13 ms·
> Wehner also said Facebook still expects expenses to grow 50% to 60% from last year > “But as I’ve said on past calls, we’re investing so much in security tha
by everdev 8y ago
> Wehner also said Facebook still expects expenses to grow 50% to 60% from last year
> “But as I’ve said on past calls, we’re investing so much in security that it will significantly impact our profitability,” Zuckerberg said. “We’re starting to see that this quarter.”
That sounds like a big 1-year jump. From what I can tell, the big Facebook scandals (fake news, Cambridge Analytica) came from faults in company policies rather than security glitches.
I wonder if labeling it "security" is a PR thing as their web ads all focus on FB taking active steps to make sure those types of scandals don't happen again.
- Bucephalus355 8y agoTo be fair, security is an amazing amount of policy. I took and passed the CISSP, and that exam must be at least 30%, maybe 40% policy. Things like knowing how does the Commerce Department’s rule of Safe Harbor apply to US companies doing business in EU. Stuff like that. That being said, it made me way better at my job. No matter how many technical justifications I have for why we should implement X, the second I brought up a small to medium legal thing everyone would fix it immediately.
- paxy 8y agoBut how do policy changes result in a 50% increase in total expenses? They can't be hiring that many lawyers.
- xxorlak 8y agoImplementation of policies has a waterfall effect throughout the org. EG: Adding something as simple as a privilege expiration (generic example) and propagating it through the org and various teams itself will take time.
- bobdole12345 8y agoThey're hiring 2/3rd more employees to act as content moderators from the sounds of the guidance.
- cxhandley 8y agoThey're about to break the brains of 1000s of people subjecting them to aweful content. This will also have consequences. What was it "move fast and break things"!
- deleted 8y ago[deleted]
- CalRobert 8y agoEvidently it's not employees, but contractors (via Accenture, etc). Rumour around these parts is a content mod killed themselves at work a couple months ago. Wouldn't want to put that on actual employees of course!
- foobarian 8y agoYou should have seen how much harder life got at our company when we discontinued a common root password across the back office. Things that used to take 5 minutes to fix by self-service now take a ticket to the owner of a system, which can take days.
- deleted 8y ago[deleted]
- jessaustin 8y agoIf one bought into "the security story", one would expect your company after this policy change to have seen fewer random regressions due to random people rooting around in systems for which they were not responsible. Did you find that to be the case?
- rorykoehler 8y agoIt's about reducing exposure to risk more than actual occurrences. You only need to regress once for it to permanently damage your business. Just because it never happened until now doesn't mean that it won't in the future.
- jessaustin 8y agoISTM typically there would have to be more going wrong for "permanent damage"? Not that it would be surprising for a shared-root organization e.g. to have poor backup skills...
- rorykoehler 8y agoCommercial damage is often worse than technical
- Pyxl101 8y agoEven if you don't have a common root password, you can still have groups of people who are sudoers for different systems.
- zeroxfe 8y agoExample: audit all employee access to PII data. Anyone who's worked at a large company can tell you how incredibly complex and expensive this can get if your systems aren't designed for this.
- TheSpiceIsLife 8y agoThat’s upside down, me thinks. It would be difficult to incur a 50% increase in expenses without massive policy shift.
- notveryrational 8y agoReal security is almost all technical and implementation. There's a very significant danger to security that policies be some kind of front line of defense, or be implemented over sound engineering practices. In almost every work environment, I've seen the policies working directly against security: if not by contradicting it, ignoring the details where the real security decisions live, or by striking the wrong balances between prescriptiveness and generality - then by out-prioritizing security decision making. (I've worked at mostly 100,000+ person companies). It's much better to have technical security controls >80-90% of the actual security. It's just expensive and harder to teach/learn/implement. That said, there's some real security gained by policy. It comes from: - Ability to communicate expectations ("adopt technical solution X") - Ability to exercise legitimized (instanciated/codified) authority Most of the rest of the value of policy comes in as business enablement value (policies are easier to communicate to auditors than security control implementations are). Policy can also be a useful placeholder for real security in the sense it will satisfy many external parties who might otherwise reprioritize/randomize security investments.
- bdhess 8y agoPolicy is not a substitute for reasonable technical controls. But it’s also not a concern that can be wished away by saying “well we just do our security the real way, in code.” Any security control implementation enforces some conceptual policy, even if that policy isn’t documented elsewhere. In some places that’s fine; in others with more robust needs, that’s insufficient. Part of what auditors audit is that policy implementations (whether in code or in human practice) match the specification. As an example, I’m glad that browser vendors require CAs to document their policies for issuing certificates. Let’s Encrypt does a great job of making much of this process automatic, but there’s still pieces that must be done by humans, and there’s still written policies in place for all of their operations. At some point in any security process, human judgment comes into play. Striking the wrong balance between technical controls and allowing for human judgment can also lead to absurd outcomes, like this recent article/discussion[0]. [0] https://news.ycombinator.com/item?id=17350645 https://news.ycombinator.com/item?id=17350645
- 8y ago
- smileysteve 8y agoThere's some truth that lack of "security" is what makes money (ads) and gets views (fake news stories), and users (fake users).
- ggg9990 8y agoA lot of their security/policy work is hiring tons of humans to fix things. For example they are hiring an additional 10,000 content moderators. That will obviously impact profitability.
- coliveira 8y agoJust like Google, they are learning that AI is not up to the task of dealing with humans that try to game the system by all means possible.
- halflings 8y agoI don't think neither companies ever denied that AI won't get 100% of the cases, they just say that you can't moderate billions of posts with human moderation alone, you need AI to take care of the 99%, and humans for ambiguous cases.
- narrator 8y agoChina has a huge staff of these people too. I think at last count they had 20,000 people employed doing content moderation for the country.
- ggg9990 8y agoI would think it is much more than 20,000 in a country of 1 billion people with such tight content controls.
- sonnyblarney 8y agoI was directly involved in one of those 'incidents' several years back where FB gave our app a special API that others did not have. This was because it was easier for us to build the 'FB experience' for their users, than it was for FB themselves. It was clean, legit, above board and secure. It's astonishing how different the 'media narrative' is from reality, and it confirms my belief that the press runs on such narratives (i.e. building up, crashing down) because in both directions the truth is inflated for dramatic, i.e. click-bait reasons. Our large company built a very good FB app that effectively was 'FB' on our platform. It was FB branded - for users, it was effectively the 'real' (and only) FB. Obviously that app had to have special APIs. Everyone involved from top to bottom was pro. We didn't store data, nor did we want or need to. The way the tech was setup (data goes to app), we didn't really have the option. Users logged into their own accounts and retrieved their data, it's not like we could just access data arbitrarily. Everything was pro and above bar - and nobody in the equation - a lot of us regular, conscientious people - thought for a second that anything was wrong or irregular in any context. In fact - the whole situation could be described as: "FB hired 3rd parties to develop some code", which surely they do in some circumstances. Nobody was harmed in any way, and there really wasn't risk of anyone being harmed. I understand that with 2018 hindsight, we might look at things a little differently, but in reality, I think we'd have still done it. Perhaps there would have been more checks and assurances (i.e. FB takes ownership of code and actually publishes the app), but in reality it was (and would still be) fine. As far as the Cambridge story - this is also misleading because the API's that were used there were available to the entire world and everyone knew exactly what they were. Were there tech people screaming foul? The press? Not really, they seemed reasonable, until it seemed that some bad agents were getting a little unscrupulous, and so FB did the right thing and altered the APIs to make them more secure. Security polices change all the time, in this case they tightened up given some field data. That's it. It's really a story about Cambridge's scammy behaviour, and possibly lies to FB on where that data was, not about FB. I don't like Facebook, I don't use it, I don't like being 'productized' etc. etc. - but I don't feel that the information in these scenarios has been properly handled by the media. Because there are legitimate issues with privacy in the new world order in 2018 that are finally coming to bear, and we definitely want to re-evaluate our situation with FB, basically, we go and dig up 'something that happened 10 years ago in which nobody was harmed' to build a 'kind of misleading narrative' around the the 'legitimate issue'.
- pdpi 8y agoSecurity isn't just "people can't get inside our servers", it's a much broader topic than that — anything that looks like "people didn't something that, in hindsight, we'd rather they couldn't have" falls under that purview, really. I'd certainly qualify working on preventing the next Cambridge Analytica, or preventing the next micro-targeted political propaganda campaign, as "security work" without even blinking.
- casefields 8y agoSecurity is gobbledygook. It’s why politicians love using national security with legislation.
- fwn 8y agoThe strong argumentative edge one gains by turning the debate towards security led to this cool concept in international relations: https://en.wikipedia.org/wiki/Securitization_(international_relations) https://en.wikipedia.org/wiki/Securitization_(international_...
- Agathos 8y agoSee also Trump's tariffs. WTO roles forbid arbitrary tariffs, unless the government claims they are for the sale of "national security."
- deleted 8y ago[deleted]