42 ms·
Two More Cases of Third-Party Facebook App Data Exposure
- t385glmp63v 8y agoFacebook has a Data Abuse Bounty program where they pay for reporting third-party data leaks like these: https://www.facebook.com/data-abuse/faq/ https://www.facebook.com/data-abuse/faq/
- _-_T_-_ 8y agoResearch: https://www.upguard.com/breaches/facebook-user-data-leak https://www.upguard.com/breaches/facebook-user-data-leak
- dang 8y agoThanks. We've changed the URL from https://www.bloomberg.com/news/articles/2019-04-03/millions-of-facebook-records-found-on-amazon-cloud-servers-ju1hde0w https://www.bloomberg.com/news/articles/2019-04-03/millions-..., which appears to be a summary of that.
- nerdjon 8y agoOne hell of a clickbait headline. Since it is more fallout from the previous data handling issues and not further screwups on Facebook's part. Not to downplay the issue... but its clearly written clickbait
- dang 8y agoWe've changed the URL to the study the article is reporting on, which also provides a cromulent title.
- throwaway5752 8y agoNot clickbait in the slightest. This is not about Facebook per se about persistence of their shared data - my information - once it's made public. HIPAA, by comparison has all sorts of statements about PII and business associates. But apparently FB can share with whoever has a pulse and I can find out about it later via Shodan. I wrote this even with the original link and version of the headline.
- nerdjon 8y ago"Millions of Facebook Records Found on Amazon Cloud Servers" was the original headline. That headline the first thing you would likely think is Facebook was using AWS and left some data open somewhere. It 100% implied Facebook was doing more wrong now, instead of the companies that already had the data from the previous issues were not handling the data correctly. Yes this news is still notable. But the headline gave the wrong impression and was banking on the already bad attitude towards Facebook.
- deleted 8y ago[deleted]
- 4werfaw34r 8y agoI swear, every HN article, you get 10% of the comments are about the article being discussed, and the other 90% are people quibbling over the headline. Ok, that's an exaggeration. And when the comments are good, they are really good. Makes the entire HN experience worthwhile.
- DoreenMichele 8y agoTitles R Hard.
- throwaway5752 8y agoSo sorry? I mentioned Shodan as a way of tying it to other leaks of negligence and I why I thought this was relevant, and not just a tossaway clickbait article. I think my disagreement is deeper in nature than semantic on the headline. I even dropped in HIPAA as a model for regulations of shared private info, as gross as it may be to think about in a regulatory sense.
- mattnewton 8y agoEh, I don’t really care if it is a failure on the point of Facebook engineers or a failure on the point of Facebook data policy that allowed other engineers to post data about me in an insuecure manner. Seems like splitting hairs here.
- miki123211 8y agoAny way to access the full article anywhere? It shows to me as "more information available on the Bloomberg Terminal"
- drak0n1c 8y agoThe link has since been updated to be the original UpGuard research source.
- taytus 8y agoAnecdata: A couple of years ago, I was at one of the very first (not sure if not the only one) FB connect meetings here in Dallas. A couple of local startups were talking about how to leverage the "login with facebook" button. It was a big thing... Most people I talked to, told me: "The very first thing I do is to save all the email of their friends" or stuff like that. So yeah, this was years ago. I'm failing to see how this is a surprise at all.
- fixermark 8y agoUnfortunately, Facebook had a fundamental misunderstanding of how privacy has to work, and their users will be paying for their error for years. If it's earth-shatteringly bad for your users if their private data is leaked by a third-party, you cannot exfiltrate that data to a thrid-party. Full stop. No amount of policy un-leaks data, and "You cannot continue to operate as a Facebook service" is an empty threat the moment it becomes more valuable for the third-party to violate the agreement than to continue to operate as a Facebook service. The takeaway: if you are responsible for user privacy, you must do the computations on the user's data. Have partners ship you the computations they wish to do, vet them, and then ship them results compliant with your users' expectations. Don't hand third-parties a subset of the keys to the kingdom and expect an honor system to preserve user privacy.
- throwawayjay01 8y agoHow would this work in the case of data portability? If Facebook were to be forced to provide an API that allowed users to export all of their data to a competing social network would Facebook be responsible for ensuring that the competitor was using the data responsibly?
- fixermark 8y agoNot at all; they'd be responsible for bundling that data in a well-defined format into a blob of some kind that the user can request be exfiltrated (after providing their credentials to authenticate the request). The third-party would then have to digest said blob. Users assume trust of the third-party regarding responsibility for data misuse when they feed the third-party the blob (same as if they'd hand-entered the data via a regular GUI). Google already offers a functional model of this via https://takeout.google.com https://takeout.google.com Putting control in the hands of the user is quite different from allowing third parties to exfiltrate data on a user without their consent. (It is worth noting that this approach is still exploitable---third party convinces users to cough up their authentication codes, then acts as the user and makes the request for the whole kingdom themselves. But user education on the amount of power handed to someone when you literally give them your passwords is a separate issue).
- jrochkind1 8y agoWait, how the heck did "At the Pool" get plaintext fb passwords?
- ChrisCinelli 8y agoThey did not. I think those are their own passwords if the user used directly the app without FB login
- seandougall 8y agoNot to discount the possibility that the article could be incorrect about this, but it makes the claim quite unambiguously: "it contains plaintext (i.e. unprotected) Facebook passwords for 22,000 users"
- traek 8y agoThey have updated the article to say > it contains plaintext (i.e. unprotected) passwords for 22,000 users and > The passwords are presumably for the “At the Pool” app rather than for the user’s Facebook account, but would put users at risk who have reused the same password across accounts.
- jrochkind1 8y agoThanks for clearing that up, didn't say that when I read it, indeed, it originally said "Facebook passwords".
- sucrose 8y agoWell, the 2nd paragraph explains that: "The passwords are presumably for the “At the Pool” app rather than for the user’s Facebook account, but would put users at risk who have reused the same password across accounts."
- socialhack3r 8y agoThis other article that got posted today might explain why this happened in more detail: https://medium.com/@six4three/deceit-by-design-zucks-dirty-secret-he-doesn-t-want-you-to-know-67dcc94e2b5d https://medium.com/@six4three/deceit-by-design-zucks-dirty-s... Seems to suggest that FB platform apis were designed to not share any privacy metadata with devs. Maybe not the same as how apps like At The Pool stored that data, but might explain the firehose of data that FB gave devs and now they will point the finger and say it was their fault for these leaks/breaches. Food for thought.
- lacker 8y agoDevelopers would have to intentionally write extra code to respect privacy metadata, so it seems unlikely that would have made a difference.
- socialhack3r 8y agoOh jeez. So you think that medium article is accurate? It would be pretty nuts if what they are saying is true. Makes something like Cambridge Analytica and whatever happened today with At The Pool be a question of "when" and not "if" when it comes to the leaking of FB user data.
- socialhack3r 8y agoCriminals seem unlikely to follow laws, so why bother having them? Of course devs would need to intentionally follow the privacy wishes of users but without metadata, even responsible developers who want to, can't. I guess my question for you, considering it looks like you worked with devs at FB, is this article regarding FB platform design accurate? That's the most shocking thing to me that this article conveys, that even if you wanted to ensure data privacy as a dev, you couldn't unless you built a custom tool. I'd be pretty surprised if most (or any) would. Curious on your thoughts.
- ChrisCinelli 8y agoBetween 2007 and 2009 it was a far west for Facebook apps. A gift app that you could write with about 100 line of code could reach 10 millions of users in 2 days. More complex apps could do better. That was the most amazing part. At that time the Facebook's API was pretty much open and you can get everything. It was an experiment and Mark Zuckerberg had a lot of hope in what people could do with that data to add value to the users. I was not doubting that he was doing it with good intentions. But he was naive... Unfortunately, most of the apps were abusing all the channels that Facebook was giving them to get more users and milk money out with ads and micro-payments (ex: through OfferPal Media - now Tapjoy). During that time I was pretty surprised how much info people were giving away with a click through. Even on the main Facebook product people were posting all kind of stuff, including stupid things they were doing. It really seemed that people were becoming more open and it was the beginning of a new era for privacy (or lack thereof). Facebook realized pretty quickly what apps were doing and they started adding more granular permissions. Eventually Facebook started limiting more and more access to the API until 2011/2012 when the user generating gold mine was pretty much gone. Again, Facebook has always been working to fix the experience for their users and also to make clear that those where 3rd party apps. But people did not really care. There have been probably hundred of thousands of apps that had access to "sensitive" user data. According to the Facebook's Term of Service, data could not be stored for more than a certain amount of time. But nothing was technically preventing people to store that data forever... And here we are...
- AdmiralAsshat 8y agoSince there are many anecdotal reports of Facebook failing to delete the profile history data even after closing your account, is there a better way people should be scrubbing their data? Some kind of tool, perhaps, that edits all of your posts and replaces them with scrambled / gibberish text?
- deleted 8y ago[deleted]
- libso 8y agoFacebook sure as hell won't create such a tool. If you do, open source it and I shall use it for sure.
- orev 8y agoThey could easily be keeping a history of everything, so while this would affect the final version of the item, it wouldn't delete the history. The data would still be there for them to mine, and to be stolen.
- ghssji 8y agoI don’t really get it. Isn’t the opposite of this (restricting third party developers) exactly what people are furious at Twitter over, for killing Tweetbot etc.?