4 ms·
> Facebook should have also designed their auth system more carefully, but that's a separate issue. It's not a separate issue, though. One of the main ways the
by vec 8y ago
> Facebook should have also designed their auth system more carefully, but that's a separate issue.
It's not a separate issue, though. One of the main ways they could have been more careful in designing their auth system was by choosing mechanisms that didn't create "legitimate purposes" for additional data collection in the first place.
This is a recurring theme in every data breach story that comes up. Every thread has someone correctly making the point that the company's business model requires them to store the leaked data, but this is not an excuse. Pick a more ethical business model.
- thaumasiotes 8y ago> Every thread has someone correctly making the point that the company's business model requires them to store the leaked data, but this is not an excuse. Pick a more ethical business model. The two points in this thread are: - The company's customers specifically demand that the company store the leaked data, and they personally provide it in the expectation that it will be (1) stored and (2) released to other users. - You can't send 2FA codes to a phone number without knowing that phone number. What would a "more ethical business model" do to address either of those points?
- vec 8y agoAs to the first point, the headline is "Facebook says millions had phone numbers, search history and location stolen". 2FA phone numbers have to be stored, but they should _never_ under _any_ circumstances be released to other users. Search histories, too, are useful to the user that generated them but shouldn't ever need to be exposed to third parties. Location data can be transient or short lived and still meet most of the technical requirements for the customer-facing features that use them, so I'm not sure there's a good rationale to permanently store it in the first place. And for where better professional ethics could have made a difference, let's walk backwards through the decision tree for 2FA: * The implementer of this feature could have used the profile phone #, and the copy could have made it clear that the feature required a phone number on the profile to function. * The implementer could have chosen to treat the phone number as secure authentication data and taken pains to store it in a manner that was opaque to the rest of the application, say encrypted at rest with a key that's only available inside the auth subsystem. * The designer of this feature could have insisted on using an authentication app instead of SMS. * The designer of the authentication workflow could have supported oAuth logins through a third party with good 2FA support, reducing demand for Facebook to support 2FA internally. * New accounts could spawn with the most restrictive permission settings and require users to affirmatively opt-in to sharing everything they want to, lowering the damage to the median user from an account being compromised and thereby also reducing customer demand for Facebook to support 2FA. * Facebook could have chosen, early and often, to push for open integration with third parties, building a market segment where they were only one social networking portal among many and no single company had anything close to a complete social graph. In such a world 2FA for Facebook accounts might seem no more urgent than 2FA for, say, Hacker News accounts. The common thread, at all levels, is that Facebook consistently prioritizes growing faster, collecting more data, and becoming more central to the functioning of the internet over what I would feel comfortable describing as the user's best interests. I run a website with a few tens of thousands of user records, which means I have been entrusted as a secret keeper for some amount of private information by tens of thousands of people. That's a very tangible burden on me, a weight of responsibility that as part of my job I have to carry. It's also a liability for my employer in the event of a data breach. That means our incentive structure pushes us to store as little data as we can get away with and to expose that data to our infrastructure in the most technically restrictive manner we can get away with. Facebook chose to build a business around treating other people's secrets as an asset, rather than a liability. That incentivizes them to hoard data and to be cavalier about how they capitalize on it, and lo and behold they routinely behave in accordance with those incentives. When I say a "more ethical business model", this is what I mean. An ethical business is, in practice, one where the incentives of the company and the incentives of its users are not in fundamental tension with one another.
- thaumasiotes 8y agoNew accounts do spawn with the most restrictive settings possible -- they cannot disclose any of your information because they don't have it. You must already affirmatively opt in to Facebook displaying any part of your profile.