Live data from Hacker News

Facebook says new bug allowed apps access to private photos of up to 6.8M users

washingtonpost.com

261–270 of 280 posts

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#261
post #240

Earlier quoted context omitted.

I am suggesting that Facebook is free, fleeting software, and that people shouldn't put a huge host of stock in it. Even legally. Also - that it can be used for organizing bad behaviours is an entirely different subject that has little to do with quality or security.

If Facebook were free and its company had a completely hands-off approach with your data, much like a company that makes paper notepads never looks at what you write, I'd agree. But Facebook is a company that actively snoops and uses the data of its resources, the end-user. It's like a security guard who's paid to prevent shoplifting actively ignoring violent crimes because it's not related to stealing, or a baby foo…

I think you make a good point, at the same time, it's nary impossible to decide right from wrong on the internet, there are many sides to every story.

If the government wants to hire people to decide what counts as what - they should do that.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#262
post #260
post #258

Earlier quoted context omitted.

Sorry, but you’re overthinking this. Facebooks product is not advertising. It’s a platform that brings users and advertisers together. Just because it’s free for some or most users of the platform doesn’t mean that only paying people (advertisers) need to be protected. Under GDPR, it actually doesn’t matter if you charge money for your product or not. If you process personal data, you’re responsible for it. This also…

Answer this: If facebook's product is not advertising, then how do they make money?

Answer this: if Facebook was only a product for advertisers, whom would they show the ads?

Facebook‘s product is a platform. It can’t exist without users, and it can’t exist without advertisers (presumably).

Since both end users and advertisers are part of the product, the data of all of them needs to be protected. It doesn’t matter who the paying party is.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#263

Earlier quoted context omitted.

They did that because cost of maintaining platform was higher than its ROI. If Google+ had like 300M-400M monthly active users I don't think they would have shut down Google+

The ROI on Google+ has been negative since before it launched.

Investments tend to take a while to return-- this one didn't pay off though.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#264
post #208

Earlier quoted context omitted.

Really? How has " consumer software gone too far in the other direction "? Does it ... kill people? Does it enforce bad policies like the healthcare industry did for the past couple of decades, causing an epidemic of obesity, diabetes and heart disease, which are the top causes of death? Yeah, regulation there definitely helped /s

> Does it ... kill people? Facebook asked users to upload nude photos. what if those get leaked and users commit suicide because of it? Would you (partially) blame facebook for their death? > Does it enforce bad policies like the healthcare industry did for the past couple of decades, causing an epidemic of obesity, diabetes and heart disease, which are the top causes of death? Genuine question but what policies are…

They asked you to upload nude photos to help them identify revenge porn... so presumably this only makes sense for people whose nude photos are already online. Can’t really blame Facebook for that...

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#265
post #262
post #260

Earlier quoted context omitted.

Answer this: If facebook's product is not advertising, then how do they make money?

Answer this: if Facebook was only a product for advertisers, whom would they show the ads? Facebook‘s product is a platform. It can’t exist without users, and it can’t exist without advertisers (presumably). Since both end users and advertisers are part of the product, the data of all of them needs to be protected. It doesn’t matter who the paying party is.

If we fine Facebook.com for bugs, do we also fine Mastodon.social? Gitlab.com? Movim.SE? I have a test instance of hasura running on heroku so... if there are bugs in hasura, will you fine me?

If you say I can avoid penalities by saying my services are "as is", what stops Facebook from doing the same thing?

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#266
post #265
post #262

Earlier quoted context omitted.

Answer this: if Facebook was only a product for advertisers, whom would they show the ads? Facebook‘s product is a platform. It can’t exist without users, and it can’t exist without advertisers (presumably). Since both end users and advertisers are part of the product, the data of all of them needs to be protected. It doesn’t matter who the paying party is.

If we fine Facebook.com for bugs, do we also fine Mastodon.social? Gitlab.com? Movim.SE? I have a test instance of hasura running on heroku so... if there are bugs in hasura, will you fine me? If you say I can avoid penalities by saying my services are "as is", what stops Facebook from doing the same thing?

Where do you draw the line between bug, neglect and outright malpractice?

Obviously, it’s still not clear for many people: All services that process personal data became more regulated through GDPR.

And yes, if any service loses its customers data, there will be a fine. The fine depends on many factors. And yes, even Mastodon.social or Gitlab.com (the service, not the OSS). The advantage of these platforms is that they actually don’t process that much personal data.

Behind any service is a legal entity that asks people for their data, to provide a service. These legal entities are subject to the same laws.

However, since the GDPR apparently determines fines on a case-by-case basis, they might give a low or no fine at all, if the service is non-commercial and had no intention to collect user data for commercial purposes. But the law still applies.

If you put a web service online that handles personal data, you must make sure to keep that data safe. It doesn’t matter if your service is free or not.

Turn this around: just because you as a user signed up for a non-commercial free service like Mastodon.social (the service, not the OSS you can host yourself), you wouldn’t want the admins of Mastodon.social to mess around with your data, no?

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#267
post #70

Earlier quoted context omitted.

It's not unprecedented either. Under HIPAA, the Department of Health and Human Services has fined organizations millions of dollars for data breaches resulting from unpatched software and inadequate security practices.

And on that note, you see a lot less (though not zero) breaches of healthcare data and most HIPAA violations are due to analog errors rather than digital exposure. The government does a good job in this area forgiving innocuous violations, as long as all parties disclose it immediately and follow procedure.

Do we see less? Or are the serious ones never reported. Breaches of health data are not exactly trackable back to the source, assuming they're even abused at all.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#268

Earlier quoted context omitted.

Absolutely. Fine everyone into the ground. Doesn't look like there is any other way to make people take security seriously. I'm not a fan of the overregulation of industries like aviation, but consumer software has gone too far in the other direction and is long overdue for an adjustment.

The end result of this is that the number of software companies drops by 99.99%. Does your company run anything on Linux? Too bad, there are vulns in the kernel and now you are fined into the ground.

Let's assume you're not being dramatic. It would be a pretty lucrative market if 99.99% of current software companies went under. New businesses would show up with a much greater focus on security and quality. That's a bad thing?

The realm problem is the inevitable regulatory capture that occurs in every market with even an ounce of complexity.

Given the number of high profile breaches we see every month, I definitely think we're due for some consequences.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#269

> The bug also impacted photos that people uploaded to Facebook but chose not to post. What about, for example, pictures sent in a private message? I'm so very glad I deleted my account months ago.

>I'm so very glad I deleted my account months ago.

I did as well. One thing that stood out to me in the article was that users who were impacted by the breach would be notified via a Facebook message. What about people who were impacted by the breach who no longer have an account?

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#270
post #227

Earlier quoted context omitted.

Absolutely. Fine everyone into the ground. Doesn't look like there is any other way to make people take security seriously. I'm not a fan of the overregulation of industries like aviation, but consumer software has gone too far in the other direction and is long overdue for an adjustment.

Fine everyone? Oh look, data breaches stop being reported. I guess we succeeded in reducing them?

Um yea, not the way it works. First external services, such as those provided by Krebs would find your data on the darknet. Second, offer employees a cut from the fines.
Post reply on HN