2 ms·
As to the first point, the headline is "Facebook says millions had phone numbers, search history and location stolen". 2FA phone numbers have to be stored, but
by vec 8y ago
As to the first point, the headline is "Facebook says millions had phone numbers, search history and location stolen". 2FA phone numbers have to be stored, but they should _never_ under _any_ circumstances be released to other users. Search histories, too, are useful to the user that generated them but shouldn't ever need to be exposed to third parties. Location data can be transient or short lived and still meet most of the technical requirements for the customer-facing features that use them, so I'm not sure there's a good rationale to permanently store it in the first place.
And for where better professional ethics could have made a difference, let's walk backwards through the decision tree for 2FA:
* The implementer of this feature could have used the profile phone #, and the copy could have made it clear that the feature required a phone number on the profile to function.
* The implementer could have chosen to treat the phone number as secure authentication data and taken pains to store it in a manner that was opaque to the rest of the application, say encrypted at rest with a key that's only available inside the auth subsystem.
* The designer of this feature could have insisted on using an authentication app instead of SMS.
* The designer of the authentication workflow could have supported oAuth logins through a third party with good 2FA support, reducing demand for Facebook to support 2FA internally.
* New accounts could spawn with the most restrictive permission settings and require users to affirmatively opt-in to sharing everything they want to, lowering the damage to the median user from an account being compromised and thereby also reducing customer demand for Facebook to support 2FA.
* Facebook could have chosen, early and often, to push for open integration with third parties, building a market segment where they were only one social networking portal among many and no single company had anything close to a complete social graph. In such a world 2FA for Facebook accounts might seem no more urgent than 2FA for, say, Hacker News accounts.
The common thread, at all levels, is that Facebook consistently prioritizes growing faster, collecting more data, and becoming more central to the functioning of the internet over what I would feel comfortable describing as the user's best interests.
I run a website with a few tens of thousands of user records, which means I have been entrusted as a secret keeper for some amount of private information by tens of thousands of people. That's a very tangible burden on me, a weight of responsibility that as part of my job I have to carry. It's also a liability for my employer in the event of a data breach. That means our incentive structure pushes us to store as little data as we can get away with and to expose that data to our infrastructure in the most technically restrictive manner we can get away with.
Facebook chose to build a business around treating other people's secrets as an asset, rather than a liability. That incentivizes them to hoard data and to be cavalier about how they capitalize on it, and lo and behold they routinely behave in accordance with those incentives. When I say a "more ethical business model", this is what I mean. An ethical business is, in practice, one where the incentives of the company and the incentives of its users are not in fundamental tension with one another.
- thaumasiotes 8y agoNew accounts do spawn with the most restrictive settings possible -- they cannot disclose any of your information because they don't have it. You must already affirmatively opt in to Facebook displaying any part of your profile.