Live data from Hacker News

Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues

nytimes.com

91–100 of 331 posts

Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues

#91
post #75
post #47

Earlier quoted context omitted.

If you're a small business - I get it, it's good to whitelist whatever information you're logging explicitly, but for smaller teams a hard to diagnose issue might lead the team to "log everything so we can sort it out later". Facebook is Facebook, whether this decision was the product of the corporation as a whole, a small dev team, or a highly paid consultant/third party, Facebook is a big enough company that they d…

I've worked for multiple Fortune 25 companies, and that excuse does not fly. Not in banking or healthcare, where breaches of privacy/confidentiality are actually illegal, rather than merely distasteful. Small teams and careless devs doing that sort of bad logging will be caught and corrected by strict security oversight. This is the sort of thing that leads the HN crowd to sneer at the old, slow ways of the enterpris…

hey just so you know your https ssl certificate is broken for congruence.io

so much for how careful you are with computers. it’s telling you worked for multiple fortune 25’s.

Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues

#92
post #47

Earlier quoted context omitted.

If you're a small business - I get it, it's good to whitelist whatever information you're logging explicitly, but for smaller teams a hard to diagnose issue might lead the team to "log everything so we can sort it out later". Facebook is Facebook, whether this decision was the product of the corporation as a whole, a small dev team, or a highly paid consultant/third party, Facebook is a big enough company that they d…

Seems like a pretty trivial automated test for so many PHD's to miss: create_user('Bob', 'BobPassword123') assert "BobPassword123" not in logfile

What if it logs "BobPassw[...]"? Is that more acceptable?

What if there is a bug and some other function logs "[...]word123"?

Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues

#94
post #72

Earlier quoted context omitted.

Seems like a pretty trivial automated test for so many PHD's to miss: create_user('Bob', 'BobPassword123') assert "BobPassword123" not in logfile

Hrm, so you checked the apache access logs, or maybe an error log, what about the system logs? Does the login request spin up a bash script and pass the password to it? I don't think it's trivial to guarantee non-existence.

> I don't think it's trivial to guarantee non-existence.

I disagree in this case. Log messages don't spontaneously appear in arbitrary places. If the developers understand what their software is doing and how their systems are configured then they should know where to check for the logging messages.

Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues

#96

"The Silicon Valley company and the F.T.C.'s consumer protection and enforcement staff have been in negotiations for months over a financial penalty" Honest question: What gets negotiated in this kind of settlement? What leverage does Facebook have in this situation to say, "no, that fine is too high"?

I'd assume it would look something like:

"No, that fine is too high. We'll settle this in court(s) since we think we can do better."

Now the FTC is facing a potentially big delay and a risk of no fine if the courts eventually hand Facebook a favorable decision.

Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues

#97

Why doesn't Zuck just quit? He's so rich. I would have fucked off and retired so long ago.

I would guess because he truly cares about making the world more open and connected and issn't in it for the money.

He also pledged to donate all his wealth along with Bill Gates and Warren Buffet

Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues

#98

Seems like they should add another 0 to the fine after the recent hat trick: 1) Prompting users to give Facebook their email passwords.[0] 2) Using that email access to "inadvertently" upload the information of their email contacts.[1] 3) Storing said passwords and others in plaintext. [2] It's pretty impressive that a company could do something so brazenly malevolent and be confident that they will escape with no mo…

I'm ashamed to say that up until now, when I saw Facebook (or similar) acting evil I thought about the quote, "Never attribute to malice that which is adequately explained by stupidity". Well, fuck that and fuck me, those people are not idiots, they're criminals.

That gets me every time I read in the media about a 'bug' that enabled some complex data transfer. People, somebody has to decide, plan, code, test and deploy the behaviour, and make sure it works. And yet, people accept the explanation it seems without much thought.

Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues

#99
post #37

Earlier quoted context omitted.

Agreed. This small of a fine comes off as a cost of doing business for a company as large as Facebook.

This is why we need GDPR in the US. Make the fine like 5% of global annual profit (not sales). Something that will hurt and make them actually think it's not worth it and actively avoid it rather than just the cost of doing business and a snicker as they walk away.

Laws don't seem to matter in this day and age as they can be gamed by money and/or legal tricks. Only way to fix the issue is to get rid of corrupt and unethical government and business leaders. Implementing something like GDPR would only be adding to the arsenal of bad actors.

Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues

#100

Seems like they should add another 0 to the fine after the recent hat trick: 1) Prompting users to give Facebook their email passwords.[0] 2) Using that email access to "inadvertently" upload the information of their email contacts.[1] 3) Storing said passwords and others in plaintext. [2] It's pretty impressive that a company could do something so brazenly malevolent and be confident that they will escape with no mo…

I'm ashamed to say that up until now, when I saw Facebook (or similar) acting evil I thought about the quote, "Never attribute to malice that which is adequately explained by stupidity". Well, fuck that and fuck me, those people are not idiots, they're criminals.

Sorry but I think you're being too hard on yourself, while also being inappropriately diplomatic toward Facebook. I mean, crimes happen all the time. I'm a criminal, I speed sometimes, I often jaywalk. I would say they are malicious, and have forfeited whatever position as a trustee of data that people have ever granted them. What do you do with a trustee who puts their interest before the beneficiary? Of course, you fire them. But indeed who is the beneficiary? At least in their public vernacular it's the user, even though more well read individuals know the beneficiary is the trustee, one in the same.

Facebook is perhaps not out of the ordinary really, it's just another of a variety of businesses who have come to realize they hate having users. They just need their data. Vampires don't want human friends either, they just need their blood.

Post reply on HN