Earlier quoted context omitted.
I very very much doubt the NYT would have agreed to an embargo on a story like this. It's a major news story, not the launch of a new car.
Since you're just getting downvoted, I may as well say that as a member of the press it isn't uncommon to see embargoes on stuff like this. They don't say a week out "hey we've got a huge security announcement" but they do say "we have something coming out this afternoon and we're doing a briefing half an hour before if you agree not to publish before we go public." It's often in the interest of the reporter to agree…
Facebook Network Breach Impacts Up to 50M Users
551–560 of 635 posts
Re: Facebook Network Breach Impacts Up to 50M Users
#552Earlier quoted context omitted.
If you're more interested in tech discussion or maybe some subcultures, and less interested in food photos/anecdotes about babies, just join http://mastodon.social/ already. Set your preferences to show posts of your native language only, start poking around the timelines, and follow people who post something interesting. Follow, boost, reply, it only takes a few days before you have plenty of interesting content in…
> Probably less chance you get caught up in any kind of breach -- it's too obscure to be a target, plus the code is open source so many eyes on it, etc. Security through obscurity... Open source != secure. I can guarantee that a hell of a lot more folks with a lot of security expertise have combed through the fb codebase than Mastodon.
Re: Facebook Network Breach Impacts Up to 50M Users
#553Excerpts from the press call transcript [1] by Guy Rosen explaining what lead to this breach being possible: > The first bug was that, when using the View As function to look at your profile as another person would, the video uploader shouldn’t have actually shown up at all. But in a very specific case, on certain types of posts that are encouraging people to post happy birthday greetings, it did show up. > The secon…
Just as Microsoft developed Patch Tuesday, Facebook should have Forced Logoff Friday
Re: Facebook Network Breach Impacts Up to 50M Users
#554Re: Facebook Network Breach Impacts Up to 50M Users
#555So here is a question: my girlfriend only uses FB on her laptop, and always logs out when she's done. I usually make fun of her for doing this. But does this mean most of the time that there was no active access token and she is mostly safe? (Excluding the windows of time where she was actively using FB) Do I have to take back all of my teasing?
Re: Facebook Network Breach Impacts Up to 50M Users
#556From Facebook's announcement: "After they have logged back in, people will get a notification at the top of their News Feed explaining what happened." I personally did not get any explanation as to why I had to log back in. It did surprise me to be logged out this morning and was wondering why.
Logged out of and back into what? Your mobile app? Your web browser tab that is left open indefinitely? I no longer use FB, so just curious. I know people that never log out of FB, and have closed their browser window/tab thinking that was good enough even though the "remember me" type option was checked. Opening a new window/tab to FB would show their account just like nothing happened because they did not log out.…
Re: Facebook Network Breach Impacts Up to 50M Users
#557Earlier quoted context omitted.
Random question - is there a way to naturalize in the EU and use GDPR to ask Facebook to remove your data? (For example an Estonian digital citizenship) I might be way way off and I am (obviously) not a lawyer but interested in material about this.
I believe it only applies if you are physically in Europe
Re: Facebook Network Breach Impacts Up to 50M Users
#558Re: Facebook Network Breach Impacts Up to 50M Users
#559Said this yesterday in the other Facebook thread, and I'll say it again. Working for Facebook is a morally bankrupt position. If you are an engineer you have plenty of job opportunities available to you and there is no excuse for you to continue contributing your labor and time to a wholly malignant organization. At a certain point one has to ask how we as an industry will start dealing with those who continue to tak…
I would love to know where you work that is so morally upstanding and globally beneficial. More than likely you’re just a hypocrite.
But, I do know that working for companies that are funded by advertising makes me feel uneasy. I know because I've worked at one or two. I also know that the company I currently work for charges our customers for the services provided, and I know there's a consensual quid pro quo in every customer agreement. I also know we don't track our customers beyond their consent. I would hope if my company ever started doing that I'd speak up, and if things didn't change I would hope to have the fortitude to leave and continue to speak up outside of the company.
I also have no doubt that my day to day work is automating away someone's job, somewhere. Where someone used to make a good living, my code will run instead. People might not get overtly laid off because of my code, but there's no doubt people who use my company's services hire less people... it's kind of the point. I definitely think about the moral implications of that. Sometimes I'm not super comfortable with the hypothetical effects of my code over a long time period. Even if I contribute less than 1% to my company's service, if my company's service saves our customers on average the equivalent of one salary a year I've been responsible for the, at best, lack of creation of hundreds of jobs. In a different world someone fed a family, bought a house, and lived a life with one of those salaries, and now that opportunity is forever gone. Sometimes that's a hard thing to grapple with, and I really hope that I'm not contributing to negative economic trends that hurt a large majority of the world's populace while enriching myself. Chances are I probably am, though.
However I am certain of a couple things. The mass collection of billions of people's information is putting upon yourself an incredible responsibility that I find hard to justify. This wasn't by accident, this wasn't dumb luck, this was a purposeful attempt to amass and control power. This power isn't inherently good or evil itself, but even in a vacuum one has a right to be suspicious of such power. Fortunately we don't live in a vacuum and over time Facebook has shown itself to not be a good steward of the power it's created. I have no doubt there are plenty of ethical people that work at Facebook, and there are definitely plenty of ethical, smart people who work in Facebook infosec. I don't blame them for the data breach. I blame the creator of this Pandora's box, I blame those who willingly continue the abuse of this power, I blame those who purposefully profit off the abuse of this power, and I blame those who refuse to realize that they will not change an organization that refuses to change. Until the use of Facebook's data is no longer rewarded with massive amounts of money Facebook will continue to collect and sell this data. The incentives are very clearly aligned. Working there, no matter your intentions, cannot change these incentives. I'm not saying everyone at Facebook is evil, but if the hiring reputation is true they are too smart to not understand these things for much longer. Facebook will continue to be morally bankrupt until its power is abolished or democratized, and since a Pandora's box cannot be closed I'll settle for democratized.
Re: Facebook Network Breach Impacts Up to 50M Users
#560Earlier quoted context omitted.
> The second bug was that this video uploader incorrectly used the single signon functionally, and it generated an access token that had the permissions of the Facebook mobile app. And that’s not the way the single sign-on functionality is intended to be used. Is it just me or does this sound like an terrible idea in the first place? Guess we can't know for sure, but why would anything unrelated to authentication gen…
Technical debt, multiple systems using multiple old authentication routines getting slowly upgraded to new auth methods. And no one taking the time to fully understand the ramifications. And honestly it seems like that was the right choice for the teams responsible. They all made tons of money delivered features and now years later a bug is found.