Live data from Hacker News

Facebook says new bug allowed apps access to private photos of up to 6.8M users

washingtonpost.com

241–250 of 280 posts

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#242
post #189

Earlier quoted context omitted.

> The long-term solution to this mess should come from users abandoning it Where will the people go? If it's other software it might end being as bad or worse.

What’s the value of Facebook? Serious question as you think people should have alternative

I didn't say an alternative that is like Facebook.

People want to communicate with others. If they use software for that then.... my original question applies.

And you've avoided answering that question.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#243

Remember when Facebook wanted you to upload nudes so they could help keep them off of Facebook and the internet...yeahhh hopefully no one trusted them with that. Also are there even any safeguards preventing private photos like these or even nudes from not being able to be viewed by any admin? I hope there is...

I assume you’re being sarcastic. that never happened.

https://www.independent.co.uk/life-style/gadgets-and-tech/ne...

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#244

> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…

> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.

I think criminalizing commercial data leaks is a more workable idea.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#245

Earlier quoted context omitted.

> If you fine Facebook, you have to fine the small companies too... Absolutely nothing wrong with that. If a small trucking company has a driver that speeds, that driver gets fined the same way a driver for a large trucking company does. > Of course the fines have to be proportional to the number of affected users. Of course.

Personally I hate analogies. The recipe for how a driver should not go over the speed limit is well known. Nowadays you even have the GPS apps alerting you and many trucks get monitored in real time from the dispatch center, drivers risking to be fired if not exactly on schedule. Most software projects are greenfield ... people reuse previous work when available and for a good price, but all custom changes are greenf…

No, you’re wrong. Speeding is one minor factor in driver or truck safety. Motor Carrier regulation is about much more than speeding. It’s a difficult problem that is addressed via a federal/state/local framework of regulation and enforcement.

I’ve worked in engineering roles where law made me potentially criminally liable for negligent handling of certain data. We took things more seriously than Facebook.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#247

Earlier quoted context omitted.

> This is false. citation please. Here's mine: > Criminal penalties > > Covered entities and specified individuals, as explained below, who "knowingly" obtain or disclose individually identifiable health information, in violation of the Administrative Simplification Regulations, face a fine of up to $50,000, as well as imprisonment up to 1 year. > > Offenses committed under false pretenses allow penalties to be incre…

My company's lawyers disagree. I'll go with my company's lawyers' judgement over a group that exists solely to protect the interests of its member doctors.

They are wrong generally speaking. Willful conduct is the standard for criminal liability. A developer in good faith introducing a bug or inheriting one from a third party is not in that situations

My guess as to why the draconian position is more about the internal process. You have to identify and disclose breaches in a timely way; if you don’t the company is at risk.

From HHS summary of the rules:

(See: https://www.hhs.gov/hipaa/for-professionals/privacy/laws-reg... ) (it’s also laid out in the regulation which I don’t have time to find.)

“Criminal Penalties. A person who knowingly obtains or discloses individually identifiable health information in violation of the Privacy Rule may face a criminal penalty of up to $50,000 and up to one-year imprisonment. The criminal penalties increase to $100,000 and up to five years imprisonment if the wrongful conduct involves false pretenses, and to $250,000 and up to 10 years imprisonment if the wrongful conduct involves the intent to sell, transfer, or use identifiable health information for commercial advantage, personal gain or malicious harm.”

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#248
post #80

Earlier quoted context omitted.

Hammurabi's code (~1700 BC) includes this about building: Building Code 229. If a builder builds a house for a man and does not make its construction sound, and the house which he has built collapses and causes the death of the owner of the house, the builder shall be put to death. 233. If a builder builds a house for a man and does not make its construction sound, and a wall cracks, that builder shall strengthen tha…

But they aren’t. Most home sales in the US follow caveat emptor. If you buy a house from a private seller and then later discover mold in the walls or a crack in the foundation I wish you luck in getting the seller to pay for the repair.

Builder is the key. If you have a house built and the foundation is cracked or mold is growing, you’ll be able to successfully sue.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#249

Facebook is a global database of political dissidents, queer persons, apostates, and other categories of people whose physical safety is put in peril when their personal lives are leaked. Facebook surely must be heavily fined and regulated for their misbehavior, because to fail to keep Facebook data safe is to put lives at risk.

[dead]

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#250
post #146

Earlier quoted context omitted.

...for a certain value of 'active' (do they say how it's defined?) My experience of internet companies has generally been that user figures are somewhat exaggerated (to put it politely).

No matter how you define “active”, there is no indication that in the aggregate people are fleeing Facebook - no matter if a few anecdotes are posted on HN.

By Facebook’s generous standards, active users have been flat for a year or more.
Post reply on HN