Live data from Hacker News

Facebook says new bug allowed apps access to private photos of up to 6.8M users

washingtonpost.com

41–50 of 280 posts

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#41

Earlier quoted context omitted.

Not the op, but meaningful fines, executive jail time for gross negligence and especially for intentionally taking inappropriate risks, breaking up or closing companies that are shown over time to be unable to safely handle sensitive information. Proper regulation. Consequences that can't be cynically taken as the cost of doing business.

Jail time for bugs? Have people here every worked on products? Bugs and security vulns are literally inevitable. Security is important but it this was the standard I'm not sure that any company would still exist.

But why do financial services bugs garner a higher penalty than one that exposes private photos? This is an argument for regulation.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#42

Earlier quoted context omitted.

Not the op, but meaningful fines, executive jail time for gross negligence and especially for intentionally taking inappropriate risks, breaking up or closing companies that are shown over time to be unable to safely handle sensitive information. Proper regulation. Consequences that can't be cynically taken as the cost of doing business.

Jail time for bugs? Have people here every worked on products? Bugs and security vulns are literally inevitable. Security is important but it this was the standard I'm not sure that any company would still exist.

Nobody said jail time for bugs, and phrasing that way is intentionally obscuring the debate. Gross negligence is an entirely different standard than just software bugs.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#43
post #11

Earlier quoted context omitted.

No. Unless they didn't report it to the regulators.

Article 34 clearly states that the breached organization must inform the data subject "without undue delay". Given that the event occurred in September, and it is now December, I would characterize that as an undue delay. There should be GDPR consequences of this - it's time that law got properly put to the test.

I'd imagine what matters is the delay from when you learn about the issue, not the delay from when it happened. This blog post looks a lot more like something they discovered now than something they discovered in September. (E.g. the way they'll have "tools for figuring out who was affected next week").

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#44

Earlier quoted context omitted.

> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.

If a plane crashed, and the company that manufactured the plane was fined because they had an engineering bug, no one would blink an eye.

The analogy doesn't work. Barring malicious intent or negligence leading to death I cannot imagine (or remember) a situation where the company would be fined for a software bug.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#45

Earlier quoted context omitted.

> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.

If a plane crashed, and the company that manufactured the plane was fined because they had an engineering bug, no one would blink an eye.

This is more akin to the manufactoring company finding a defect that may or may not have contributed to a crash. Facebook hasn't said anything about if this bug was actually exploited

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#46

> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…

> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.

Yes, I am suggesting that. I don't necessarily think jail time is the right thing, but I do think something like meaningful fines are more than reasonable for major software bugs that cause these kinds of breaches of privacy. It will make larger companies like this be much more careful when money is on the table for them to lose.

To me, if we can criminalize something like a major oil spill such as BP/Deepwater Horizon, how is this much different? It's not like they did the oil spill on purpose, but they still need had consequences for those risks that they were taking. Software companies, esp larger ones like Facebook, should have the same kind of consequences for their risks of software bugs that cause these kinds of privacy breaches.

Also, as someone else below pointed out to someone else with a similar tone as your phrasing of "criminalize software bugs": "intentionally obscuring the debate. Gross negligence is an entirely different standard than just software bugs."

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#47

Earlier quoted context omitted.

Not the op, but meaningful fines, executive jail time for gross negligence and especially for intentionally taking inappropriate risks, breaking up or closing companies that are shown over time to be unable to safely handle sensitive information. Proper regulation. Consequences that can't be cynically taken as the cost of doing business.

Jail time for bugs? Have people here every worked on products? Bugs and security vulns are literally inevitable. Security is important but it this was the standard I'm not sure that any company would still exist.

Jail time for bugs that should have been preventible and caused harm to users. Mistakes and bugs happen, but we also have methods of mitigating them. Standards, quality controls, tests, analysis, and other care. I specifically said jail time for gross negligence because that means not taking care and allowing harm to users.

If you had an error that leaked private information, it's worth an investigation. If it made it through despite controls, that's understandable. If they find you failed to do analysis on the risk to users privacy, if you failed to have controls in place, if you didn't code review or test the code, then you have made specific choices that harmed users. That should be criminal.

We need to take software engineering seriously as a discipline. We have the potential to do more wide scale aggregate harm than any structural engineering collapse. We need to start acting like it.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#50

> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…

The punishment should be mass loss of users due to loss of trust, but for some reason people still use it.
Post reply on HN