7 ms·
A Facebook engineer abused access to user data to track down woman
- stevespang 5y agoHeh, so Zuckerberg's baby is now enabling predators and stalkers ? I smell lawsuits going for the very deep pocket of Zuck . . . .
- rvz 5y ago> from 2014 to August 2015. Everyone here is unsurprised by this and at this point I expect the social networks to just abuse my user data anyway. They won't change and they will never stop this. Who is to say that this is already happening with the other social networks that are scooping up our data but in 5 years time will only admit their actions afterwards. Maybe they are all doing this as we type. To Downvoters: So you think that these social media companies are NOT abusing our data? There's tons of evidence of this everywhere, including this confession. There can only be one explanation of why I'm getting downvoted heavily of an undeniable known fact and it is likely that it is by those working at these companies because they know that I am right and the point still stands regardless of any downvotes (and censoring of the truth).
- GrumpyNl 5y agoCompany i used to work for gave almost every employee full access to the db through phpmyadmin.
- agumonkey 5y agoWas it a social network thing too or a totally different market ?
- Cthulhu_ 5y agoI don't think it actually matters much; your database is your core business and access to it should be restricted. Same as your machines. To the point where, if you have everything set up right (which is a big if, granted), NOBODY should need physical access to ANY machine or database. All access through the application's management interface, where access can be finely tuned and access logs can be used to hold people accountable.
- agumonkey 5y agoit was mostly a question of scale, that a business mishandle 500 customers data is one thing, but 100k feels different to me.
- meowster 5y ago"Almost every employee" could just mean 1 of 2 which is not a big deal, or 99 of 100 which is a big deal.
- junon 5y agoThis is a pretty widespread issue I'd imagine, we just don't hear about it or people aren't caught. I know they've been locked down since I've left, but some of the tools we were allowed to just freely access at Uber were a tad scary, to say the least. I'm sure every company with a very large userbase, such as Facebook/Microsoft/Google/etc claim they have internal protections/checks but have even more holes like this.
- aaronmdjones 5y ago> At the time, more than 16,000 employees had access to users’ private data, according to the book. > Stamos suggested tightening access to fewer than 5,000 employees and fewer than 100 for particularly sensitive information like passwords. I'm sorry, what? I can tell you the number of legitimate engineers that should have access to user's passwords. It's a nice, round number. It's zero.
- mothsonasloth 5y agoOr one step further, the passwords are hashed and salted using a encoding spec like BCrypt. Any employee logins are done through skeleton keys that are audited.
- Guest42 5y agoIs it not possible to only have the hashes or does it have to get persisted somewhere in the process?
- pm90 5y agoOnly the hashed versions should ever be stored. Like the OP said there is Zero reason to store plaintext user passwords.
- actually_a_dog 5y agoIMO, it's likely that the article was confusing "passwords" with "hashes" here. No company the size of Facebook is going to be storing plain-text passwords in 2021.
- dylan604 5y ago"No company the size of Facebook is going to be storing plain-text passwords in 2021 on purpose." We've seen stories where the servers were logging the plain text data it received where those logs persisted for some time, but the plain text was never "stored" in the database.
- 5y ago
- HumblyTossed 5y agoI would not be surprised if this was common. I simply don't have enough faith in society today to believe that most people would understand how wrong this is.
- Drybones 5y agoI was on vacation in Egypt, this year, with a guy who worked at Facebook, along with a fairly large group of us from the States. He would stalk people's Facebook profiles in our group to find out information on them and even confront them about it, if they made him upset enough. He even messaged them directly on Facebook to tell them off. As a side note, he was mostly only interested in having hook ups and orgies with Ukrainian tourist women, while in Egypt, made even more bizarre when we found out he has a wife back in the United States, of which, worked at Apple. He was not a well liked guy and he was very rude to the Egyptian natives, especially towards the Bedouins.
- danlugo92 5y ago"Ukrainian women in Egypt" sounds like a pretty niche segment to go after.
- api 5y ago"You don't have anything to fear unless you have something to hide..." I bet this is incredibly common, and far more so at lower profile and even shadier surveillance capitalist companies.
- emtel 5y agoI worked at Facebook for most of 2017 and 2018. In the first week, they made it clear that you would be fired instantly for any improper access of user data. They further said that if you need to access any sensitive personal data, or if you need to log in as a user in order to debug a problem, you need to have approval from your manager _before_ the access, not after. Also, you are not allowed to access the data of anyone you know personally for any reason whatsoever. You have to find someone else to do that if it needs to be done. Finally, they really do audit every single access of personal data. I had every reason to believe that if I accessed any data improperly, I would be fired within the week if not the day. I don’t know how much abuse still exists despite all of the above, but I don’t think this article does a good job of explaining how seriously Facebook takes this.
- harrisrobin 5y agoThe issue is that this is even a possibility. It should not be possible to access user data, even if a manager approves it.
- pm90 5y agoThere’s a difference between having an audit trail and actually using it. I would be interested to know how often Facebook analyzes this data and actually fires people for improper usage.
- flak48 5y agoThe article does mention more than 50 people being fired for it between 2014 and Aug 2015
- emtel 5y agoI don’t have proof, but we were told that every access of sensitive data was actively audited. It’s very rare to need to do this for your job, so I don’t imagine it’s a huge volume of events to be audited.
- mtmail 5y ago> I would be interested to know how often Facebook analyzes this data and actually fires people for improper usage. From the article: Facebook fired 52 people from 2014 to August 2015 for abusing access to user data
- pm90 5y agoTotally unsurprised by this. Where I used to work, user activity/transactions data sent to us would be stored on a single giant nfs volume. If you were added to a Linux group you can full, unaudited access to everything. Whenever someone tried to build anything that would restrict and audit access there would be a ton of pushback from engineers and customer support who loved being able to ssh into a machine and have full access to everything.
- _jal 5y agoNot uncommon in early-stage startups. I've learned to build these sorts of things with access control and auditing up-front, but certainly have built my share of attractive nuisances over time. My advice is stub something out up front, before you go to production. You don't have time to do it right, but you do have time to establish the norm. Even if your audit trail is just a two-minute DB trigger that records that Worker Bob changed Customer Alice's password yesterday at 11, make it clear that there needs to be an articulable reason at hand for having used mechanisms that may violate users' trust.
- Taylor_OD 5y agoThis is so common. Think of any start up you gave way too much info to. They have lots of lower paid employees who can look at that data. It happens a lot.
- protoman3000 5y agoAt this point, why not just make any of this social media information public? What’s the difference to more than 16 000 people knowing with whom you cheated vs. the whole world knowing? By 6 degrees of Kevin Bacon there surely is a connection to one of these 16000 people in your bubble, hence the secrets are theoretically out, too. Why should they have the advantage over you and potentially blackmail you? /s
- mrits 5y agoThere is 0% chance this article is correct. No employees at facebook had access to passwords for obvious reasons. Someone is trying to sell a book.
- sschueller 5y agoDoes anyone remember Uber's "god view". That has privacy violations written all over it, I wonder what happened to it.
- staticassertion 5y agoIn a sane world this would be a company-ending event, or at least seriously impact their stock and C level execs. The idea that: a) User data access is not just allowed but normal (or at least that it was at one point) b) That it's allowed at all so widely c) That (a) and (b) are true despite repeated abuse is absolutely insane. "Nearly every month" is insane. It should be criminal, but it isn't. Sadly, it's all too common for engineers to have way more access than is necessary, though this seems extreme. I see no reason why any engineer, outside of extreme circumstances that should set off alarm bells, should have access to sensitive user data like passwords. It should generally not be the case that direct access of data is needed at all.
- cmrdporcupine 5y agoPretty inexcusable by 2015. FB was hardly a new company at that point. Every Googler gets the message that you keep your mitts off private information in logs (or get terminated) drilled into them in their first week of training. Logs access is a) restricted b) audited c) tiered and d) enforced. That was the case in 2011 when I started and it's the case now. Not saying Google is perfect, but it's not like companies like FB didn't have a template for privacy standards that they could have followed. All that said, but back then I just personally assumed that this is how FB was operating :-( I am hoping they've improved since.
- underseacables 5y agoI know an engineer, a security engineer at Google who is pretty well-known, who went to work at Google specifically so he could get at peoples personal data. I don’t know if he actually does it, but he boasted quite openly for years that he wanted to be the “architect“ and see everything and know everyone’s secrets. He is now a highly placed Google security employee.
- cghendrix 5y agoThat’s pretty disturbing.
- sthatipamala 5y agoIf that was his plan, he picked the entirely wrong company to accomplish it. There are many layers of access control at Google that would make that impossible regardless of how highly placed he is. He'd be better off at a smaller company with less mature security tools.
- jeffbee 5y agoThere are no “architect” roles at google. Most people outside anti-abuse roles have no access to user data, and even the abuse people use audited frontend tools that formalize the policy that the viewer must reference the ticket they are working on and the limited data they need to see. People with direct access to production data streams mostly see encrypted data. There’s a big, annoying technical scheme in place to make sure private or sensitive data is elided whenever a message is printed in plain text to a log. It stretches from the protocol compiler all the way down to C++ stream operators. I’m not saying nobody ever sees user data. Sometimes you need to find out why an email is crashing the mailer. But those accesses are limited in scope, auditable, and available to relatively few people. In my opinion it isn’t really the Facebooks and Googles of the world you need to worry about, it’s the companies with massive collections of user data and without the technical chops to protect it. Like Dropbox.
- deleted 5y ago[deleted]
- bobthechef 5y agoShe should sue Facebook. This industry has no will to change. It must be coerced. Ideally, your data should be encrypted and no one at Facebook should not have access to it. Only those people whom you have chosen to then share that data should have access to the degree given (crypto wise, maybe this means you decrypt and broadcast to those people like email). Any reason why a Proton-like model wouldn't work for technical reasons? Facebook could still make money off ads, but those ads would be less targeted. Good. We need less targeting.
- smalltarget 5y agoSo this is just FB. Imagine what other services engineers and employees can abuse to lookup personal information of people they know.
- iamalexa 5y agoA lot of the commenters here are rightly not surprised about this. A few years down the line this is going to be a similar thing with voice activated devices like Alexa. Employees, contractors, advertisers will all have access to the voice data of not just the person using these devices but of those who just happen to be in the vicinity. And no one will be surprised about it.
- caseysoftware 5y agoWhile Facebook has a massive pile of data, what about the other massive collectors of data out there? Do similar processes and consequences apply in the worlds of the your banks, credit card company, Experian, Equifax, the NSA, FBI, and other groups, both government and commercial?
- globular-toast 5y agoWhy is there a massive, high resolution, unflattering picture of Zuckerberg at the top of this article? What does he have to do with this?