Live data from Hacker News

Facebook says new bug allowed apps access to private photos of up to 6.8M users

washingtonpost.com

251–260 of 280 posts

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#251

I never assume that “settings” guarantee what they claim. It’s just not practical even with good intentions, for a single non-public code base. As a developer, I know it is hard to implement something once, harder to implement consistently across multiple interfaces, and damn near impossible to keep correct years later after employee turnover and other twists. The sad thing is that it costs a ton more money to do thi…

This bug is just another example of the Valley children doing what they do best - writing terrible code. Keep moving fast and breaking things, kids. Please keep your culture confined to the west.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#252

I never assume that “settings” guarantee what they claim. It’s just not practical even with good intentions, for a single non-public code base. As a developer, I know it is hard to implement something once, harder to implement consistently across multiple interfaces, and damn near impossible to keep correct years later after employee turnover and other twists. The sad thing is that it costs a ton more money to do thi…

even moreso when you remember that SO MANY COMPANIES enforce most of their auth z/n at the edge, and are a lot looser between internal services

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#253

Earlier quoted context omitted.

Hi. I've worked in medical software repeatedly. I totally want to deal with HIPAA. It's a good idea for clients (the people who actually matter) and it's not nearly as difficult a prospect to work with as people say. The set of demands it makes upon you are small and reasonably constrained and are nearly all process-based rather than technical. Where it is technical, plenty of folks will sign a BAA for you to take bi…

>"But HIPAA" has never, in my experience, been employed except by people who find the idea of doing the right thing inconvenient or inconveniently expensive. (It is virtually never that hard and its benefits are clear.) Thank you for directly attacking my character without even addressing my actual argument. I'm not arguing against HIPAA, I'm arguing against such regulations in spaces that don't require that kind of…

[deleted]

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#254

Earlier quoted context omitted.

Hi. I've worked in medical software repeatedly. I totally want to deal with HIPAA. It's a good idea for clients (the people who actually matter) and it's not nearly as difficult a prospect to work with as people say. The set of demands it makes upon you are small and reasonably constrained and are nearly all process-based rather than technical. Where it is technical, plenty of folks will sign a BAA for you to take bi…

>"But HIPAA" has never, in my experience, been employed except by people who find the idea of doing the right thing inconvenient or inconveniently expensive. (It is virtually never that hard and its benefits are clear.) Thank you for directly attacking my character without even addressing my actual argument. I'm not arguing against HIPAA, I'm arguing against such regulations in spaces that don't require that kind of…

[deleted]

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#255

Earlier quoted context omitted.

Going to play the devil’s advocate. If you fine Facebook, you have to fine the small companies too, and even individual developers developing OSS, since the law should apply to everyone equally. Of course the fines have to be proportional to the number of affected users. So would you like a fine for your bugs? And note that contrary to other professions, software development doesn’t have generally agreed recipes for…

> If you fine Facebook, you have to fine the small companies too, and even individual developers developing OSS, since the law should apply to everyone equally. I would agree regarding small companies, but I wouldn't put oss developers in the same boat, fining the entity that provides a service makes more sense. It doesn't matter if that service relies on OSS or not. It's the company providing the service to the cons…

> It's the company providing the service to the consumer who is responsible to vet the final product.

I agree with your post, but I tend to think of facebook's users as providing the product (their attention). If the consumer is a company buying advertising, then where's facebook's motivation to be careful with a user's "private" data?

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#257
post #117

Unrelated, but I'd love to know how that article managed to get a picture of that Facebook sign without people standing in front of it. I drive by it daily and I've never seen it without people posing in front of it :)

If you take multiple pictures then run algorithm that only keeps mode ( most occurring ) pixels then stationary object will stay and moving people or objects will disappear. Photoshop has this function. Tutorials on YouTube.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#258

Earlier quoted context omitted.

> If you fine Facebook, you have to fine the small companies too, and even individual developers developing OSS, since the law should apply to everyone equally. I would agree regarding small companies, but I wouldn't put oss developers in the same boat, fining the entity that provides a service makes more sense. It doesn't matter if that service relies on OSS or not. It's the company providing the service to the cons…

> It's the company providing the service to the consumer who is responsible to vet the final product. I agree with your post, but I tend to think of facebook's users as providing the product (their attention). If the consumer is a company buying advertising, then where's facebook's motivation to be careful with a user's "private" data?

Sorry, but you’re overthinking this. Facebooks product is not advertising. It’s a platform that brings users and advertisers together. Just because it’s free for some or most users of the platform doesn’t mean that only paying people (advertisers) need to be protected.

Under GDPR, it actually doesn’t matter if you charge money for your product or not. If you process personal data, you’re responsible for it. This also applies to private people with no commercial interest who start to gather data from strangers (in exchange for some service or whatever).

Edit: The motivation should’ve been there from the beginning, if only for ethical reasons. Now the motivation is probably enforced by hefty fines.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#260
post #258

Earlier quoted context omitted.

> It's the company providing the service to the consumer who is responsible to vet the final product. I agree with your post, but I tend to think of facebook's users as providing the product (their attention). If the consumer is a company buying advertising, then where's facebook's motivation to be careful with a user's "private" data?

Sorry, but you’re overthinking this. Facebooks product is not advertising. It’s a platform that brings users and advertisers together. Just because it’s free for some or most users of the platform doesn’t mean that only paying people (advertisers) need to be protected. Under GDPR, it actually doesn’t matter if you charge money for your product or not. If you process personal data, you’re responsible for it. This also…

Answer this: If facebook's product is not advertising, then how do they make money?
Post reply on HN