3 ms·
> and we have no evidence that Wes or anybody else accessed any user data This raises way more questions than it answers. Most notably: why aren't you recordin
by grrowl 11y ago
> and we have no evidence that Wes or anybody else accessed any user data
This raises way more questions than it answers. Most notably: why aren't you recording who accesses user data?
- nostalgiac 11y agoReads to me that they are recording the access and no-one did access it.
- lstamour 11y agoNot necessarily. If that were the case, wouldn't they use the stronger, "and we have evidence that no data was accessed through this exploit"? The fact is: They can't possibly protect user data once the private SSL keys leak. At that point anyone can intercept user data on third-party, non-Facebook servers if they're affiliated with an ISP, wifi hotspot or other point of access. Anyone could send targeted phishing emails for their servers: How would they know, if the SSL cert looks legit and the DNS is regionally poisoned?