4 ms·
There's a lot of very obvious "didn't bother reading the article but I'm going to comment on the headline" behaviour in this thread. FB users put their details
by cmdshiftf4 7y ago
There's a lot of very obvious "didn't bother reading the article but I'm going to comment on the headline" behaviour in this thread.
FB users put their details on their publicly accessible FB, someone ran a scraper across FB for publicly accessible info and dumped it into an insecure elasticsearch cluster and a researcher found that cluster.
How is FB at fault there? I say this as someone who has colossal issues with that company in general.
- daddylonglegs 7y agoFacebook have a history of making settings default to little or no privacy, making those settings obscure and difficult to set, and changing those settings and their defaults faster than most people can keep up. This data dump is the not at all surprising result of Facebook's policies. I remember the Zuckerberg family being caught out by Facebook's settings over a photo and complaining when the photo spread: https://gizmodo.com/randi-zuckerberg-is-just-as-confused-by-facebook-privac-5971227 https://gizmodo.com/randi-zuckerberg-is-just-as-confused-by-...
- cmdshiftf4 7y agoI'm not sure I agree. I've had a FB profile, that I admittedly don't look at often, which I've had set to private for its duration and can't remember a time where I've had to jump into the security settings to change something due to my private information suddenly becoming public. We can argue that the core UI is trivial and hence non-technical people jump on and essentially make user errors, but I'd be inclined to put the onus on people using a private platform to host their private information to ensure they've set up their account in a way that reflects the settings they want. Don't get me wrong here either, if someone hacks a platform and extracts private information, or if the platform's infrastructure is misconfigured and exposes private information, then by all means I want the company responsible held account. Which is something that currently does not really happen. I'm just hesitant to blame FB for users misconfiguring their accounts and alien actors taking advantage of that misconfiguration.
- daddylonglegs 7y agoI disagree, this seems to require users to read and understand the EULA, navigate all the settings (and again each time they change) and have a high degree of information op-sec for the things that aren't mentioned in the EULA or settings (such as 1 pixel tracker images on third party websites). This would have to be done for each and every service you come into contact with. People may not be able to opt out of these services. Many people will buy phones and devices and, when they receive them, discover that the Facebook app and similar apps are pre-installed and cannot be removed. Additionally, here in the UK many schools use Facebook to communicate important information to parents. Even without semi-official requirements, the effect of so many people and organisations running social interactions through Facebook means that people have little choice but to join themselves. I think we need both legal requirements and social standards about how these things are handled to make things like Facebook safe by default, not safe if you and the people you know put effort and expertise into controlling your exposure. PS. I haven't downvoted your comments, I don't know why one of them looks to have been downvoted.
- davvolun 7y ago> Diachenko believes the trove of data is most likely the result of an illegal scraping operation or Facebook API abuse by criminals in Vietnam, according to the evidence. The only ones capable of preventing either the scraping operation or the API abuse would be Facebook. Scraping is an arms race, but I certainly don't trust Facebook to care about protecting my data, except where it would infringe on their ability to sell it. If it's "API abuse," that's definitely on Facebook to prevent.