4 ms·
> far poorer security and privacy practices Poorer than Meta? Is that even possible?
by groovybits 4y ago
> far poorer security and privacy practices
Poorer than Meta? Is that even possible?
- tfsh 4y ago> poorer security. likely so, Meta does have thousands of competent engineers, ensuring their data remains exactly where they want it to be
- youngNed 4y ago> Meta does have thousands of competent engineers, ensuring their data remains exactly where they want it to be do they, aye? https://www.datacenterknowledge.com/security/meta-probe-533-million-user-data-leak-draws-close https://www.datacenterknowledge.com/security/meta-probe-533-...
- charcircuit 4y agoPractically every website is vulnerable to an attacker scraping it. If you give people information it's hard to stop them from saving that information.
- BaseballPhysics 4y ago> Meta does have thousands of competent engineers, ensuring their data remains exactly where they want it to be Meta's own employees testified that it would be impossible to enumerate and locate all the data they're either collecting or synthesizing about their users. So you'll forgive me if I don't really believe you.
- Kilenaitor 4y agoNo. They testified that a single person wouldn't be able to. > The court-appointed expert asked who at Facebook would be able to answer the question: where is all the information on a single user stored. > > "I don't believe there's a single person that exists who could answer that question. It would take a significant team effort to even be able to answer that question," answered Zarashaw. https://www.businessinsider.com/meta-doesnt-know-where-all-your-data-is-engineers-say-2022-9 https://www.businessinsider.com/meta-doesnt-know-where-all-y...
- BaseballPhysics 4y agoFrankly, that's a distinction without a difference. A governance policy is only as good as your ability to identify and enumerate your data, their provenance, their location, access controls, etc. If no one person can do that job, it means they aren't actually tracking that information in a way that it can be holistically assessed, audited, etc. Going to the original article that Business Insider cribbed from (which, of course, elides a lot of fascinating detail, because BI isn't a news source, it's an aggregator for people without attention spans): https://theintercept.com/2022/09/07/facebook-personal-data-no-accountability/ https://theintercept.com/2022/09/07/facebook-personal-data-n... We find that this is supported by an internal Facebook document where an insider stated that: > “We do not have an adequate level of control and explainability over how our systems use data, and thus we can’t confidently make controlled policy changes or external commitments such as ‘we will not use X data for Y purpose,’” Which makes sense given one of their engineers noted: > “It is rare for there to exist artifacts and diagrams on how those systems are then used and what data actually flows through them,” With one specific example given regarding their ad tracking: > “It would take multiple teams on the ad side to track down exactly the — where the data flows. I would be surprised if there’s even a single person that can answer that narrow question conclusively.” So, to sum up: no one person can determine what data they're collecting. There is a profound lack of internal documentation and knowledge about how data is processed and where it flows. And Facebook themselves admits they can neither control nor explain how systems use that data. And I'm supposed to believe that "Meta does have thousands of competent engineers, ensuring their data remains exactly where they want it to be"? Please.
- rrdharan 4y agoThis is exactly the problem. Plenty of folks who’ve worked at small startups that haven’t faced regulatory scrutiny can tell you about how poor the common data handling practices are relative to the major leagues. e.g. unilateral write access (no multiparty approvals), no TTLs or deletion guarantees, overly broad access, stale / unmaintained ACLs, copies of production data all over the place, supply chain vulnerabilities, lack of mTLS / endpoint security, etc. etc. The upside (for end users) of big brand names being big targets is they have a lot more to lose than your average startup that no one will remember when it folds and sells its data.
- baby 4y agoI’ve worked at Meta and I can imagine that other companies have worse security in general yeah. I think people here have a glamorous idea of how companies run security. Most companies don’t even have security teams.
- BaseballPhysics 4y agoMost companies don't have Meta's dragon's hoard of personal data. Meta is essentially a surveillance company, with the incredible caveat that they no longer know what data they're collecting.