software? Do you have a legal or economic background? It seems pretty clear to me that anyone suggesting that software bugs in applications that have no risk of causing physical harm should have criminal liability has no idea what they are talking about and what damage such a law would cause. Case in point look at the quality of medical software today. Hospitals still use windows x…
HIPAA only carries criminal penalties when someone knowingly discloses covered information - not a software bug. Until the bug is identified at least. For the most part HIPAA is enforced with civil penalties. And your "nightmare" scenario of (civil) liability flowing from programming bugs already exists in the investment world and it hasn't come apart at the seams. Google Axa Rosenberg. A coding error in their tradin…
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#234Facebook is a global database of political dissidents, queer persons, apostates, and other categories of people whose physical safety is put in peril when their personal lives are leaked. Facebook surely must be heavily fined and regulated for their misbehavior, because to fail to keep Facebook data safe is to put lives at risk.
I don’t get it. If we agree it sucks, why not just stop using it? Why do you want to use something made by people who don’t care about you?
That said, you and I can agree that FB sucks, and delete our accounts. It is up to other people whether they follow suit.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#235Earlier quoted context omitted.
My company's lawyers disagree. I'll go with my company's lawyers' judgement over a group that exists solely to protect the interests of its member doctors.
Are these lawyers you have talked to and gotten meaningful and nuanced advice from, or are they lawyers your bosses have talked to and derived maximally avoidant policies from? I'm not saying that you shouldn't have policies that fit your risk profile, but I ask because I have been in those former conversations (and I have done a nontrivial amount of auditing+compliance work in this space) and have never come away wi…
To me that trumps a non-lawyer’s interpretation of a non-legal web site.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#236Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#237Remember when Facebook wanted you to upload nudes so they could help keep them off of Facebook and the internet...yeahhh hopefully no one trusted them with that. Also are there even any safeguards preventing private photos like these or even nudes from not being able to be viewed by any admin? I hope there is...
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#238> The bug also impacted photos that people uploaded to Facebook but chose not to post. What about, for example, pictures sent in a private message? I'm so very glad I deleted my account months ago.
For pictures present on your phone which Facebook uploaded just in case you’d want to post them later. To hide latency essentially
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#239> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…
> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.
It happens with such regularity that I'm amazed anyone here would be kind enough to accept their fake apologies for clearly malicious actions.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#240Earlier quoted context omitted.
Need I remind you of the genocide in Myanmar organised to a large degree on social media, or the threat to political dissidents all over the world when authorities or malicious actors can get their hands on leaked, private data of individuals? Are you seriously suggesting that information in this day and age does not have the power to directly cause harm, including lethal harm, to people?
I am suggesting that Facebook is free, fleeting software, and that people shouldn't put a huge host of stock in it. Even legally. Also - that it can be used for organizing bad behaviours is an entirely different subject that has little to do with quality or security.
But Facebook is a company that actively snoops and uses the data of its resources, the end-user. It's like a security guard who's paid to prevent shoplifting actively ignoring violent crimes because it's not related to stealing, or a baby food company ignoring that some metal got into their food because the food is still OK if you pick out the metal bits.