19 ms·
Facebook says new bug allowed apps access to private photos of up to 6.8M users
- jasonkester 8y ago“Private” photos that people uploaded to Facebook. Sounds like a good time to reiterate the advice: Don’t upload things to the internet that you don’t want to be on the internet. That way there won’t be any of your things on the internet that you didn’t want to be there.
- adtac 8y agoUnfortunately, that advice is nearly useless on HN as the people who need it aren't on this platform.
- spinach 8y agoExcept that your friends, family, and others can upload private photos with you in them.
- jakear 8y agoI left FB when they made reverted a policy that let you opt to confirm all tags before they showed up in searches for you. This means anyone in the world can upload an image, tag you in it, and it will show up in searches for you. It still won’t show up on your profile if you have confirmations for that enabled, but still.
- isostatic 8y agoNo need to tag, just facial recognition will get you from previous tags and other metadata
- jakear 8y agoWill it show up in searches from just facial recognition? That would be very bad for anyone trying to live in a way incongruent with their culture’s standards. (I personally left in solidarity with a Muslim friend who no longer wears Hijab, but would prefer her family didn’t know that; pictures of her without Hijab started showing up in searches without her approval suddenly and without warning when they removed the old “confirm before search results” option)
- InclinedPlane 8y agoJust stop having a face. And friends, or family. Become an unperson. The solution is so obvious. It's always hilarious how people try to pretend that it's easy to just drop out of society and the systems that people use to keep in touch. Sure, you can live like the unabomber in a shed in Montana with no phone service, but having that be the only option to keep your personal data safe from leaks is a bit much of an ask. People should be able to live their lives and take reasonable but not extraordinary precautions to safeguard their privacy and be able to have some expectation of privacy as a result. Unfortunately, there is so much data being collected on everyone, so many intrusions to our private lives, and so little care being taken by the stewards of that private data that it is not, it turns out, a reasonable expectation. And the onus for solving that problem shouldn't be on individuals. We shouldn't be forced to live our lives in fear of digital representations of our appearance being leaked onto the internet as someone might have once feared an ordinary photograph could steal a soul. Rather, those who are going to great efforts to destroy the boundaries of personal privacy should be heavily regulated to prevent them from doing so and heavily incentivized to safeguard private data whenever they are in possession of it.
- jpwgarrison 8y agoSadly, this is the moment that those photos stop being private. I get that this is hard for the general public to understand - but at this point, uploading anything to Facebook = obfuscated, maybe, but not private.
- Raphmedia 8y ago> including images that people began uploading to the site but didn’t post publicly. This means that if you started to upload a photo to the uploader wizard and then thought better, the photo is still out there.
- tracker1 8y agoAlso, never take nude photos with your face/head in the photo. Never let someone take photos/video of you drunk. Unless you want kids with this person, always use a condom.
- AlexandrB 8y agoThis ship hasn’t just sailed, but its masts are no longer even visible over the horizon. Both major phone operating systems actively encourage synchronizing all photos with a server on the internet.
- chrisseldo 8y agoFacebook's release: https://developers.facebook.com/blog/post/2018/12/14/notifying-our-developer-ecosystem-about-a-photo-api-bug/ https://developers.facebook.com/blog/post/2018/12/14/notifyi...
- vuln 8y agohttps://outline.com/nsaNJ4 https://outline.com/nsaNJ4
- polskibus 8y agoDoes it fall under GDPR violation?
- megous 8y agoNo. Unless they didn't report it to the regulators.
- nneonneo 8y agoArticle 34 clearly states that the breached organization must inform the data subject "without undue delay". Given that the event occurred in September, and it is now December, I would characterize that as an undue delay. There should be GDPR consequences of this - it's time that law got properly put to the test.
- jsnell 8y agoI'd imagine what matters is the delay from when you learn about the issue, not the delay from when it happened. This blog post looks a lot more like something they discovered now than something they discovered in September. (E.g. the way they'll have "tools for figuring out who was affected next week").
- WA 8y agoWhat? You get fined under GDPR for a breach. If you don’t report it, the fine will be a lot higher if they find out. We will see how this plays out, but there should be a fine nevertheless (because others have been fined and they reported it).
- megous 8y agoBased on what article?
- WA 8y agoIf you process personal data, you must make sure to protect the data. If you fail to protect the data, you can get a fine. How high it is depends on various factors. Reporting the breach timely to the authorities can help to have a lower fine. But reporting it doesn’t make the fine go away. After all, you started to process personal data and are responsible for it. Alternatively, you could’ve opted for not processing personal data if you think you can’t protect the data adequately. You can read all this here: https://gdpr-info.eu/issues/fines-penalties/ https://gdpr-info.eu/issues/fines-penalties/
- bluetidepro 8y ago> "We're sorry this happened." That about sums it up for all these privacy breaches these days. It's getting to the same level of "thoughts and prayers" for tragedies. No actual change or consequences for the problems happening, just empty "sorries" and "promises" that it won't happen again/they'll get it fixed. I don't know if this is a GDPR violation or not (as someone else asked), but if it is, I hope we start actually seeing action of these sorts of things.
- fullshark 8y agoUntil consumers reveal that they care this is how it will be unless governments regulate/punish.
- Jhndb 8y agoAnd as we've seen so far, consumers do not care in the slightest.
- neurobashing 8y agomy response to this is always in the vein of, "how exactly should customers show they care?" "Well, leave!" isn't an option. They can't leave. Quitting Facebook when you're an active user means you lose a huge amount of social contact. I can think of a dozen people I know who are there because it's how they send baby pics and the like to family. They're non-technical and don't care about federated mastodons, they just want to see their niece and go to their high school reunion. So yeah they get really mad at this stuff but the network effect is so strong, you can't simultaneously convince the entire graduating class of whatever to plan reunions via some new thing when 1)everyone's already on facebook and 2)they've been using it for so long it's part of their workflow.
- ams6110 8y agoMost people I know are getting off of Facebook, or were never on it. The only people I know who are really still active are people using it to market themselves/their business, and are not there because they care about Facebook, but because they want to be findable there (and everywhere). I guess I'm old, but I find that email is great for sending baby pics to friends and family, and for planning things.
- inetknght 8y ago> The bug also impacted photos that people uploaded to Facebook but chose not to post. What about, for example, pictures sent in a private message? I'm so very glad I deleted my account months ago.
- nscalf 8y agoIn so much that they let you delete your account.
- bpye 8y agoIf they aren't actually deleting accounts then they are going to end up with a hefty fine under the GPDR one day...
- burnt_toast 8y agoGiven that it's known that Facebook builds shadow profiles of non-users it seems hard to believe that they would give up the data of ex-users. https://www.bustle.com/p/what-are-shadow-profiles-facebook-ceo-mark-zuckerberg-dodged-questions-about-this-feature-8759987 https://www.bustle.com/p/what-are-shadow-profiles-facebook-c...
- perfmode 8y agoFor pictures present on your phone which Facebook uploaded just in case you’d want to post them later. To hide latency essentially
- deleted 8y ago[deleted]
- graeme 8y agoOn this topic, does anyone know if photo access granted to facebook apps on ios means facebook will upload all photos in the background? Have never seen an analysis of it.
- imgabe 8y agoI think it should be clear to everyone at this point that nothing on Facebook is private. Don't put anything there you wouldn't post publicly.
- SamWhited 8y agoAny company that talks about their old "move fast and break things" motto as if it's a good idea should be treated this way (or not used at all). In industry perspective: We call ourselves "engineers", but real engineers are held accountable when they sign off on using an untested metal alloy in bridge joists and then people die when the bridge collapses. Facebook's constant bad engineering may not kill people directly, but it does lead to a lot of really important information stolen, peoples financial future being ruined, and who knows what other consequences for their users. If you still work for Facebook in this day and age you should be ashamed of yourself; I know people can justify just about anything while claiming that they'll "make it better from the inside" or because they just need to collect a fat paycheck and are comfortable and don't want to look for something new, but we need to fight these impulses anywhere we work.
- ams6110 8y agoBeyond that, nothing online is private. And generally, nothing can be removed. There will always be bugs, mistakes, new vulnerabilities. Eventually it will get out.
- lucb1e 8y agoTwo can keep a secret if one of them is dead, sure. But that doesn't mean you have to assume that having something on the internet means it's going to leak all by itself. The advice we should be giving is not putting all of our eggs in centralized baskets Especially if we know the baskets have goals not aligned with our own, despite it being oh-so-convenient, but also not centralized in the first place.
- Rjevski 8y agoAs usual, I'd like to point out how scummy this site really is. The paywall advertises a "Premium EU Ad-Free Subscription" which is more expensive than the standard subscription and explicitly states "No on-site advertising or third-party ad tracking" as one of the perks. Trying to buy it has the following: > By subscribing, you agree to the above terms, the Terms of Service, Digital Products Terms of Sale & Privacy Policy. On the privacy policy, we have this: > hen you use our Services, third parties may collect or receive certain information about you and/or your use of the Services (e.g., hashed data, click stream information, browser type, time and date, information about your interactions with advertisements and other content), including through the use of cookies, beacons, mobile ad identifiers, and similar technologies, in order to provide content, advertising, or functionality or to measure and analyze ad performance, on our Services or other websites or platforms. This information may be combined with information collected across different websites, online services, and other linked or associated devices. These third parties may use your information to improve their own services and consistent with their own privacy policies. There is absolutely no mention of the "Premium" ad-free subscription in the privacy policy at all, so they are still granting themselves the right to stalk you all over the place even with the premium, more expensive subscription. Not to mention, the privacy policy page itself loads a handful of different trackers before any kind of consent was even granted. I can see Google Analytics, something from "c.go-mpulse.net", something else from "bam.nr-data.net" explicitly sending my user-agent in the URL (why? They'd get it in the headers anyway), Google News JS, Google Pay and the New Relic JS agent. My only response to this is a big "fuck you" and this link: https://outline.com/zd5du7 https://outline.com/zd5du7 so you can read the content without any of that garbage and without paying them since they don't even deserve a single penny.
- Allower 8y ago<3
- saulrh 8y agoIt's too much to hope that Facebook takes a hint from Google and shuts down its social network to preserve user privacy, right?
- aylmao 8y agoGoogle didn't shut down Google+ to preserve user privacy. Not sure if that's what you're implying with your comment-- I hope it's not.
- dragonwriter 8y ago> Google didn't shut down Google+ to preserve user privacy They accelerated the planned shutdown for exactly that reason.
- rohan1024 8y agoThey did that because cost of maintaining platform was higher than its ROI. If Google+ had like 300M-400M monthly active users I don't think they would have shut down Google+
- digianarchist 8y agoThe ROI on Google+ has been negative since before it launched.
- aylmao 8y agoInvestments tend to take a while to return-- this one didn't pay off though.
- lucb1e 8y agoThey claim that, though, and that's the joke GGP was making.
- sakisv 8y agoAt which point should we stop treating these things as bugs and start treating them like features instead? Not this particular thing per se but, you know, it's Facebook. As the recent history has proven these things kind of come with the package.
- Allower 8y agoBURN THEM TO THE GROUND
- connorgutman 8y agoSomeone needs to go Mr. Robot and 5/9 Facebook's servers. This is getting ridiculous.
- vivab0rg 8y agoThe hero we need.
- Oras 8y agoSince Facebook is walking away all the time without any consequences, this will happen again and again. The long-term solution to this mess should come from users abandoning it which is happening gradually based on recent reports.
- jamesrcole 8y ago> The long-term solution to this mess should come from users abandoning it Where will the people go? If it's other software it might end being as bad or worse.
- Oras 8y agoWhat’s the value of Facebook? Serious question as you think people should have alternative
- jamesrcole 8y agoI didn't say an alternative that is like Facebook. People want to communicate with others. If they use software for that then.... my original question applies. And you've avoided answering that question.
- dreamdu5t 8y agoIs there going to be no moderation policy for the constant day-in day-out Facebook tabloid clickbait?
- foobaw 8y agoWhere are the technical details on what the bug was and how it was possible? Shouldn't this be disclosed?
- d4l3k 8y agoSeems pretty clear https://developers.facebook.com/blog/post/2018/12/14/notifying-our-developer-ecosystem-about-a-photo-api-bug/ https://developers.facebook.com/blog/post/2018/12/14/notifyi...
- Mc_Big_G 8y agoWhy is anyone still using FB/Whatsapp/Instagram? It seems the vast majority just don't care at all about privacy.
- WA 8y agoWhatsApp: Because the market share outside the US is insane. Germany has 70% Android users and they don’t use iMessage. Nor any of the other ones unfortunately.
- dqhAR 8y agoToo big to avoid. Data leaks happen to every tech company. As users/customers, won't have knowledge of the leaks unless they are publicly reported. How can you "socialize" these days without using at least one of these internet social/media platforms? Ways to avoid givin them your data are either to be totally reclusive or to be a tech geek who relies only on niche tech products that aren't mainstream. What if they are used as highly valuable networking platforms for your job? Some people live off some kind of business model taking advantage of the sites. Also they work hard at maintaining their audience captivated and engaged.
- jjg77 8y agoDon't believe this BS. FB is selling your private info/photos. A planned breach to divulge your data to 3rd parties, then they cover it up "oh no, we got hacked!". Quit that lame ass platform long ago... MZ is not who you think he is.
- askafriend 8y agoPlease don't come to HN with this garbage.
- makecheck 8y agoI never assume that “settings” guarantee what they claim. It’s just not practical even with good intentions, for a single non-public code base. As a developer, I know it is hard to implement something once, harder to implement consistently across multiple interfaces, and damn near impossible to keep correct years later after employee turnover and other twists. The sad thing is that it costs a ton more money to do things really well, and companies can basically take advantage of the low price of doing things poorly until finally forced. And by then, they have tons of money so they can comply but any startup is screwed because now it costs more for everyone, even those entering the game.
- gbumakefan 8y agoThis bug is just another example of the Valley children doing what they do best - writing terrible code. Keep moving fast and breaking things, kids. Please keep your culture confined to the west.
- jdc0589 8y agoeven moreso when you remember that SO MANY COMPANIES enforce most of their auth z/n at the edge, and are a lot looser between internal services
- newscracker 8y agoIf there’s one thing that Facebook has been highly successful at, it’s making people numb and uncaring about any of these “bugs”. Like the saying goes, “One death is a tragedy; one million is a statistic” — Facebook has made all its privacy blunders and issues over many years a statistic...something people may nod their head at, feel bad for a moment and go back happily to the same company’s platforms. Unless lawmakers around the world do something, nothing will materially affect Facebook (the company). Even if they do, I personally have no faith that the company is capable of changing unless people at the top, like Mark Zuckerberg and Sheryl Sandberg, are out.
- jhowell 8y agoNot very good at the data security thing. In other industries such as health care, there are tables that define fines and penalties. Maybe the same is needed here.
- yumraj 8y agoMost of the comments below are echoing the statement "jail time for bugs!!!!!" and similar sentiments, and therein lies the problem. "bugs" is a catch all word, it covers everything from a pesky typo in UI to bugs like this, severe security issues, meltdown/spectre, VW bugs, and so and so forth. Of course no jail time for a typo, but why not a jail time or severe financial and career consequences for severe bugs especially when it can be shown that a bug was caused due to intentional decisions, malicious intents, sloppy testing, rushed product etc. and not due to genuine mistakes - similar to medical malpractices. Of course lawyers will love it, but it can improve the overall situation. And yes, I'm a software engineers and do know what I'm talking about.
- walrus1066 8y agoWho would be held responsible? Coder? QA? Code reviewer? PM? person putting pressure on PM?
- yumraj 8y agoDepends... If malicious intent, most likely the business owners, PM or engineering management, but in some cases software engineers. If due to rushed product, certainly the management and not software engineers or QA. and so on.. It depends..
- ben174 8y agoUnrelated, but I'd love to know how that article managed to get a picture of that Facebook sign without people standing in front of it. I drive by it daily and I've never seen it without people posing in front of it :)
- techsin101 8y agoIf you take multiple pictures then run algorithm that only keeps mode ( most occurring ) pixels then stationary object will stay and moving people or objects will disappear. Photoshop has this function. Tutorials on YouTube.
- bob_theslob646 8y agoHow come Google never has had a breach? Do they do a better job with security? Is Facebook more of a target than Google?
- libdjml 8y agoGood question, to which I don’t know the full answer. But if you look at their motto “move fast and break things”, insistence on pushing new features as fast as possible, and the recent clash and resignation of their CSO, I’d say google are just more mature about security, and understand their products are entirely reliant on trust of their users.
- tqi 8y agohttps://www.theverge.com/2018/10/8/17951914/google-plus-data-breach-exposed-user-profile-information-privacy-not-disclosed https://www.theverge.com/2018/10/8/17951914/google-plus-data... https://www.theverge.com/2018/12/10/18134541/google-plus-privacy-api-data-leak-developers https://www.theverge.com/2018/12/10/18134541/google-plus-pri...
- Ivoirians 8y agoTechnically, these aren't breaches or leaks, they're vulnerabilities. Whether you believe data was exfiltrated is essentially a reflection of how much you trust or distrust Google.
- trumped 8y agoLol
- sifoobar 8y agoDoes it matter? I have a hard time thinking of a worse company to entrust with personal information. The reach of Google makes Facebook look like a joke. At least when it's leaking they're not making more money.
- QML 8y agoProbably the latter: the larger the value of a network, the more likely it is to attract attackers.
- tareqak 8y agoThe Irish Data Protection Commission says that it opened a broad investigation into Facebook's GDPR compliance in light of numerous data breaches - https://www.ft.com/content/d796b5a8-ffc1-11e8-ac00-57a2a826423e https://www.ft.com/content/d796b5a8-ffc1-11e8-ac00-57a2a8264...
- sammycdubs 8y agoThat privacy popup in NY really worked!
- synthmeat 8y agoPeople here are calling for draconian measures without considering low-hanging fruits first - why not just require the platform to disclose this within its primary medium? Bright big popup right over main facebook.com (and peripheral webs/apps) dismissable only if you scrolled it all the way down, confirmed to have read it, saying "private photos of millions of users were leaked" in big bold letters, would go a long way.
- spiderPig 8y agoTurns out solving 3000 Leetcode questions doesn't teach you now to do security right
- cmurf 8y agoI needed to change my phone number for an online account for a major well known transportation company. The app offers a way to do this, and receive a text message containing a verification code. Upon receipt the code is autoentered into the app, but immediately got an error that said I had to open a support ticket which can only be done with a web browser, not in app. Customer support by email says I have to provide a copy of my driver's license or passport to "secure the account". I said that's not reasonable, companies leak too much personal data so you can't have anymore of mine, I'll just open a new account. They replied they'd just change the phone number (now no longer requiring the required photo ID). They did and the end. - No explanation why the verification code process would not work. - None of my ID's have either my email address, account number, or phone number, and the account doesn't even have my name on it. Giving them photo ID does jack shit for the purpose claimed. - If the account security is questionable, you should not only require text verification of the new phone number, but they should have removed my stored payment accounts, requiring me to reenter them. AFAIK the credit card verification requires CVV and phone number matching the credit card account. That seems like the right way to secure the account rather than bullshit photo IDs.
- ucarion 8y agoFacebook is a global database of political dissidents, queer persons, apostates, and other categories of people whose physical safety is put in peril when their personal lives are leaked. Facebook surely must be heavily fined and regulated for their misbehavior, because to fail to keep Facebook data safe is to put lives at risk.
- mav3rick 8y agoThese people have an option to not use Facebook.
- bluetidepro 8y agoYou have an option not to use a ton of industries that are still heavily fined and regulated for their misbehavior. That logic doesn't matter in this context.
- abrahamepton 8y agoYou never know when, one day, you'll find yourself in a similar group of targeted people based on some otherwise-mundane characteristic. And by then it'll be too late for you to "not use Facebook".
- denlekke 8y agothey track and keep data on non-users as well though
- bad_user 8y agoGoing to play the devil’s advocate. If you fine Facebook, you have to fine the small companies too, and even individual developers developing OSS, since the law should apply to everyone equally. Of course the fines have to be proportional to the number of affected users. So would you like a fine for your bugs? And note that contrary to other professions, software development doesn’t have generally agreed recipes for building bug-free software, so was that really negligence? Was it malpractice? Being fined for a contribution to an OSS project would be terrible, wouldn’t it? And no, the size of the company doesn’t and shouldn’t matter in the eyes of the law, only the impact. Also people uploading stuff on the Internet should really expect a best effort privacy. If you expect secrecy, then uploading shit on a platform meant for sharing is pretty dumb. Note that I will blame Facebook for willful privacy violations. And I hope to see them suffer under GDPR. But a bug doesn’t fall in the same category.
- Jaruzel 8y agoAs IT people, we owe it to our families to offer to self-host their social data on one of the many open-source platforms that are available. Maybe spend some time over the Xmas period having 'The Conversation' with our loved ones about their data safety?
- keyboardmowing 8y agoWasn’t there a point in time that fb wanted users to submit their nude photos so that they could better detect fake profiles ? Lol
- cody3222 8y agoDidn't they just launch a feature earlier this year telling people to upload their nudes so they could better detect when an ex miss-used them? https://www.theguardian.com/technology/2017/nov/07/facebook-revenge-porn-nude-photos https://www.theguardian.com/technology/2017/nov/07/facebook-...
- rhegart 8y agoRemember when Facebook wanted you to upload nudes so they could help keep them off of Facebook and the internet...yeahhh hopefully no one trusted them with that. Also are there even any safeguards preventing private photos like these or even nudes from not being able to be viewed by any admin? I hope there is...
- randyrand 8y agoI assume you’re being sarcastic. that never happened.
- intopieces 8y agohttps://www.independent.co.uk/life-style/gadgets-and-tech/news/facebook-nude-photos-revenge-porn-upload-pictures-images-safety-a8365646.html https://www.independent.co.uk/life-style/gadgets-and-tech/ne...
- addicted 8y agoI’ll be interested in seeing what the number of affected users actually ends up being. As John Gruber at Daring Fireball has pointed out, Facebook has a rich history of giving initial numbers which tend to grow by orders of magnitudes over the coming weeks.
- nixarian 8y ago"Dumb Fucks."
- annadane 8y agoI mean, it's a bug. Happens to everyone. Criticize them for the things they should be but don't make a case out of everything.
- snovv_crash 8y agoThe more leaks there are, the more I feel that the mindset will shift from user data being an asset to a liability.