Earlier quoted context omitted.
Not the op, but meaningful fines, executive jail time for gross negligence and especially for intentionally taking inappropriate risks, breaking up or closing companies that are shown over time to be unable to safely handle sensitive information. Proper regulation. Consequences that can't be cynically taken as the cost of doing business.
Jail time for bugs? Have people here every worked on products? Bugs and security vulns are literally inevitable. Security is important but it this was the standard I'm not sure that any company would still exist.
Facebook says new bug allowed apps access to private photos of up to 6.8M users
41–50 of 280 posts
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#42Earlier quoted context omitted.
Not the op, but meaningful fines, executive jail time for gross negligence and especially for intentionally taking inappropriate risks, breaking up or closing companies that are shown over time to be unable to safely handle sensitive information. Proper regulation. Consequences that can't be cynically taken as the cost of doing business.
Jail time for bugs? Have people here every worked on products? Bugs and security vulns are literally inevitable. Security is important but it this was the standard I'm not sure that any company would still exist.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#43Earlier quoted context omitted.
No. Unless they didn't report it to the regulators.
Article 34 clearly states that the breached organization must inform the data subject "without undue delay". Given that the event occurred in September, and it is now December, I would characterize that as an undue delay. There should be GDPR consequences of this - it's time that law got properly put to the test.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#44Earlier quoted context omitted.
> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.
If a plane crashed, and the company that manufactured the plane was fined because they had an engineering bug, no one would blink an eye.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#45Earlier quoted context omitted.
> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.
If a plane crashed, and the company that manufactured the plane was fined because they had an engineering bug, no one would blink an eye.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#46> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…
> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.
To me, if we can criminalize something like a major oil spill such as BP/Deepwater Horizon, how is this much different? It's not like they did the oil spill on purpose, but they still need had consequences for those risks that they were taking. Software companies, esp larger ones like Facebook, should have the same kind of consequences for their risks of software bugs that cause these kinds of privacy breaches.
Also, as someone else below pointed out to someone else with a similar tone as your phrasing of "criminalize software bugs": "intentionally obscuring the debate. Gross negligence is an entirely different standard than just software bugs."
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#47Earlier quoted context omitted.
Not the op, but meaningful fines, executive jail time for gross negligence and especially for intentionally taking inappropriate risks, breaking up or closing companies that are shown over time to be unable to safely handle sensitive information. Proper regulation. Consequences that can't be cynically taken as the cost of doing business.
Jail time for bugs? Have people here every worked on products? Bugs and security vulns are literally inevitable. Security is important but it this was the standard I'm not sure that any company would still exist.
If you had an error that leaked private information, it's worth an investigation. If it made it through despite controls, that's understandable. If they find you failed to do analysis on the risk to users privacy, if you failed to have controls in place, if you didn't code review or test the code, then you have made specific choices that harmed users. That should be criminal.
We need to take software engineering seriously as a discipline. We have the potential to do more wide scale aggregate harm than any structural engineering collapse. We need to start acting like it.
Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#48Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#49Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users
#50> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…