Earlier quoted context omitted.
Can anyone on HN please explain why, why, WHY are we still using SMS/telephony which has exactly 0 encryption wh---I guess that's the reason? It's insane. I've heard banks using SMS!!!! To send a code. We have TOTP for that! Or even perhaps a push notification or something better than bloody SMS. I refuse to use the networking system altogether. No phones, no calls. Of course you do 'need' a number so I keep one hand…
I don't know anything about the technical details with this, but I wonder why mobile service providers don't just kill off regular SMS and calling, and start providing service exclusively through data connections? The infrastructure for that old stuff can't be free for them, there must be some significant costs associated with it. Maybe Starlink will be able to provide a mobile phone service that only offers a data c…
Facebook does not plan to notify half-billion users affected by data leak
241–250 of 315 posts
Re: Facebook does not plan to notify half-billion users affected by data leak
#242Earlier quoted context omitted.
Certainly I cannot be the only one who finds phone numbers, email addresses, and many other things quite inconsequential compared to name and address. In particular, there could easily be a postal system implemented where the sender would not need the actual physical address of the receiver. The receiver could easily ask the postal service to generate an arbitrary key which could either be single use, or multiple use…
So much of what is considered private "PII" today was considered public information only a generation ago. When I was a kid (1970s): - Names, addresses, and phone numbers were published by the phone company in a book and given to everyone. - Hospital admissions/discharges were published in the local newspaper. - Social Security Number was used for everything. Many people included it on their pre-printed checks. Engra…
Yes, and I think it was wrong to do so.
I think it's ridiculous to be worried about websites tracking one's noncorporeal identity tied to an integer on the internet compared to that everyone in my sport's club can easily retrieve my physical place of residence.
Re: Facebook does not plan to notify half-billion users affected by data leak
#243"The Facebook spokesman said the social media company *was not confident it had full visibility on which users would need to be notified*." @Facebook here you go: https://haveibeenpwned.com
I think Facebook (rightfully, IMO) would argue the existence of that data dump is no proof that data came from Facebook’s servers. They can’t assume that, or trolls or unscrupulous competitors would start creating ‘Facebook’ data dumps left and right. I do wonder what EU regulators will say about their viewpoint that they do not have to inform their users, though.
Re: Facebook does not plan to notify half-billion users affected by data leak
#244I’ve said it before and I’ll say it again, unless and until, companies like Facebook are fined appropriate amounts they’ll never stop. Quite literally, every business school on the fucking planet will tell you do something if it’s cheaper. It is cheaper for them to not give a fuck, than to give one. Unless they are fined upwards of $20-50bn it’ll never stop because it’s always going to benefit their bottom line. Full…
My only issues with this are that it's impractically hard to protect data to the extent necessary, and large fines become a lever for disgruntled employees to cause massive damage.
Re: Facebook does not plan to notify half-billion users affected by data leak
#245I’ve said it before and I’ll say it again, unless and until, companies like Facebook are fined appropriate amounts they’ll never stop. Quite literally, every business school on the fucking planet will tell you do something if it’s cheaper. It is cheaper for them to not give a fuck, than to give one. Unless they are fined upwards of $20-50bn it’ll never stop because it’s always going to benefit their bottom line. Full…
Re: Facebook does not plan to notify half-billion users affected by data leak
#246I’ve said it before and I’ll say it again, unless and until, companies like Facebook are fined appropriate amounts they’ll never stop. Quite literally, every business school on the fucking planet will tell you do something if it’s cheaper. It is cheaper for them to not give a fuck, than to give one. Unless they are fined upwards of $20-50bn it’ll never stop because it’s always going to benefit their bottom line. Full…
I agree but where would the money go?
Re: Facebook does not plan to notify half-billion users affected by data leak
#247Earlier quoted context omitted.
> If Facebook has since deleted some of those accounts or associated phone numbers, they may no longer have a way to contact those users That would totally defy logic. I don't think that Facebook deletes anything ever .
I deleted my account a few months ago and was pleasantly surprised to find that it didn't surface in the breach. It could just be hiding in a different datastore of course, but it's definitely more fucks than I thought they gave.
Re: Facebook does not plan to notify half-billion users affected by data leak
#248Earlier quoted context omitted.
"Where?!" Everywhere. It's being phased out in many places, but as a rule of thumb, mostly everywhere still. "known to be very bad ... been shouting ..." Right, yeah, to put it in some perspective remember that you're talking second factor here. This is not your login, this is a secondary confirmation and you still need some serious motivation to bypass it. It's definitely doable, I work in security and I know what k…
I'd never seen or heard of it being used for payments before, which is why I asked - I'd heard of phone numbers being used as account names (effectively) in some payment systems, but being involved in the workflow of making payments is entirely novel to me. I'm aware it's not your login, but it feels the same as asking someone for publicly searchable information to "verify your identity" - an additional "security" st…
I do agree with you there. To be clear, while I think the problem is of a smaller magnitude, I do agree with your general point. Other alternatives like very simple TOTP tokens additionally don't require a phone number and so you don't have this stupid "add your phone number now, we'll use it only for security, pinky swear!" prompts.
Heck, there could even be an argument that SMS OTP is now illegal with GDPR unless the user gives explicit consent. You can't use user data (PII) if it's not with consent, for a legitimate purpose, to fulfill a contract, for the user's own good, to comply with law enforcement, and I'm probably forgetting one or two reasons. Now that it's clear that stuff like TOTP is a better alternative, there is no reason to process people's phone number anymore for this purpose, making it impossible for you to send that SMS OTP. (Of course, you'd have to convince a judge that TOTP is better than SMS before we actually get case law on this specific use of a phone number so... *mumbles something about nine-tenths of the law*.)
Re: Facebook does not plan to notify half-billion users affected by data leak
#249"The Facebook spokesman said the social media company *was not confident it had full visibility on which users would need to be notified*." @Facebook here you go: https://haveibeenpwned.com
I think Facebook (rightfully, IMO) would argue the existence of that data dump is no proof that data came from Facebook’s servers. They can’t assume that, or trolls or unscrupulous competitors would start creating ‘Facebook’ data dumps left and right. I do wonder what EU regulators will say about their viewpoint that they do not have to inform their users, though.
Mark Zuckerbergs phone number was in the dataset. It came from Facebook.
Re: Facebook does not plan to notify half-billion users affected by data leak
#250Earlier quoted context omitted.
If customers do not care enough to stop using the product then there is no harm. Put in another way: the people you are trying to protect don't want your protection, because they don't care enough about the breach to stop using the product. They shouldn't be learning about the breaches from the company that has been breached because that gives the company too much power. Instead we should empower watchdog organizatio…
> If customers do not care enough to stop using the product then there is no harm. Facebook users (notably not customers) are the ones being harmed here, and they don't exactly have free reign to choose the platform their communities talk and organize on. If I choose not to use Facebook then I'm isolating myself from my community.