Earlier quoted context omitted.
> If customers do not care enough to stop using the product then there is no harm If you quit using FB and were still leaked, now what? If you were leaked because they hold a shadow account?
Good point! What do you think we should do about this problem? Ban companies from holding onto data when they are deactivated? How would we enforce that? The problem is even worse: if your friend shares their contact list and that is the data that gets leaked, what then? I think that brings to question the entire idea of a phone number belonging to one person. A friend can give consent to share your information. Mayb…
Facebook does not plan to notify half-billion users affected by data leak
291–300 of 315 posts
Re: Facebook does not plan to notify half-billion users affected by data leak
#292For years companies have been steadily asking, mandating or even trickling users to give them their phone numbers under the excuse of security (while the real reasons were different), now what? How can they be trusted anymore? This also strikes a great point about the data sharing between Facebook and WhatsApp. Linking data between services augments the dangers and the consequences are not obvious to the end user. I…
Google does the same, they've even published a paper showing just adding an email address is enough to eliminate 90+% of phishing attempts.
Re: Facebook does not plan to notify half-billion users affected by data leak
#293I’ve said it before and I’ll say it again, unless and until, companies like Facebook are fined appropriate amounts they’ll never stop. Quite literally, every business school on the fucking planet will tell you do something if it’s cheaper. It is cheaper for them to not give a fuck, than to give one. Unless they are fined upwards of $20-50bn it’ll never stop because it’s always going to benefit their bottom line. Full…
But Governments rarely have a fine based on the entity's revenue, let alone calculating fine based on the impact of the negligence like this. I guess FB has decided even if GDPR fine is triggered, paying that is better than reminding half-billion users that using their platform is dangerous.
I've witnessed while literally getting sick due to the compliance burden when running the company as a single person i.e. in make sure I don't fall behind any of them; Large companies calculating the expenditure to 'fix the fine' if raised by the Govt. after several years and deciding NTGAF as the fine/fix is 'negligible' for them.
Re: Facebook does not plan to notify half-billion users affected by data leak
#294Earlier quoted context omitted.
Never trust caller ID or senderid on phone calls or SMS. The reason is that phone companies interoperate grudgingly and do the minimum required to pass calls and messages between each other, and also most phone companies are 100+ year old companies who have just layered modern tech on top of their old stuff. They handle a massive unending stream of calls/messages and they can't possibly validate each one (even if the…
>they can't possibly validate each one // Why not? They don't pass on all metadata, that's part of the problem. If a call originates in $foreign_country, the sender gets to spoof it as a local call (sometimes they even use your own phone number). Are you really telling me there's no way to tell the difference between an off-shore call and a local one. It seems if this were true that billing is impossible, yet somehow…
I'll give you one simple example of the magnitude of this. In Ontario & Quebec, Canada, in the 1920s, there were almost 800 local phone companies operating, and "The Bell Telephone Company of Canada" was the long-distance provider that connected all those companies together. Even back then they handled almost 3M long distance calls per day (from roughly ~500,000 phones).
Over time, Bell bought up all those local independent companies and merged their records, customers, infrastructure, operations, etc..
That's Ontario and Quebec only, 2 provinces out of 10.
Fast forward like 60 years and in Canada local/regional phone companies in various parts of the country were still a thing in the early 1980s, and even now we still have distinct phone companies for some of our provinces.
And this is just one country that has less than 40M people. Now repeat this process in the US, and other parts of the world, going back almost a century, and you can start to understand the complexity we're dealing with here.
The insanity of these merged and glued-together tech stacks would make most people faint.
Obviously they're not all still running on super old tech, but if you look at any major incumbent telco's DCs you will commonly find switching systems from as far back as the 1960s that have been wrapped in layer after layer of "modernization" but are still there routing calls and running old code.
I know you believe what you are saying is "simple enough", and it probably should be, but sadly it's not.
And while you're right to say it's a cost thing, it is also a technical problem in that it would require massive coordination both internally within telcos but also between companies that are competitors to each other, and aren't naturally inclined to work together in the first place.
Re: Facebook does not plan to notify half-billion users affected by data leak
#295The "real names" myth was the biggest scam played against people in the past 15 years. The media are also wholesale responsible for perpetuating that damaging trend. Historians of the future will look at the past 2 decades with disbelief.
Scam? That assumes deliberately misleading people for the scammer to benefit. Who exactly is benefiting from this? While I don't agree that it's obvious even now that that using real names is damaging (i.e. makes things worse than anonymity/pseudonymity) the assumption that it's a scam goes 100% against Hanlon's razor. It's pretty easy to claim that using real names online does more harm than good when pointing at a…
Re: Facebook does not plan to notify half-billion users affected by data leak
#296Earlier quoted context omitted.
Never trust caller ID or senderid on phone calls or SMS. The reason is that phone companies interoperate grudgingly and do the minimum required to pass calls and messages between each other, and also most phone companies are 100+ year old companies who have just layered modern tech on top of their old stuff. They handle a massive unending stream of calls/messages and they can't possibly validate each one (even if the…
We have STIR/SHAKEN but the phone companies are dragging their feet on implementing it.
I'm curious to see if it rolls out as smoothly as we hope.
Re: Facebook does not plan to notify half-billion users affected by data leak
#297Earlier quoted context omitted.
Perhaps the fine amount should be a function of market cap for public companies.
The fine should be proportional to the damage. A tiny medical startup that leaks psychotherapy records “hurts” more than a company that leaks your shoe size. Perhaps companies should buy insurance for this and then that would incentivize insurance companies to help protect their clients. Insurance requirements are a significant safety factor at many physical businesses. The law is important, but being denied insuranc…
They literally do, and I think it lightens the blow more than anything.
Re: Facebook does not plan to notify half-billion users affected by data leak
#298My twitter account got flagged as suspicious even though I haven't used it during the past few months and have a long random password. Now they want my mobile number to "verify" me in addition to a captcha. It is ridiculous and ovcoiolsly tech companies can't be trusted with personal data of that caliber. I have never used my real name with that twitter account and now they want to know it all, why? Greed is my guess…
Nope. Account disbanded.
Re: Facebook does not plan to notify half-billion users affected by data leak
#299Earlier quoted context omitted.
> This huge leak has definitely killed the > SMS text messaging service. So with this breach, one now must use WhatsApp for messaging contacts? That is rather convenient for Facebook. As someone who has much friction already convincing people to use SMS with me instead of the WhatsApp account that I've never had (nor a Facebook account), making SMS even more problematic is great for Facebook. Many people assume bad i…
The reason that Whatsapp massively took off in certain parts of the world, and to an extent even replaced the public-telephone system (e.g. restaurants and other local businesses may even want to be contacted by Whatsapp, not phone), is because SMS is expensive, but data is not. Sure, you might be in a part of the world where SMS is a viable option, but for many people it no longer is, and instead of asking for SMS y…
Re: Facebook does not plan to notify half-billion users affected by data leak
#300Earlier quoted context omitted.
I have a strong suspicion that, if a government tried to fine a company in billions, that company would simply leave the country forever. I'm not saying that this is a good thing or a bad thing. It's just an intuition that I have.
To make a rubbish analogy, this is like arguing that making it illegal for teachers to do murders would make all the murderous teachers move. Great? We'll be left with the non murderous ones. I don't think there's much that would wholesale get Facebook to withdraw from a huge market like the US but if they did then competitors that did obey the new laws would take their place, as long as the entire business model was…