Live data from Hacker News

A Facebook engineer abused access to user data to track down woman

businessinsider.com.au

1–10 of 108 posts

Re: A Facebook engineer abused access to user data to track down woman

#3
> from 2014 to August 2015.

Everyone here is unsurprised by this and at this point I expect the social networks to just abuse my user data anyway. They won't change and they will never stop this.

Who is to say that this is already happening with the other social networks that are scooping up our data but in 5 years time will only admit their actions afterwards.

Maybe they are all doing this as we type.

To Downvoters: So you think that these social media companies are NOT abusing our data? There's tons of evidence of this everywhere, including this confession.

There can only be one explanation of why I'm getting downvoted heavily of an undeniable known fact and it is likely that it is by those working at these companies because they know that I am right and the point still stands regardless of any downvotes (and censoring of the truth).

Re: A Facebook engineer abused access to user data to track down woman

#4
This is a pretty widespread issue I'd imagine, we just don't hear about it or people aren't caught.

I know they've been locked down since I've left, but some of the tools we were allowed to just freely access at Uber were a tad scary, to say the least.

I'm sure every company with a very large userbase, such as Facebook/Microsoft/Google/etc claim they have internal protections/checks but have even more holes like this.

Re: A Facebook engineer abused access to user data to track down woman

#5
> At the time, more than 16,000 employees had access to users’ private data, according to the book.

> Stamos suggested tightening access to fewer than 5,000 employees and fewer than 100 for particularly sensitive information like passwords.

I'm sorry, what?

I can tell you the number of legitimate engineers that should have access to user's passwords.

It's a nice, round number.

It's zero.

Re: A Facebook engineer abused access to user data to track down woman

#6
post #3

> from 2014 to August 2015. Everyone here is unsurprised by this and at this point I expect the social networks to just abuse my user data anyway. They won't change and they will never stop this. Who is to say that this is already happening with the other social networks that are scooping up our data but in 5 years time will only admit their actions afterwards. Maybe they are all doing this as we type. To Downvoters:…

Company i used to work for gave almost every employee full access to the db through phpmyadmin.

Re: A Facebook engineer abused access to user data to track down woman

#7

> At the time, more than 16,000 employees had access to users’ private data, according to the book. > Stamos suggested tightening access to fewer than 5,000 employees and fewer than 100 for particularly sensitive information like passwords. I'm sorry, what? I can tell you the number of legitimate engineers that should have access to user's passwords. It's a nice, round number. It's zero.

Or one step further, the passwords are hashed and salted using a encoding spec like BCrypt.

Any employee logins are done through skeleton keys that are audited.

Re: A Facebook engineer abused access to user data to track down woman

#9

> At the time, more than 16,000 employees had access to users’ private data, according to the book. > Stamos suggested tightening access to fewer than 5,000 employees and fewer than 100 for particularly sensitive information like passwords. I'm sorry, what? I can tell you the number of legitimate engineers that should have access to user's passwords. It's a nice, round number. It's zero.

Is it not possible to only have the hashes or does it have to get persisted somewhere in the process?

Re: A Facebook engineer abused access to user data to track down woman

#10
post #6
post #3

> from 2014 to August 2015. Everyone here is unsurprised by this and at this point I expect the social networks to just abuse my user data anyway. They won't change and they will never stop this. Who is to say that this is already happening with the other social networks that are scooping up our data but in 5 years time will only admit their actions afterwards. Maybe they are all doing this as we type. To Downvoters:…

Company i used to work for gave almost every employee full access to the db through phpmyadmin.

Was it a social network thing too or a totally different market ?
Post reply on HN