Live data from Hacker News

Facebook says new bug allowed apps access to private photos of up to 6.8M users

washingtonpost.com

61–70 of 280 posts

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#61

Earlier quoted context omitted.

If a plane crashed, and the company that manufactured the plane was fined because they had an engineering bug, no one would blink an eye.

The analogy doesn't work. Barring malicious intent or negligence leading to death I cannot imagine (or remember) a situation where the company would be fined for a software bug.

>or negligence

Right. Companies like FB are entrusted with the private information of hundreds of millions of people. There should be investigations as there would be in a plane crash. If negligence is found, there should be appropriate punishment doled out.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#62

> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…

Comparing Facebook to murder is dramatic and childish.

This Facebook hysteria is tiring.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#63

Earlier quoted context omitted.

Until consumers reveal that they care this is how it will be unless governments regulate/punish.

my response to this is always in the vein of, "how exactly should customers show they care?" "Well, leave!" isn't an option. They can't leave. Quitting Facebook when you're an active user means you lose a huge amount of social contact. I can think of a dozen people I know who are there because it's how they send baby pics and the like to family. They're non-technical and don't care about federated mastodons, they jus…

Let's make the next mandated change to Facebook's operations a red bordered, 90% screen coverage dialog, modal:

"We are required to notify you that we have leaked information from your account, please be advised that we have no idea who has your profile information, pictures, post history or any other information contained in your posts. Please consider resetiing your entire online persona to avoid financial and/or social consequences."

With two buttons: "Erase me from Facebook" or "I get it, I don't care."

Just planting seeds, Bill Hicks style...

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#64

> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start act…

> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.

Hammurabi's code (~1700 BC) includes this about building:

Building Code

229. If a builder builds a house for a man and does not make its construction sound, and the house which he has built collapses and causes the death of the owner of the house, the builder shall be put to death.

233. If a builder builds a house for a man and does not make its construction sound, and a wall cracks, that builder shall strengthen that wall at his own expense.

Bugs in houses have been criminalized for a very long time. Online data may be less fundamental than safe housing, but housing our data safely becomes proportionally more important as more of modern life depends on it.

[0] http://www.wright.edu/~christopher.oldstone-moore/Hamm.htm

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#66

“Private” photos that people uploaded to Facebook. Sounds like a good time to reiterate the advice: Don’t upload things to the internet that you don’t want to be on the internet. That way there won’t be any of your things on the internet that you didn’t want to be there.

> including images that people began uploading to the site but didn’t post publicly.

This means that if you started to upload a photo to the uploader wizard and then thought better, the photo is still out there.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#67

Earlier quoted context omitted.

> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.

If a plane crashed, and the company that manufactured the plane was fined because they had an engineering bug, no one would blink an eye.

Yes, there is a qualitative difference between a plane crashing and people dying and 69 million photos being leaked. If you have trouble understanding the difference you should probably see a therapist.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#69

Earlier quoted context omitted.

> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.

Yes, I am suggesting that. I don't necessarily think jail time is the right thing, but I do think something like meaningful fines are more than reasonable for major software bugs that cause these kinds of breaches of privacy. It will make larger companies like this be much more careful when money is on the table for them to lose. To me, if we can criminalize something like a major oil spill such as BP/Deepwater Horiz…

Just a quick question, do you write software? Do you have a legal or economic background? It seems pretty clear to me that anyone suggesting that software bugs in applications that have no risk of causing physical harm should have criminal liability has no idea what they are talking about and what damage such a law would cause.

Case in point look at the quality of medical software today. Hospitals still use windows xp and other completely insecure and outdated software. Because absolutely nobody wants to deal with the nightmare that is HIPAA.

Re: Facebook says new bug allowed apps access to private photos of up to 6.8M users

#70

Earlier quoted context omitted.

> I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things. Sounds like you're suggesting that we criminalize software bugs.

Yes, I am suggesting that. I don't necessarily think jail time is the right thing, but I do think something like meaningful fines are more than reasonable for major software bugs that cause these kinds of breaches of privacy. It will make larger companies like this be much more careful when money is on the table for them to lose. To me, if we can criminalize something like a major oil spill such as BP/Deepwater Horiz…

It's not unprecedented either. Under HIPAA, the Department of Health and Human Services has fined organizations millions of dollars for data breaches resulting from unpatched software and inadequate security practices.
Post reply on HN