6 ms·
Facebook now says its password leak affected ‘millions’ of Instagram users
- codequeen 7y agowhat a complete mess
- hw 7y agoA mess is probably an understatement. I've been wrestling with them for turning off access via their Graph API to a public resource on a Page where the Page has access to that resource, and their rationale was due to the great privacy changes they're making to protect users privacy. While they're busy breaking the apps that businesses rely on to manage their Facebook Pages (without prior notice, ala the whole Instagram API fiasco), they aren't protecting the one thing that allows access to a user's privacy - passwords.
- hw 7y agoSo Facebook "determined" that the passwords were not "internally abused" or "improperly accessed". But, they could have been accessed. When employees have access to passwords, how does FB know that they were not transferred outside of FB? An employee could have taken pictures, or have a photographic memory and remember a large number of passwords.
- orev 7y agoIf they were sitting in a log file somewhere, you could probably audit who had accessed them. The file permissions might have allowed access, but the audit logs could show that nobody did. P.S. I have no knowledge of what actually happened.
- tptacek 7y agoHow do you know that the platform engineers at Instacart haven't surreptitiously inserted a memory debugger into their app servers and recorded all the passwords people log in with? Does that sound far fetched to you? It's something teenagers have done for fun.
- zeko1195 7y agoThis would never happen at Amazon and I am sure at every other major tech company. There are systems in place to prevent exactly this.
- s3buckets 7y agoFunny that you mention Amazon, because open S3 buckets have been implicated in dozens of security breaches. It's not so much that Amazon is the culpable party in those instances, but so many times, have I encountered a headline citing a "massive exposure of protected data" and somewhere in the body of the article, someone had dropped everything into an S3 bucket marked open read for public everyone. So, is it Amazon's fault? This sort of thing was an FTP server thing, before S3 reduced the hardware infrastructure overhead of setting up and maintaining your own secure FTP server... But, then again, lowering the technical bar meant letting in more and more non-experts, and naive, or otherwise less competant people. This, of course, broadens market penetration, and increases revenue. So, to add barriers, irritating warnings, nanny-goat advisories, hazard alarms to such a versatile and useful product might seem tantamount to leaving money on the table. After all, the goal of the product is ease of use. And, by the way, how does one solve the problem of bone-headed users? But, you know, there's the real distinction between an AWS S3 data breach and a Facebook data breach: with S3, you've shot yourself in the foot. Facebook, on the other hand, is pointing a gun at you.
- tptacek 7y agoI don't know enough about Amazon to call bullshit on this, but I do know enough about other major tech companies to call bullshit on this.
- OrgNet 7y agoWhich other large company store plain text passwords? How long before they start trying to re-use the passwords to log in other services without your consent
- ceejayoz 7y ago> Which other large company store plain text passwords? That's not really what Facebook is saying they did. They accidentally logged passwords to a log file somewhere. They're not saying they stored them in the users database in plain text.
- sudhirj 7y agoI really want to be a fly on the wall at the meeting where the inevitable "you shouldn't have done this" statement is countered with "but you said we should move fast and break things".
- krupan 7y agoWe have had the cryptographic technology for year that allows us to authenticate ourselves to third parties without giving them secret information. Why are we still using passwords?
- tptacek 7y agoI will say here what I said on security Slack just a few minutes ago: Security people see shit like this all the time. Facebook found a raw request log, which inevitably contained lots of passwords. Rather than doing what most tech companies would have done --- delete the log and pretend nothing ever happened --- they disclosed the log in a fashion that guaranteed a whole news cycle about it. I don't like Facebook. Facebook is bad. But Facebook handled this about as well as I've seen anyone handle this. Cheers to them for that. This story is not a good reason to single Facebook out.
- crescentfresh 7y agoAs a very large and very public tech company, they assume they have whistleblowers' eyes on anything that gets discovered, even internally. I assume they go public with it precisely so that no one else can do so first.
- ceejayoz 7y ago> they disclosed the log in a fashion that guaranteed a whole news cycle about it 1. Aren't they legally required to under GDPR? 2. Let's not give them too much credit. They updated an old blog post on the day the Mueller investigation report got released.
- deleted 7y ago[deleted]
- iidzy 7y ago>Aren't they legally required to under GDPR? Yeah, if they get caught. Which they don't have to be.
- ceejayoz 7y agoA fine of 2-4% of global revenue seems like an insanely high risk to take here.
- wglb 7y agoIt is more like if they don't respond, repeatedly. Also, it isn't clear if there is PD (Personal Data) there--just a password would not be enough to identify a person. If it were in combination to user ID or email, it would be.