I never assume that “settings” guarantee what they claim. It’s just not practical even with good intentions, for a single non-public code base. As a developer, I know it is hard to implement something once, harder to implement consistently across multiple interfaces, and damn near impossible to keep correct years later after employee turnover and other twists. The sad thing is that it costs a ton more money to do thi…
Facebook says new bug allowed apps access to private photos of up to 6.8M users
251–260 of 280 posts
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#252I never assume that “settings” guarantee what they claim. It’s just not practical even with good intentions, for a single non-public code base. As a developer, I know it is hard to implement something once, harder to implement consistently across multiple interfaces, and damn near impossible to keep correct years later after employee turnover and other twists. The sad thing is that it costs a ton more money to do thi…
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#253Earlier quoted context omitted.
Hi. I've worked in medical software repeatedly. I totally want to deal with HIPAA. It's a good idea for clients (the people who actually matter) and it's not nearly as difficult a prospect to work with as people say. The set of demands it makes upon you are small and reasonably constrained and are nearly all process-based rather than technical. Where it is technical, plenty of folks will sign a BAA for you to take bi…
>"But HIPAA" has never, in my experience, been employed except by people who find the idea of doing the right thing inconvenient or inconveniently expensive. (It is virtually never that hard and its benefits are clear.) Thank you for directly attacking my character without even addressing my actual argument. I'm not arguing against HIPAA, I'm arguing against such regulations in spaces that don't require that kind of…
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#254Earlier quoted context omitted.
Hi. I've worked in medical software repeatedly. I totally want to deal with HIPAA. It's a good idea for clients (the people who actually matter) and it's not nearly as difficult a prospect to work with as people say. The set of demands it makes upon you are small and reasonably constrained and are nearly all process-based rather than technical. Where it is technical, plenty of folks will sign a BAA for you to take bi…
>"But HIPAA" has never, in my experience, been employed except by people who find the idea of doing the right thing inconvenient or inconveniently expensive. (It is virtually never that hard and its benefits are clear.) Thank you for directly attacking my character without even addressing my actual argument. I'm not arguing against HIPAA, I'm arguing against such regulations in spaces that don't require that kind of…
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#255Earlier quoted context omitted.
Going to play the devil’s advocate. If you fine Facebook, you have to fine the small companies too, and even individual developers developing OSS, since the law should apply to everyone equally. Of course the fines have to be proportional to the number of affected users. So would you like a fine for your bugs? And note that contrary to other professions, software development doesn’t have generally agreed recipes for…
> If you fine Facebook, you have to fine the small companies too, and even individual developers developing OSS, since the law should apply to everyone equally. I would agree regarding small companies, but I wouldn't put oss developers in the same boat, fining the entity that provides a service makes more sense. It doesn't matter if that service relies on OSS or not. It's the company providing the service to the cons…
I agree with your post, but I tend to think of facebook's users as providing the product (their attention). If the consumer is a company buying advertising, then where's facebook's motivation to be careful with a user's "private" data?
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#256Where are the technical details on what the bug was and how it was possible? Shouldn't this be disclosed?
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#257Unrelated, but I'd love to know how that article managed to get a picture of that Facebook sign without people standing in front of it. I drive by it daily and I've never seen it without people posing in front of it :)
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#258Earlier quoted context omitted.
> If you fine Facebook, you have to fine the small companies too, and even individual developers developing OSS, since the law should apply to everyone equally. I would agree regarding small companies, but I wouldn't put oss developers in the same boat, fining the entity that provides a service makes more sense. It doesn't matter if that service relies on OSS or not. It's the company providing the service to the cons…
> It's the company providing the service to the consumer who is responsible to vet the final product. I agree with your post, but I tend to think of facebook's users as providing the product (their attention). If the consumer is a company buying advertising, then where's facebook's motivation to be careful with a user's "private" data?
Under GDPR, it actually doesn’t matter if you charge money for your product or not. If you process personal data, you’re responsible for it. This also applies to private people with no commercial interest who start to gather data from strangers (in exchange for some service or whatever).
Edit: The motivation should’ve been there from the beginning, if only for ethical reasons. Now the motivation is probably enforced by hefty fines.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#259Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#260Earlier quoted context omitted.
> It's the company providing the service to the consumer who is responsible to vet the final product. I agree with your post, but I tend to think of facebook's users as providing the product (their attention). If the consumer is a company buying advertising, then where's facebook's motivation to be careful with a user's "private" data?
Sorry, but you’re overthinking this. Facebooks product is not advertising. It’s a platform that brings users and advertisers together. Just because it’s free for some or most users of the platform doesn’t mean that only paying people (advertisers) need to be protected. Under GDPR, it actually doesn’t matter if you charge money for your product or not. If you process personal data, you’re responsible for it. This also…