Earlier quoted context omitted.
> Can we not let this become framed as a "breach"? No > systems were compromised. Nothing of Facebook's was > accessed that wasn't supposed to be accessed. This was > data intentionally exposed by Facebook, just exfiltrated > and given to an entity whom Facebook hadn't authorized. This is similar to a HIPAA "breach" where the word doesn't imply that a security system was compromised, but that protected data was acces…
Listening to politicos, you'd think the systems were actually compromised, and, in the same breath, boogeypeople from Russia are mentioned in order to conflate things in the mind of the audience. This willful conflation is a tactic to drive a narrative. HIPAA data is accessed by researchers, sometimes anonymized, but not in all cases. These are not considered breaches. In addition, as others indicate, FB posts are no…
We're seeing a divide between the technical and popular interpretations of the term "breach". When an industry drops the ball and responds pedantically, that's a strong sign that further regulation is needed. If only to force a common language.
Facebook insists they were not "breached" because many states require notification in the event of "security breaches of information involving personally identifiable information" [1]. Each body of law defines "breach" differently. Most do not limit it to technical security malfunctions.
[1] http://www.ncsl.org/research/telecommunications-and-informat...