9 ms·
Facebook does not plan to notify half-billion users affected by data leak
- darig 5y agoDo your thing Europe.
- sigmonsays 5y agohow is this acceptable? i'm glad I quit facebook long ago but this angers me for the people who dont stay up to date on security breaches.
- iso1631 5y agoFacebook today closed at a record high of 309, up from 299, on the first trading day after this leak hit the press. It has since increased to a higher record high (currently 312 with 10 minutes left)
- 1-6 5y agoWall Street fueled by Jim Cramer's FAANG doesn't care about consumer privacy.
- deleted 5y ago[deleted]
- Cookingboy 5y agoBecause Wall Street realizes even consumers don't care about consumer privacy. If Ashley Madison and Equifax walked away with barely a scratch from their catastrophic breaches, then this is almost nothing in comparison.
- pmlnr 5y agoI genuinely don't understand how Equifax is allowed to exist post-hack.
- mandmandam 5y agoSo what? Failure to disclose is illegal many places for good reason, and the relevant authorities are the ones who need to be doing shit about this. No one expects consumers to regulate other areas, why tech?
- newswasboring 5y agoI think people do care, its just impossible for them to express how much they care. Like I want to do something about this data breach, what else can I do apart from remove myself from facebook (there is good evidence that that wouldn't help me either)? Its a monopolistic market and they are very good at hiding the risks. People don't accept random spam and data leaks out of not caring, but because even if they care the current business models will not care about their opinion.
- m12k 5y agoWhat's the maximum fine under GDPR? It's some percentage of global revenue, right?
- pilsetnieks 5y ago4%
- grenoire 5y agoPriced in, as usual (not even meme-ing).
- blackearl 5y agoWasn't this leak already 2 years old? Just because the media decided to pump it up this week doesn't mean it just happened. I've also yet to see anything real come of these kinds of leaks.
- omnimike 5y agoGive that the data leak is 2+ years old I’m wondering why it’s getting so much attention in the media right now, just as FB hits record highs. The cynic inside me suspects that this is actually a ploy to manipulate the stock price, though I can’t tell who would benefit from it.
- iso1631 5y agoBecause the data is now widely available to anyone and his dog
- 1-6 5y agoSometimes I wonder if the data from the cameras on my Oculus Quest 2 is being sent to FB's servers and kept. I guess I'll never know.
- fshbbdssbbgdd 5y agoIt’s going over your wifi, right? To start, you could evaluate whether the upload bandwidth could fit a video signal.
- shock-value 5y agoI think there is no doubt it isn't uploading a raw video signal. But all kinds of things could be derived from that video and uploaded.
- dkarras 5y agoIf you enable hand tracking (without controllers), they explicitly notify that they are collecting data about your hands. Combine that with your arm length, hand size / shape, height and I bet you'd be pretty unique. If there aren't enough bits, data about "the way you move" or stand, general posture etc. would be more than enough to identify you I believe. A simple DNN can eat that data like breakfast. I don't care much but it is interesting nonetheless.
- m4rtink 5y agoIt's a powerful device with superb cameras & sensors, used to play user specific content, running totally unauditable code, connected to the Internet and requiring a real identity account to even start. What could possibly go wrong.
- fshbbdssbbgdd 5y agoI can’t wait to plug it into my brain stem!
- dmitrygr 5y ago
- amacalac 5y agoYeah, can you imagine them having to tell Zuck his number got leaked. He's gonna be furious! Source: https://www.androidauthority.com/mark-zuckerberg-signal-1215333/ https://www.androidauthority.com/mark-zuckerberg-signal-1215...
- imoverclocked 5y agoI guess his users can now call him directly to air grievances over data leaks.
- adamsvystun 5y agoThis is disappointing. Admitting the mistake is crucial in the process of fixing the problem. This just shows that they have learned little after all the company has been through.
- dylan604 5y ago>This just shows that they have learned little after all the company has been through. This is just yet another example of that. It's not like we didn't realize they don't care until this instance. It's hard wired in the DNA, and this is just more evidence of that.
- claaams 5y ago"Zuck: People just submitted it. Zuck: I don't know why. Zuck: They "trust me" Zuck: Dumb fucks."
- MattGaiser 5y agoAdmitting the mistake, not admitting the mistake publicly.
- smsm42 5y agoThat implies they see it as a problem that needs to be fixed. But what if they don't care? After all, their business is collecting and selling these data. It being copied by somebody looks bad, but advertisers probably won't do downloading user lists on darknet, so the damage to the main business is minimal. And people still on Facebook don't seem to be willing to punish Facebook for violating their privacy, so...
- mrweasel 5y agoWon't that get them in trouble in the EU? I had to check, but the GDPR was implemented in 2018, and the leak was in 2019.
- benja123 5y agoIt’s not clear which leak the data is from. From the articles I read there were two leaks that the data may have come from. One in 2018 and one in 2019.
- drusepth 5y agoIn either case, it seems like they would have notified users (if at all) when they were alerted to the leak and fixed the vulnerability.. not 2-3 years later.
- yepthatsreality 5y agoThat’s fine. This has pushed me to close my last remaining account with them in the next 24 hours, so they won’t need to send me a breach notice after they’re sued for it. Thanks Facebook admin for the encouragement to speed up my plans!
- throwaway122378 5y agoWhen will our elected officials focus on new laws for new challenges. Our digital “bill of rights” is long overdue
- woudsma 5y agoAnd they apparently also didn't plan on deleting my PII (phone number was in the leak), even after I permanently deleted my account at FB over 3 years ago. I thought I had the 'right to be forgotten' because of the GDPR, as I'm a European citizen. Has there been any real enforcement of these laws aside from the relatively small fine here and there? I've been blocking FB actively for the last few years, I can't even visit FB because of my /etc/hosts file setup. It seems quite impossible to get back some privacy online even though I try and take measures. Use Duckduckgo, Brave browser, VPN, no social media, etc. I was a happy person when GDPR first came through.
- aminozuur 5y agoThe data was scraped years ago and just released now. Only the things you shared publicly already, such as your first and last name on Facebook, were "leaked", except for a few private phone numbers.
- woudsma 5y agoI've never had public profile information. Only visible for friends (and my phone number wasn't even visible there). How would my private phone number get into that dataset? That would suggest that they have more than just public data.
- nuclear_eclipse 5y agoYour friends can (and almost certainly will) share their contact info (including your name/phone/email) with Facebook , Messenger, or Whatsapp, even if your account is deleted and doesn't exist.
- t0mas88 5y agoIf you're in Europe you can file a complaint with your local data protection agency. They will definitely already have some investigation on Facebook so this just adds more to it.
- 5y ago
- dylan604 5y agowhy would we need to? it's all of the news, so the people have been notified. --Facebook
- Muromec 5y agoWhat is really strange about this data leak is what is missing in it. I see at least two countries that aren't there.
- benja123 5y agoTo be fair I don’t think I have ever been notified by any company when my data has been leaked and according to haveibeenpwned that has happened quite a few times. I am not a lawyer, but I find myself wondering if they are binded to GDPR in this case as judging from online articles the actual “leak” itself may have happened prior to May 2018. It also maybe that the nature of the PII itself is not such that it needs to be reported to the users (no passwords, private messages etc...)
- cdolan 5y agoI have been notified many times by reputable firms that my data has been taken, even if it was just a password. Most of the stuff that I appear on havibeenpwned for is some strange data brokerage that probably grabbed my data from another hacked brokerage, etc
- deleted 5y ago[deleted]
- erellsworth 5y agoDoesn't this mean they will get fined out the arse by Europe under the GDPR?
- Red_Leaves_Flyy 5y agoWho's going to blink first though?
- erellsworth 5y agoGood question.
- type0 5y agoIt doesn't and they know that.
- Johnny555 5y agoAren't they required to disclose this, at least to California residents, under California's data breach disclosure laws? Or was it not the type of PII covered under the law?
- nolok 5y agoIn EU law too. Booking.com just got convicted half a million just for notifying TOO LATE (two weeks after the fact). I assume they expect to claim it's not a fb leak in some convoluted way, otherwise I don't understand that move. Oh wait, weren't there also shadow numbers in this ? Aka you had my number you uploaded it so it's in the leak even though I had no relation to them ? Might be why, they have no right to contact me to warn me
- pmlnr 5y agoYeah, but the b.com leak involved credit card data which changes everything in the eyes of regulators. Sadly this is not true for "mundane" data like phone numbers, email addresses, or even physical addresses.
- sofixa 5y agoIn regards to GDPR, personally identifiable information is the main focus.
- t0mas88 5y agoThey are absolutely required to report this to the data protection agencies in all European countries. As the other comment mentioned, missing the 72 hour deadline on this is enough to get a fine as Booking.com did. I'm curious to see the total in GDPR fines from this for Facebook. Will probably take a year or two before we know.
- nerbert 5y agoAt this point they must be like a deer in front of the flashlights, hoping the car will dodge them.
- 2pEXgD0fZ5cF 5y agoYou can count on the people at Facebook to do the wrong thing
- hetspookjee 5y agoSo it wasn't too long ago that the news got head of the Facebook "Supreme Court" that is supposedly even above mr Zuckerberg. I wonder what would happen if you'd appeal to them about this blatant disregard of sovereign laws worldwide. I don't know a single country that does not have some law in place forcing the leaker to notify the user. Obviously barrely any country does it, and if so, Booking just got a laughable 400k fine in the Netherlands for not notifying in time (though they eventually did just too late). I'm sure Facebook will get away with it. One thing I've learned s that theirs barrely a better time to buy big tech stock when they've announced a data leak. Though others seem to have caught on with that sentiment as the stock has been rising.
- varispeed 5y agoEven if a country decided about doing something about it, would they risk Facebook blocking that country altogether? Facebook has so much money, pretty much any fine will be just a slap on the wrist. What else they can do without causing public to go mad? Capture Mark and make him do time?
- bassdropvroom 5y agoSo after longing it out, today I had a look on haveibeenpwned, and it seems I am one of those whose data has leaked. After re-reading all of the events of this breach, it seems that the exploit was fixed in Aug 2019 (as claimed by Facebook). I had deleted my account some 2 years prior to that. Either these attackers have had access for over 2 years, or Facebook has not deleted my data, and likely everyone else's data either. What can an individual, or perhaps everyone affected, do in this scenario?
- nuclear_eclipse 5y agoAssuming that the data is just your phone number and name/email, is it not possible that this is just from friends who have allowed Facebook and/or Messenger to share contact info? Your original account data almost certainly would have been deleted/purged due to various regulatory requirements, but that doesn't necessarily stop your contact info from being shared again and making its way back into the system.
- sorokod 5y agoBut then again, Occam's razor would suggest that FB never deleted the data in the first place. By the way, data is not "making its way back" like some sort of salmon trying to get back to the source, it is forcefully harvested by FB.
- nuclear_eclipse 5y agoPresenting a screen/dialog to the user at first login asking for permission to access contact data does not sound like "forcefully harvested". Users rarely understand the consequences of their decision, which is why I would love to see iOS and Android eliminate the option of wholesale contact access, but use of Facebook apps is not predicated upon receiving your contact data.
- atat7024 5y agoIt does if your average user is so uneducated they freeze up and whack the next button until the screen with all those words on it goes away.
- scottmcleod 5y agoA scrape is not a leak
- pmlnr 5y agoWell, FB doesn't allow me to export my own contacts' details - email, phone number, etc - with it's data export, so no, this is a leak.
- varispeed 5y agoThat's what I thought. GDPR was created mainly to spend tax payer money on thousands of meetings, lawyers, dinners, conferences and whatever else was possible just to tick few boxes, give people false sense of security and pat themselves on the back while salivating over buffed up bank accounts. For such a blatant disregard for the law, surely they should have been fined by now? Given that they can just exist like that it seems to me they are probably selling or supplying governments with information about citizens, so they may be above the law because of that.
- auiya 5y agoFacebook is probably also not planning to pay out hefty fines for GDPR violations, but alas...
- Imnimo 5y agoMaybe they could save time by notifying the people who were -not- affected.
- anonu 5y agoIf you use the internet your name and phone number is going to be out there eventually. There's not much you can do. Not saying things can't be better. But at this point in time, your name and number should be assumed not to be private.
- paulpan 5y agoAs others noted in the other thread (https://news.ycombinator.com/item?id=26736285 https://news.ycombinator.com/item?id=26736285), the correct action here would be a punitive fine by FTC or FCC for 1) the size of the leak and 2) that FB is refusing to notify impacted users. Something to the tune of $30-50B, to also send a clear message to all other companies. In this case, FB appears to have sat idle since previous $5B fine for the Cambridge Analytica fiasco. So 10X that previous fine would seem appropriate. Long term, holding the leaders and board of companies criminally liable for user PII and data leaks (similar to SOX compliance) might be the best solution. The reality, however, is that no such regulation will occur and companies like FB can continue to lackadaisically treat user privacy and data security.