Earlier quoted context omitted.
> Sounds like you're suggesting that we criminalize software bugs. When there is irreparable damage I believe it should be criminalized. You cannot regain privacy after an incident such as this, it is irrevocably taken from you against your will.
Suppose there is a bug in the Linux kernel. Some business runs their webservers on Linux. They have user email addresses (PII). Is Linus responsible for breaches? If so, then OSS dies. If not, then how do you intend to prove that their are no vulns in any of your dependencies for the rest of time?
Facebook says new bug allowed apps access to private photos of up to 6.8M users
271–280 of 280 posts
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#272Earlier quoted context omitted.
As one aside on this, the main issue people have with regulations is not regulations in and of themselves, but the negative effect they have on small businesses and competition/entrepreneurship more generally. I think you'd find extremely few genuine voices against regulations that only start to apply once a company (and all associated entities) grosses in excess of e.g. $100 million annual revenue. By that point com…
So basically regulation that impacts them directly or materially? The ideal of some arbitrary cut off point has been tried in lots of scenarios, and is gamed by all parties. Example: Copyright will protect new works for x years, at which point Disney lobbies for the arbitrary goal posts to be moved.
Keeping regulations focused on big players serves the dual purpose of focusing regulation where its affect will be most significant, while also ensuring it doesn't negatively affect the market. But yeah, like you're mentioning the big problem is that once companies reach a certain size they begin to develop the political connections necessary for them to simply kill, or at least castrate, any potential regulation that might genuinely require them to behave in a way that is inconvenient - even if it's better for society.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#273Earlier quoted context omitted.
As one aside on this, the main issue people have with regulations is not regulations in and of themselves, but the negative effect they have on small businesses and competition/entrepreneurship more generally. I think you'd find extremely few genuine voices against regulations that only start to apply once a company (and all associated entities) grosses in excess of e.g. $100 million annual revenue. By that point com…
Libertarian hackers always think of regulations as pesky pinpricks from the nanny state but in this case, in their domain of software, regulations would actually serve more of something along the lines of industry standards to ensure that software is created up to code. Hackers want good code, don't they?
Tax payer funded systems are one of the most controversial things we have. You'll find sharp disagreement on topics like e.g. public vs private funding for everything from education to medical and a wide array of other issues. Yet you'll find most of nobody that wants to privatize e.g. the fire department. This is because most of everybody would agree that the fire department does a good job, does it efficiently, and does it cheaply.
The point of this is that if there were a regulatory framework that was unambiguously and intrinsically superior to any alternative you'd find next to no opposition to it. Everybody wants the same thing in the end -- we just disagree on what's more likely to get you there. In many ways, I think lemonade stands are just a timeless and perfect example. In many states in the US today it is literally illegal, or at least unlawful, for a kid to go sell lemonade in their front yard. They can [and have] faced ticketing, confiscation, and so on. This is clearly idiotic by any standard, yet the very rules and regulations the produced this were all at some point created with good intentions. Perhaps ensuring food safety, or avoiding money laundering, or whatever other rule they happen to be breaking by selling a cup of lemonade for a quarter.
A rule that would generally stand to impose substantial penalties for writing bad code is something that would have unimaginably vast consequences at the lower level. And I think you're looking more at destroying small business in the tech industry than in suddenly having a world where all code is "good". By contrast the companies at the top can afford to greatly expand their staff and create factory lines of code review, extensive internal penetration testing, general audits, and so on. And perhaps most importantly, when they do end up violating the rule they have the resources to manage this just fine. And so it's very possible that the regulation could have an overall net positive effect there. But if it were applied to society as a whole (instead of just large companies), I think you'd be effectively killing off tech industry competition.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#274Earlier quoted context omitted.
> Does it ... kill people? Facebook asked users to upload nude photos. what if those get leaked and users commit suicide because of it? Would you (partially) blame facebook for their death? > Does it enforce bad policies like the healthcare industry did for the past couple of decades, causing an epidemic of obesity, diabetes and heart disease, which are the top causes of death? Genuine question but what policies are…
> " Would you (partially) blame facebook for their death? " No, because doing nude pictures of yourself and then distributing them, no matter where, is just stupid. Parents should educate their kids to know better, or seek counseling if that mistake was made. You're also talking of a hypothetical situation. When planes crash, people die, guaranteed. And yearly there are more than 100 plane crashes. > " Genuine questi…
Considering this article is about Facebook leaking 6+million photos to third parties, including photos that were uploaded but never shared, it's well within the realm of possibility that at least one of those millions of photos was a nude. In fact, I'd bet there were quite a few nudes in the leaked set. It only takes one more step to turn that hypothetical of yours into a reality.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#275Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#276Earlier quoted context omitted.
Canada recently passed a law that adds fines to data breach incidents iirc. A professor mentioned it and its why I'm researching auth on my winter break. Come to think of it, does anyone know of good auth resources for a mean stack that isn't a copy paste blog? I'm trying the udacity auth course as a starting point (uses oauth2)
I just spent som time going through this. The relevant rfc and drafts perhaps? https://tools.ietf.org/wg/oauth/ Also checkout OWASP https://www.owasp.org/ If your implementing openid connect, use a certified lib https://openid.net/developers/certified/
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#277Earlier quoted context omitted.
> It's the company providing the service to the consumer who is responsible to vet the final product. I agree with your post, but I tend to think of facebook's users as providing the product (their attention). If the consumer is a company buying advertising, then where's facebook's motivation to be careful with a user's "private" data?
Sorry, but you’re overthinking this. Facebooks product is not advertising. It’s a platform that brings users and advertisers together. Just because it’s free for some or most users of the platform doesn’t mean that only paying people (advertisers) need to be protected. Under GDPR, it actually doesn’t matter if you charge money for your product or not. If you process personal data, you’re responsible for it. This also…
The post I responded to, I think, made a very good point about responsibility being on service providers rather than OSS contributors.
However, the wording about "providing the service to the consumer" seems a bit problematic; it leaves the door open to discussions about who the consumer is, and thereby who is accountable. I'm glad you brought up GPDR - it seems to take the right approach, with regards to protecting personal data no matter who's holding it.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#278How come Google never has had a breach? Do they do a better job with security? Is Facebook more of a target than Google?
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#279Earlier quoted context omitted.
Are these lawyers you have talked to and gotten meaningful and nuanced advice from, or are they lawyers your bosses have talked to and derived maximally avoidant policies from? I'm not saying that you shouldn't have policies that fit your risk profile, but I ask because I have been in those former conversations (and I have done a nontrivial amount of auditing+compliance work in this space) and have never come away wi…
They are lawyers who personally do our training and put together testing material based on that training. To me that trumps a non-lawyer’s interpretation of a non-legal web site.
That they have a different company risk profile doesn't necessarily change the facts at hand. And, TBH, they don't have to tell you the truth if it helps achieve their immediate goals. (They can tell you you'd be personally and criminally liable. It might make you do what they want better. It might also not be true.) Or it may all be in good faith. But what you describe doesn't square with anything I've ever worked with, at multiple clients and employers.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#280Earlier quoted context omitted.
Fine everyone? Oh look, data breaches stop being reported. I guess we succeeded in reducing them?
Um yea, not the way it works. First external services, such as those provided by Krebs would find your data on the darknet. Second, offer employees a cut from the fines.