6 ms·
I worked at Facebook for most of 2017 and 2018. In the first week, they made it clear that you would be fired instantly for any improper access of user data. T
by emtel 5y ago
I worked at Facebook for most of 2017 and 2018. In the first week, they made it clear that you would be fired instantly for any improper access of user data.
They further said that if you need to access any sensitive personal data, or if you need to log in as a user in order to debug a problem, you need to have approval from your manager _before_ the access, not after.
Also, you are not allowed to access the data of anyone you know personally for any reason whatsoever. You have to find someone else to do that if it needs to be done.
Finally, they really do audit every single access of personal data. I had every reason to believe that if I accessed any data improperly, I would be fired within the week if not the day.
I don’t know how much abuse still exists despite all of the above, but I don’t think this article does a good job of explaining how seriously Facebook takes this.
- harrisrobin 5y agoThe issue is that this is even a possibility. It should not be possible to access user data, even if a manager approves it.
- pm90 5y agoThere’s a difference between having an audit trail and actually using it. I would be interested to know how often Facebook analyzes this data and actually fires people for improper usage.
- flak48 5y agoThe article does mention more than 50 people being fired for it between 2014 and Aug 2015
- emtel 5y agoI don’t have proof, but we were told that every access of sensitive data was actively audited. It’s very rare to need to do this for your job, so I don’t imagine it’s a huge volume of events to be audited.
- mtmail 5y ago> I would be interested to know how often Facebook analyzes this data and actually fires people for improper usage. From the article: Facebook fired 52 people from 2014 to August 2015 for abusing access to user data
- whatshisface 5y agoThere's a certain trend in most companies that every bureaucratic rule can be traced back to a specific event where someone caused a problem by doing what the rule was written to forbid - so it's possible that you were indirectly told about four incidents.
- staticassertion 5y agoThose policies will only catch someone after the fact. Firing someone is the bare minimum, it prevents a single repeat offender, but they could already do damage. None of this should even be possible.
- underseacables 5y agoThey had this rule at America Online when I worked there early 2000s. It was routinely violated by the managers, and was really only in place for the rank and file to cover their butts. I just assume bad management and executives of Facebook routinely violate peoples privacy by digging through their information, it’s there, and Facebook hasn’t exactly shown an interest in protecting privacy.
- ocdtrekkie 5y agoThe big problem with a company as large as Facebook, is it's easy for the reality on the ground and the statements executives make to differ greatly: The company policy may be as stated, but there may be line employees and managers who have no issue with abuse of personal data, and even cover for each other. The idea that people can just go in and access personal data at Facebook without some sort of actual pre-authorization is insane.
- antris 5y ago>They further said that if you need to access any sensitive personal data, or if you need to log in as a user in order to debug a problem, you need to have approval from your manager _before_ the access, not after. But were you still able to just look at the data or login as the user without the permission? I think that's the key question. Talk is cheap. As a user it's not good enough for me that people are being told internally not to abuse their access. Just remove the permissions from the employees and make them request the permissions for each individual case instead of trusting the employees to follow the rules.
- ryan93 5y agoI believe they dont allow you to access peoples public profile while at work.
- darkwizard42 5y agoDisclaimer: was at FB in 2014 You could at the time start trying to log in as a user and MULTIPLE red warnings came up that proceeding further would automatically notify your manager and skip of access and a reminder of data policies. Now at that point I did not go further but I did know that content moderation and security teams had special access so I imagine they did both, heavily warn avg FB eng AND restrict access.
- jsbdk 5y agoHow about people with direct database access?
- kmeisthax 5y agoI imagine at Facebook's scale that nobody has direct access to individual database or application instances; and that if someone actually needed to run queries of any kind in production, it'd be as stringent as deploying a code change.
- edmundsauto 5y agoI am close with some people who worked there until recently. All data access is audited; production access is limited via ACLs in both the main data storage system as well as all the others like the warehouse, realtime ingestion, etc. FB appears to take this extremely seriously. I just pinged my friends and they said the only way people get fired is for sexual harassment or improper data access. And the second is the one that gets audited and monitored every day.
- asdfasgasdgasdg 5y agoI'm surprised that this stuff is audit only. At my company, at least in the past five years or so, this type of access has been forbidden to almost all employees. You need to request access to these types of systems and provide justification for why you should have it. Access is controlled on a per-system basis -- it's not blanket access. Many of the most sensitive systems have auto-expiring access for humans. Nowadays we are seeing many systems switch to a regime where you have to get another engineer to sign off on any access to production, and your access is limited to at most 24h. This isn't merely a policy -- it is enforced by technical controls that forbid ordinary human-user access to production. I literally cannot even send an RPC to services I work with that handle private data without getting a colleague to sign off on it.
- saddlerustle 5y agoHow “sensitive” is facebook user data though? All content in a facebook account is already visible to an average of >100 people - their facebook friends. (Messenger had stronger protections than OP is describing)
- asdfasgasdgasdg 5y agoExtremely sensitive, by the lights of the organization I work for. The people to whom FB user data is visible are known to the user. Those people have been explicitly authorized by the user to view that data. FB is acting as the user's agent in conveying that data only to authorized recipients, who the user presumably trusts to some degree or another to not further propagate the data. The data is generally not publicly visible, and FB employees are generally not among the list of entities the user intends to convey the data to.
- Shish2k 5y ago> I'm surprised that this stuff is audit only These days things are mostly working the way you describe - I need to request permission to view my own service’s logs, and I’m working in backend infra not going anywhere near user data (logs are like “did we hit any hardware errors when trying to install the OS on this host?”)
- tut-urut-utut 5y agoJust firing is not enough for the cases of personal data abuse. What I would like to see is those employees being reported by Facebook to the authorities to be further legally prosecuted. We should not rely on the goodwill or internal guidelines of a single company in such a sensitive topic.
- efsavage 5y agoAgreed, I was there at the same time, and was taken pretty seriously, and grew progessively more locked down as time went on. A friend of mine worked at a large bank in customer service and this was also a big part of their training, and there was even a speech trainees were given before going to their desk at the end of training. He said, almost invariably, that at least one person from every class was fired within hours for looking up the accounts of someone they knew or a celebrity.
- dividedbyzero 5y ago> almost invariably, that at least one person from every class was fired within hours for looking up the accounts of someone they knew or a celebrity. While I don't doubt people do this for real, staging something like that might actually be pretty effective.
- pdpi 5y ago> Also, you are not allowed to access the data of anyone you know personally for any reason whatsoever. Which explicitly also includes yourself, because looking yourself up would e.g. let you see who has you blocked. You're also fairly unlikely to access personal data by accident. You have to explictly go look for it in the internal tooling, which has pretty good signage around interfaces that could potentially expose you to personal data by accident so you know to be careful (I did a couple of tickets for the abuse team and testing that stuff was riddled with interstitials asking if I was sure I wanted to access personal data). "Oops I didn't notice" just doesn't fly. They're also fairly good at removing the semi-legitimate reasons you'd have for accessing personal data. If you have friends or family that are having some sort of issue, they have a separate priority queue you can submit requests to so they'll look into those issues for you, for example. If you need test data, there's great tools to generate test users with all sorts of weird configurations (so you don't have to rely on finding a live one that meets your criteria)
- herbst 5y agoSo did people actually get fired over this? Or do you have any reason to actually believe that they would have noticed?
- martincmartin 5y agoYes. There was a public blog post a few year ago from someone complaining about being fired for this.
- deleted 5y ago[deleted]
- cfors 5y agoThese comment's are all relatively ignorant of the fact that implementing these sorts of privacy controls generally makes your product worse and your engineers miserable. > Facebook employees were granted user data access in order to “cut away the red tape that slowed down engineers,” the book says. If we can take a step back, this is a totally reasonable policy. Unfortunately Facebook is facing the reality of the law of large numbers in that once you have 1000+ people the chances of having a bad actor in your system is much higher than 10 people. Maybe this is a hot take, but I for one prefer that my company trusts me to do the right thing rather than make it hard to do my job. I'm not saying that there isn't a solution for this, but behind the "facebook corporation" there is generally just a bunch of engineers that want to do a good job at work.
- BigBubbleButt 5y agoThis is completely unethical and unreasonable. It's like arguing that police don't need more accountability because it makes it harder for them to do their jobs, and most of them aren't bad people, so who cares about a few bad apples? Yeah it sucks, but it's part of the job. Start thinking about the people you're supposedly serving instead of yourself first. I'm pretty sure that the overwhelming majority of facebook users want to hear about tighter privacy protections at facebook, not fewer.
- deleted 5y ago[deleted]
- LanceH 5y agoThey are well audited already. Does every step possible need to be taken to ensure that no data can be leaked ever? No. You can walk out your door right now and hop on a bus. That driver has a CDL, a good first step. But how do we know that the driver isn't drunk? Through threat of possible audit (breathalyzer) after any incident. We don't test them before handing them the keys every day. We trust people all the time with things far more critical than a facebook user's data, and we audit them far more loosely, if at all. "completely unethical and unreasonable" > This seems to be influenced by the belief that tech is some utopia where everything is solvable and the world will be a better place. There is room for good enough in trust. There is a big difference between throwing guardrails up so people don't do wrong and beating them down with requests for permission over and over all day during their work, driving home the point they can't be trusted. Eight hours a day of being told you can't be trusted is about more than the worker's convenience -- it's about their morale at least and possibly their mental health. It also instills the attitude of "if I can do it, it's legal, because otherwise they would have stopped me from doing it."
- panic 5y agoIf you know the right people, can you be taken off the audit list? I remember in the early days of Facebook, access to everyone’s account was seen as an unofficial perk of the job; the cynic in me would say that this perk still exists but is only given to people who can be trusted to never talk about it.
- na85 5y agoMeanwhile the CEO volunteered early on to dox people at Harvard pretty much for funsies[0]. Yet TFA contains a quote about how abusing personal data is "against Mark's DNA". Horseshit. Facebook is the enemy. [0] https://www.esquire.com/uk/latest-news/a19490586/mark-zuckerberg-called-people-who-handed-over-their-data-dumb-f/ https://www.esquire.com/uk/latest-news/a19490586/mark-zucker...
- siftyy 5y agoWhile sure I think it’s wise to stay weary of any company you give your data to, Mark said that when he was 19 and Facebook was limited to students. I think it’s disingenuous to use a quote from 2004 to represent his thinking today.
- k12sosse 5y agoDidn't it start as a hotornot clone using girls pictures without their approval? Never understood why anyone would trust this guy if that was the case. Pervs are some of the most reliably untrustables on the planet.