4 ms·
Basically all I see is a blame game on CA and that researcher. For the sake of brevity, when someone is hosting a REST API web server at Facebook, did not they
by CodeSheikh 9y ago
Basically all I see is a blame game on CA and that researcher. For the sake of brevity, when someone is hosting a REST API web server at Facebook, did not they notice a large number of requests coming from a certain app id (3rd party dev) for a certain type of data (user, his data, his friends, their data and so on)? At that point you knew what exact users were compromised, 5 or 50 million. And then CA came back to your platform and bombarded those same users (or subset of those users) with their propaganda ads etc. Point being, there were data foot prints left when they pulled the data for those specific users and their were data foot prints left when they came back for those users. Facebook is not Techcrunch that you don't care much about the nature of traffic coming in b'coz it is a blog. Facebook is where people literally share their every day life activities. I am assuming that there should be some smart self-governing systems in place at FB platform that would raise flags when such type inward/outward traffic gets generated.