Live data from Hacker News

Facebook says new bug allowed apps access to private photos of up to 6.8M users

washingtonpost.com

51–60 of 280 posts

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#51

Earlier quoted context omitted.

> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.

We criminalize other actions which result in harm to people. Why not software bugs too?

Well, there's two big differences... Planes have far fewer unknown unknowns than software: the specter bug in Intel chips is a great example of a place where the standard operating procedure was wrong, but no one ever knew it. It wasn't a case of negligence, though it had real world impact.

The other big difference is that (for the most part) keeping a passenger plane in the air isn't an adversarial task. Actual breaches are the result of active bad actors, which is completely different from the problems you encounter in designing a plane.

So criminal action seems crazy to me, though I can definitely see a great case for changing the incentives around storing user data. Could definitely see a good case for fines (and even an ongoing per-user tax, to make it an up front cost) for storing PII.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#52
post #21

Earlier quoted context omitted.

my response to this is always in the vein of, "how exactly should customers show they care?" "Well, leave!" isn't an option. They can't leave. Quitting Facebook when you're an active user means you lose a huge amount of social contact. I can think of a dozen people I know who are there because it's how they send baby pics and the like to family. They're non-technical and don't care about federated mastodons, they jus…

Most people I know are getting off of Facebook, or were never on it. The only people I know who are really still active are people using it to market themselves/their business, and are not there because they care about Facebook, but because they want to be findable there (and everywhere). I guess I'm old, but I find that email is great for sending baby pics to friends and family, and for planning things.

Well anecdotally in your small social group that may be true. But Facebook has 2.27 Billion active users...

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#53
post #29

“Private” photos that people uploaded to Facebook. Sounds like a good time to reiterate the advice: Don’t upload things to the internet that you don’t want to be on the internet. That way there won’t be any of your things on the internet that you didn’t want to be there.

Except that your friends, family, and others can upload private photos with you in them.

I left FB when they made reverted a policy that let you opt to confirm all tags before they showed up in searches for you.

This means anyone in the world can upload an image, tag you in it, and it will show up in searches for you. It still won’t show up on your profile if you have confirmations for that enabled, but still.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#54
post #32
post #21

Earlier quoted context omitted.

Most people I know are getting off of Facebook, or were never on it. The only people I know who are really still active are people using it to market themselves/their business, and are not there because they care about Facebook, but because they want to be findable there (and everywhere). I guess I'm old, but I find that email is great for sending baby pics to friends and family, and for planning things.

I had this problem recently, I wanted to get in contact with an old friend I hadn't seen in years. Because it had been so long I no longer had a current phone number or email address. At this stage we didn't even live in the same country as each other. Solving this problem, or problems like it, might go a long way to reducing the appeal of Facebook.

That's exactly why I joined Facebook in the first place...

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#55
post #33

Earlier quoted context omitted.

my response to this is always in the vein of, "how exactly should customers show they care?" "Well, leave!" isn't an option. They can't leave. Quitting Facebook when you're an active user means you lose a huge amount of social contact. I can think of a dozen people I know who are there because it's how they send baby pics and the like to family. They're non-technical and don't care about federated mastodons, they jus…

Leaving is of course an option. The fact that they don't leave mearly show that they value the gained social contact higher than the cost of data breaches.

that's my point, normal people value social interaction over an absolutist position of "well at least my data is secure!". normal people view never seeing their lil' cousin again as punishment, not the correct position to adopt bc it prevents being caught in a data breach

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#56
post #17

As usual, I'd like to point out how scummy this site really is. The paywall advertises a "Premium EU Ad-Free Subscription" which is more expensive than the standard subscription and explicitly states "No on-site advertising or third-party ad tracking" as one of the perks. Trying to buy it has the following: > By subscribing, you agree to the above terms, the Terms of Service, Digital Products Terms of Sale & Privacy…

<3

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#57

> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…

> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.

> Sounds like you're suggesting that we criminalize software bugs.

When there is irreparable damage I believe it should be criminalized. You cannot regain privacy after an incident such as this, it is irrevocably taken from you against your will.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#58

Earlier quoted context omitted.

If a plane crashed, and the company that manufactured the plane was fined because they had an engineering bug, no one would blink an eye.

The analogy doesn't work. Barring malicious intent or negligence leading to death I cannot imagine (or remember) a situation where the company would be fined for a software bug.

That is more of a failure of the imagination then. It's not like programming would cease to exist if fines were introduced.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#59

> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…

> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.

> Sounds like you're suggesting that we criminalize software bugs.

When my dad went to college, a very old and bitter professor (this was Civil Engineering, communist Eastern Europe) told the students on the first day in class something along the lines of: "If you know you're stupid or don't give a shit about your work, just go home and save everyone the trouble of dealing with your future fuckups. Mistakes here can cause deaths or losses of huge amounts of money".

I believe we've reached the point in which negligence in the software world can cause loss of lives, even when the software is not operating a crane or an airplane (think Grindr leaking account data over http in Saudi Arabia).

So you're minimizing the issue by asking if we should criminalize software bugs. We should and currently do criminalize negligence. If bugs are a result of negligence (you know, 'move fast and break things', 'better to ask for forgiveness than for permission') then fines, jailtime and criminal records should be a'coming. This is no longer child-play, this is the new world which runs on software.

Post reply on HN