4 ms·
So Facebook "determined" that the passwords were not "internally abused" or "improperly accessed". But, they could have been accessed. When employees have acces
by hw 7y ago
So Facebook "determined" that the passwords were not "internally abused" or "improperly accessed". But, they could have been accessed. When employees have access to passwords, how does FB know that they were not transferred outside of FB? An employee could have taken pictures, or have a photographic memory and remember a large number of passwords.
- orev 7y agoIf they were sitting in a log file somewhere, you could probably audit who had accessed them. The file permissions might have allowed access, but the audit logs could show that nobody did. P.S. I have no knowledge of what actually happened.
- tptacek 7y agoHow do you know that the platform engineers at Instacart haven't surreptitiously inserted a memory debugger into their app servers and recorded all the passwords people log in with? Does that sound far fetched to you? It's something teenagers have done for fun.