Live data from Hacker News

Facebook says new bug allowed apps access to private photos of up to 6.8M users

washingtonpost.com

271–280 of 280 posts

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#271
post #57

Earlier quoted context omitted.

> Sounds like you're suggesting that we criminalize software bugs. When there is irreparable damage I believe it should be criminalized. You cannot regain privacy after an incident such as this, it is irrevocably taken from you against your will.

Suppose there is a bug in the Linux kernel. Some business runs their webservers on Linux. They have user email addresses (PII). Is Linus responsible for breaches? If so, then OSS dies. If not, then how do you intend to prove that their are no vulns in any of your dependencies for the rest of time?

The person storing the data is the one responsible for securing the data. Everyone keeps trying to push data security up the stack, but the company/ individual collecting it is the responsible party.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#272

Earlier quoted context omitted.

As one aside on this, the main issue people have with regulations is not regulations in and of themselves, but the negative effect they have on small businesses and competition/entrepreneurship more generally. I think you'd find extremely few genuine voices against regulations that only start to apply once a company (and all associated entities) grosses in excess of e.g. $100 million annual revenue. By that point com…

So basically regulation that impacts them directly or materially? The ideal of some arbitrary cut off point has been tried in lots of scenarios, and is gamed by all parties. Example: Copyright will protect new works for x years, at which point Disney lobbies for the arbitrary goal posts to be moved.

Exactly. Large companies love regulations when they affect everybody since they can easily abide the regulations while they help to destroy potential competitors.

Keeping regulations focused on big players serves the dual purpose of focusing regulation where its affect will be most significant, while also ensuring it doesn't negatively affect the market. But yeah, like you're mentioning the big problem is that once companies reach a certain size they begin to develop the political connections necessary for them to simply kill, or at least castrate, any potential regulation that might genuinely require them to behave in a way that is inconvenient - even if it's better for society.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#273

Earlier quoted context omitted.

As one aside on this, the main issue people have with regulations is not regulations in and of themselves, but the negative effect they have on small businesses and competition/entrepreneurship more generally. I think you'd find extremely few genuine voices against regulations that only start to apply once a company (and all associated entities) grosses in excess of e.g. $100 million annual revenue. By that point com…

Libertarian hackers always think of regulations as pesky pinpricks from the nanny state but in this case, in their domain of software, regulations would actually serve more of something along the lines of industry standards to ensure that software is created up to code. Hackers want good code, don't they?

I don't understand why people have to otherize each other. No, again opposition to regulations has nothing to do with some ambiguous opposition to nanny stating in and of itself. That is tangential to the real issue. Before getting to that, let's take a really quick digression.

Tax payer funded systems are one of the most controversial things we have. You'll find sharp disagreement on topics like e.g. public vs private funding for everything from education to medical and a wide array of other issues. Yet you'll find most of nobody that wants to privatize e.g. the fire department. This is because most of everybody would agree that the fire department does a good job, does it efficiently, and does it cheaply.

The point of this is that if there were a regulatory framework that was unambiguously and intrinsically superior to any alternative you'd find next to no opposition to it. Everybody wants the same thing in the end -- we just disagree on what's more likely to get you there. In many ways, I think lemonade stands are just a timeless and perfect example. In many states in the US today it is literally illegal, or at least unlawful, for a kid to go sell lemonade in their front yard. They can [and have] faced ticketing, confiscation, and so on. This is clearly idiotic by any standard, yet the very rules and regulations the produced this were all at some point created with good intentions. Perhaps ensuring food safety, or avoiding money laundering, or whatever other rule they happen to be breaking by selling a cup of lemonade for a quarter.

A rule that would generally stand to impose substantial penalties for writing bad code is something that would have unimaginably vast consequences at the lower level. And I think you're looking more at destroying small business in the tech industry than in suddenly having a world where all code is "good". By contrast the companies at the top can afford to greatly expand their staff and create factory lines of code review, extensive internal penetration testing, general audits, and so on. And perhaps most importantly, when they do end up violating the rule they have the resources to manage this just fine. And so it's very possible that the regulation could have an overall net positive effect there. But if it were applied to society as a whole (instead of just large companies), I think you'd be effectively killing off tech industry competition.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#274
post #208

Earlier quoted context omitted.

> Does it ... kill people? Facebook asked users to upload nude photos. what if those get leaked and users commit suicide because of it? Would you (partially) blame facebook for their death? > Does it enforce bad policies like the healthcare industry did for the past couple of decades, causing an epidemic of obesity, diabetes and heart disease, which are the top causes of death? Genuine question but what policies are…

> " Would you (partially) blame facebook for their death? " No, because doing nude pictures of yourself and then distributing them, no matter where, is just stupid. Parents should educate their kids to know better, or seek counseling if that mistake was made. You're also talking of a hypothetical situation. When planes crash, people die, guaranteed. And yearly there are more than 100 plane crashes. > " Genuine questi…

> You're also talking of a hypothetical situation

Considering this article is about Facebook leaking 6+million photos to third parties, including photos that were uploaded but never shared, it's well within the realm of possibility that at least one of those millions of photos was a nude. In fact, I'd bet there were quite a few nudes in the leaked set. It only takes one more step to turn that hypothetical of yours into a reality.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#276

Earlier quoted context omitted.

Canada recently passed a law that adds fines to data breach incidents iirc. A professor mentioned it and its why I'm researching auth on my winter break. Come to think of it, does anyone know of good auth resources for a mean stack that isn't a copy paste blog? I'm trying the udacity auth course as a starting point (uses oauth2)

I just spent som time going through this. The relevant rfc and drafts perhaps? https://tools.ietf.org/wg/oauth/ Also checkout OWASP https://www.owasp.org/ If your implementing openid connect, use a certified lib https://openid.net/developers/certified/

Thanks (to both replies)

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#277
post #258

Earlier quoted context omitted.

> It's the company providing the service to the consumer who is responsible to vet the final product. I agree with your post, but I tend to think of facebook's users as providing the product (their attention). If the consumer is a company buying advertising, then where's facebook's motivation to be careful with a user's "private" data?

Sorry, but you’re overthinking this. Facebooks product is not advertising. It’s a platform that brings users and advertisers together. Just because it’s free for some or most users of the platform doesn’t mean that only paying people (advertisers) need to be protected. Under GDPR, it actually doesn’t matter if you charge money for your product or not. If you process personal data, you’re responsible for it. This also…

Overthinking or not, it seems like you're agreeing with what I was getting at...

The post I responded to, I think, made a very good point about responsibility being on service providers rather than OSS contributors.

However, the wording about "providing the service to the consumer" seems a bit problematic; it leaves the door open to discussions about who the consumer is, and thereby who is accountable. I'm glad you brought up GPDR - it seems to take the right approach, with regards to protecting personal data no matter who's holding it.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#278

How come Google never has had a breach? Do they do a better job with security? Is Facebook more of a target than Google?

Probably the latter: the larger the value of a network, the more likely it is to attract attackers.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#279

Earlier quoted context omitted.

Are these lawyers you have talked to and gotten meaningful and nuanced advice from, or are they lawyers your bosses have talked to and derived maximally avoidant policies from? I'm not saying that you shouldn't have policies that fit your risk profile, but I ask because I have been in those former conversations (and I have done a nontrivial amount of auditing+compliance work in this space) and have never come away wi…

They are lawyers who personally do our training and put together testing material based on that training. To me that trumps a non-lawyer’s interpretation of a non-legal web site.

If you read the sibling comment where Spooky23 cites the HHS page on HIPAA, it might be worth ruminating on that versus your interpretation of why your company's lawyers lay out the training in the way that they do.

That they have a different company risk profile doesn't necessarily change the facts at hand. And, TBH, they don't have to tell you the truth if it helps achieve their immediate goals. (They can tell you you'd be personally and criminally liable. It might make you do what they want better. It might also not be true.) Or it may all be in good faith. But what you describe doesn't square with anything I've ever worked with, at multiple clients and employers.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#280
post #270
post #227

Earlier quoted context omitted.

Fine everyone? Oh look, data breaches stop being reported. I guess we succeeded in reducing them?

Um yea, not the way it works. First external services, such as those provided by Krebs would find your data on the darknet. Second, offer employees a cut from the fines.

Pay employees when their company is fined for security breaches? Damn, good thing I'm a software developer.
Post reply on HN