They appear to have resolved this issue in a timely fashion. I can no longer find a request for phone number during the sign up process or once logged in to find friends.
Not for the guy who was outed, they didn't.
91–100 of 124 posts
They appear to have resolved this issue in a timely fashion. I can no longer find a request for phone number during the sign up process or once logged in to find friends.
Not for the guy who was outed, they didn't.
I deleted my facebook account in March 2010. In November, six months later, the only evidence of my account was that my facebook information was loaded onto my friends telephone. He had my profile photo, plus some random tidbits of information automatically grabbed from facebook by his phone.
I deleted my facebook account ~6 years ago, but before I completely deleted it I changed my name to "DLC Text". About a year ago I started getting emails from facebook recruiters, and guess what my name was resolving to in their system? Yep, that's right -- "DLC Text". For 6 years they have kept my information even though it was deleted.
A friend of mine ragequit facebook a little less than a year ago, came back, and it allowed him to reactivate his profile. I don't think it ever said 'delete' though.
Earlier quoted context omitted.
If you are truly concerned about harm to users, did you try reporting this to facebook.com/security or facebook.com/whitehat? FWIW, I've alerted some people. Your post is unclear on one point. Did you see this screen BEFORE confirming via SMS that you were in possession of the mobile number you entered? If it was after confirmation, that's a very different thing.
You know, buddy, I think from FB we could all use a little more "thanks for pointing out this problem that we at FB should have prevented or refused to implement" and a little less of sarcastic "if you are truly concerned...jump through our hoops." Preventing harm to users is your job, not ours. Associates of mine have made SEVERAL complaints to FB about security concerns through your standard "hoops" (including /whi…
Please also remember that not every report actually pans out. I can't say we should have prevented this because I don't yet know if there is something to prevent. It now appears that the behavior the OP is calling a "fuckup" happened after he confirmed ownership of the phone number. This might change things a bit.
Preventing harm is our responsibility. But if you happen to find an open door, or what might look like an open door, it's more helpful to get all the facts first, report to the vendor, and disclose later if you think the reporting process is unsatisfactory.
For instance, if you have not heard a response from /whitehat, please email me and I will see what I can find out. Or disclose it. I can't stop you.
When it comes to the rules of disclosure, I'm well aware that where you stand depends on where you sit, but I personally think these kinds of firedrills aren't the right way to do it.
Earlier quoted context omitted.
Hum. Respect the law ? I don't know in the US. But here in Europe that's pretty much against the law in most countries.
Point of order: If you don't even know what the law is, you might try finding out, before sniping about how someone supposedly is not "respecting" it. If you did, you might then find, for instance, that the best course of action is to complain about the law (or lack of laws), and do something about that.
Anyway, I think you're wrong. I do know the law in France and Europe. And since I live in France, I have a contract with Facebook Ireland. Not Facebook US. So it's the Irish law that is the appropriate law. I don't know the details of Irish law in that matter. So your Argumentum ad nauseam saying I should know the law could have been correct... (if not excessive and irrespective) but since Ireland is part of the European Union... I do not need to go seek the exact Irish law. Directive 95/46/CE is there to unify the European law on that subject.
See by yourself :
http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:...
"SECTION I PRINCIPLES RELATING TO DATA QUALITY Article 6 1. Member States shall provide that personal data must be: (a) processed fairly and lawfully; (b) collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those purposes. Further processing of data for historical, statistical or scientific purposes shall not be considered as incompatible provided that Member States provide appropriate safeguards; (c) adequate, relevant and not excessive in relation to the purposes for which they are collected and/or further processed; (d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that data which are inaccurate or incomplete, having regard to the purposes for which they were collected or for which they are further processed, are erased or rectified; (e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the data were collected or for which they are further processed. Member States shall lay down appropriate safeguards for personal data stored for longer periods for historical, statistical or scientific use."
Do you think what Facebook Ireland is doing, yes because Facebook Ireland offers the EXACT same service than Facebook US, respects the law in Ireland ?
Then you should know that it's the everyone's right to ponder about the due respect of law without having to file a formal complaint and start a trial. Otherwise, journalists would have to sue half the world. By the way suing costs money that I don't have. So if the only ones that can complain about some problems in a company policy, are the ones that have the money to sue the company... we're in a sad society. I think that's the moment when an American starts complaining about socialism in Europe.
Earlier quoted context omitted.
If you are truly concerned about harm to users, did you try reporting this to facebook.com/security or facebook.com/whitehat? FWIW, I've alerted some people. Your post is unclear on one point. Did you see this screen BEFORE confirming via SMS that you were in possession of the mobile number you entered? If it was after confirmation, that's a very different thing.
For context of readers, I note you are a FB engineer. Thanks for looking at this. 1. I'm not concerned about harm to users from this issue, I don't pretend to be. That should be Facebook's role. 2. This isn't a bug or a vulnerability, it's something you've actually coded - a feature. It doesn't 'accidentally' match up the number I've just entered with other people's phonebooks, you've programmed it to do that. Fine,…
The potential privacy compromise here is that people who might've not wanted the user to know that they had them in their synced-to-Facebook phonebook, or may have a secret profile connected to said phonebook, could be unwittingly exposed to the user. As your example of the friend with the hidden gay profile shows, that can have alarming results. I'd say that example's bad enough and worth addressing (even if the answer is just better messaging about how synced phonebooks can be used) and that the PI/law enforcement talk is just muddying the waters.
Earlier quoted context omitted.
If you are truly concerned about harm to users, did you try reporting this to facebook.com/security or facebook.com/whitehat? FWIW, I've alerted some people. Your post is unclear on one point. Did you see this screen BEFORE confirming via SMS that you were in possession of the mobile number you entered? If it was after confirmation, that's a very different thing.
Facebook does not care about user privacy. They have gone on record saying this multiple times (and then quickly recanted it). They do not care about user privacy because it goes against everything that Facebook needs in order to grow. For example, if you tag a photo with a friend's name, all of that friend's friends can see this photo, even if you restrict who can see your photos. You cannot change this, which means…
Just because a company is big doesn't mean it has to sell out and stop caring about user privacy.
Earlier quoted context omitted.
You know, buddy, I think from FB we could all use a little more "thanks for pointing out this problem that we at FB should have prevented or refused to implement" and a little less of sarcastic "if you are truly concerned...jump through our hoops." Preventing harm to users is your job, not ours. Associates of mine have made SEVERAL complaints to FB about security concerns through your standard "hoops" (including /whi…
I get what you're saying and I'm sorry if I was snarky. On the subject of politeness, I myself don't enjoy reading posts titled "Facebook privacy fuckup" at 5am on a Sunday. Please also remember that not every report actually pans out. I can't say we should have prevented this because I don't yet know if there is something to prevent. It now appears that the behavior the OP is calling a "fuckup" happened after he con…
Earlier quoted context omitted.
Well, what I am wondering is: is this actually an unintended consequence or a conscious choice that has been made?
A company doesn't have a single conscience. It may have been a conscious choice by an engineer, or it may have been an unintended consequence of some other code change. Either way, I highly doubt it involved the check-off from a director-level employee. If every decision had to get approval from the management team, then progress would grind to a halt, and Facebook would end up like Microsoft.
Insightful: while it's seemingly simple and obvious, everyone I know has fallen prey to the opposite belief, myself included.
I deleted my facebook account in March 2010. In November, six months later, the only evidence of my account was that my facebook information was loaded onto my friends telephone. He had my profile photo, plus some random tidbits of information automatically grabbed from facebook by his phone.
I deleted my facebook account ~6 years ago, but before I completely deleted it I changed my name to "DLC Text". About a year ago I started getting emails from facebook recruiters, and guess what my name was resolving to in their system? Yep, that's right -- "DLC Text". For 6 years they have kept my information even though it was deleted.
I really don't agree with this, but I can't deny that there's value in this data. It's unscrupulous to hold onto it, though.
In my opinion, there should be some way to hard-delete information like this, even if the user has to go through some two-key-nuclear-launch confirmation process to prevent accidental deletes.
Earlier quoted context omitted.
I deleted my facebook account ~6 years ago, but before I completely deleted it I changed my name to "DLC Text". About a year ago I started getting emails from facebook recruiters, and guess what my name was resolving to in their system? Yep, that's right -- "DLC Text". For 6 years they have kept my information even though it was deleted.
Silly semantic question - when you 'delete' your facebook account, do they use the word 'delete' or just 'disable' or 'shut off' or something similar? A friend of mine ragequit facebook a little less than a year ago, came back, and it allowed him to reactivate his profile. I don't think it ever said 'delete' though.