3 ms·
This is a very imaginative use of the word “breach”, according to the details reported in the article at least. Internal staff (inadvertently) had access to use
by AmericanChopper 2y ago
This is a very imaginative use of the word “breach”, according to the details reported in the article at least. Internal staff (inadvertently) had access to users plaintext passwords. The article doesn’t mention any use of these credentials in a breach though, and doesn’t make any refutation of Meta’s claim that this never occurred. Internal staff having access to my data is what I would normally expect from a service like the ones Meta operates. It’s a bad mistake to make, but contriving these circumstances into being a “breach” is a bit more mask-off than I’m used to the Data Protection agencies being. Hope Ireland makes good use of its $102M.
- nomilk 2y agoIn many senses, internal staff having access to plaintext passwords is a breach.
- AmericanChopper 2y agoIt’s a control failure, not a breach. It would also be an incident, one that could result in a subsequent breach, or one that warrants some work to be done to ensure it does not turn into a breach. But it has not resulted in an unauthorised party gaining access to the data, and is therefor not a breach.
- ethbr1 2y agoI think it's impossible to say there was no breach, given they were exposed for 7 years.
- AmericanChopper 2y agoI would agree. Which is why I’m suggesting that the Irish Data Protection Commission and Engadget should refrain from saying that. It’s also impossible to say that I am not responsible for a breach of your private data either. How much should the Irish Data Protection Commission fine me?
- ethbr1 2y ago"Potentially breached" would probably be an accurate phrasing. If you had my private data written in the back of a notebook, that you carried around with you to coffee shops, for a few days, I'd feel substantially better than if you did it for a few years. Likelihood that someone peeked scales with time.
- AmericanChopper 2y agoSure, and I don’t disagree that it’s a bad situation for Meta to have created. It’s being fined for “potentially violating” a statute that I find objectionable. Being breached implies that some harm befell consumers, this article (and the others I’ve read about this incident) don’t make any reference to an actual harm being uncovered.
- ethbr1 2y agoI think there should be a "reasonable expectation" of a breach having happened. Secrets laying in an accessible place for 7 years... reasonable expectation is someone looked at them.
- AmericanChopper 2y agoIt’s a reasonable possibility, it’s also a reasonable possibility that nobody did. But somebody incidentally seeing them, and maybe, maybe not recognising they were passwords is not a breach. Somebody intentionally misusing them would be, and I haven’t seen anything to suggest there’s a reasonable expectation that that occurred. A reasonable expectation is also not the standard of proof I’d generally like to see from a government attempting to enforce a penalty.
- ethbr1 2y agoI think knowledge of them would absolutely be a breach, because you wouldn't be able to guarantee that person didn't remember and subsequently misuse them.
- deleted 2y ago[deleted]
- markarichards 2y agoIt's relatively common for publications to lazily only reference an action that resulted in a legal outcome, rather than the justification provided for the outcome. For instance, Bob imprisoned for car bomb rather than Bob imprisoned after judgement rules deaths unlawfully resulted from Bob's malicious car bombing. Had Bob's car bomb been on a film set and no one hurt, Bob would hopefully be fine. If you read coverage with this in mind, then what matters is more a case of how likely an action is to be unlawful and thus how lazy the publication is being. If someone blows up a car, we'd assume it was unlawful. If a company stores passwords unlawfully we'd assume it was unlawful and hopefully for good reason... From GDPR: "personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed" A typical security policy for securing passwords is to never store them in plaintext. It would be a rare situation for the storage to not be accessible (what would be the point of storing it). Thus it would seem fair to assume that in most cases plain text storage of passwords would be a breach of security (internal controls breach) would implicitly also be a breach of personal data (legal definition) as it would at the very least be accidentally accessible to staff, contractors or third parties (whoever hosts the storage). So, it will likely fit the definition of a breach. But, it still needs to escalate to a point where it would be recognised as serious enough to warrant action (like reporting to data subjects or regulators). There are situations where storing passwords in plaintext may not warrant reporting or fines, such as if upon realising the breach it was evident that nobody had accessed the data and it was destructed before harm could be realised; but I doubt anyone would ever know about these situations happening in companies so it's fair to assume they wouldn't reach major news sites.
- AmericanChopper 2y agoEven by the broadest possible definition of a breach, this is still just a control failure rather than a breach. The control that failed might have made it possible for Meta employees to perpetrate a breach, but the article makes no mention of that happening, or provides any suggestion that there is evidence that it might have happened. At at least one point in my career, I have also accidentally mishandled password data (I accidentally leaked them into a log one time - well one time that I know of at least). When I did that I caused a control to fail, and I caused a security incident that required follow up remediation work (including password resets and disclosure), which is exactly what happened here. But I did not cause a data breach to occur. I struggle to image a world where I could have caused my employer to be fined $102M for that incident, and for that to be deemed a data breach, when there is no evidence (presented or referenced in this article at least) that a breach ever occurred. If I leave the office and forget to lock the door, I've caused a control failure. But if nobody comes in to rob us, then I haven't caused a robbery or a breach or anything else like that to occur, even if a typical security policy might require me to lock the door before leaving. The creativity required to come to this conclusion doesn't do anything to improve the credibility of the GDPR, which from an outside perspective really doesn't look like anything other than an import tariff on foreign tech in disguise.
- shprd 2y ago> This is a very imaginative use of the word “breach” You're mistaken. You might be thinking of breach in terms of "hacking into", but they used it as: personal data breach Which accurately means "unauthorised access to personal data"[0] and seem to be the language used by the DPC. [0] - https://ico.org.uk/for-organisations/law-enforcement/guide-to-le-processing/personal-data-breaches/#ib1 https://ico.org.uk/for-organisations/law-enforcement/guide-t...
- AmericanChopper 2y agoThat describes an entirely different incident to the one referenced in this article.
- shprd 2y agoEdited the link out. It doesn't make a difference anyway for the purpose of this discussion.
- AmericanChopper 2y agoYou didn’t edit the link out, you replaced your comment with a completely different one. I always though HN was pretty good at preventing ninja edits like that…
- smittywerben 2y agoI don't know about you but if tens of millions of passwords stored in plaintext are accessible to 80k people they're as good as useless now. You're thinking too much like "hacker selling data security" and not enough like "stalker who works at facebook logged into my gmail because I use the same password as my facebook" regular bob security. Just because you didn't end up in a dataset on some forum doesn't mean that someone's ex has a boyfriend who started his first day at facebook and left his laptop unattended and the ex saw see your facebook password is your "cat's name + 123" in the debug log and nobody at Facebook says anything for years or something. Anyways I think it's fine for them to define breach as the loss/destruction of data i.e. making a password known, which destroys it's value.
- AmericanChopper 2y agoIf this control failure allowed malicious insiders to access private data, and misuse people’s personal accounts, then a data breach would have actually occurred. But I haven’t seen any suggestion that this happened, only references to the possibility that it might have happened. I’m really just thinking like somebody who believes that if the government is going to punish you for something, then I believe the event you’re being punished for should have actually occurred, and also that they should be able to prove it occurred. If reference to standard security policies formed part of the basis of this decision (as the article states), then the harm that you’re trying to contrive into existence here also has no merit. There is no framework of information security that allows for a password to permanently retain its value as a secret keeping tool. Conventionally passwords have only retained their value for a set period of time, and even the most modern security standards for managing secrets requires you to rotate them at even the most remote possibility that they were exposed. The idea that a password rotation has harmed Facebook users, and the implication that their password was a valuable asset that they could reasonably expect to retain its value forever is quite ridiculous.
- smittywerben 2y agoI could agree that this fine is bureaucratic Big Compliance enforcing its made-up standards. At the same time, it's hard for me to feel bad for Facebook. If someone's violating internal auditing procedures, those same procedures won't catch them. It's dangerous because it's a violation of the procedure itself. Proving such violations without tools like no-knock warrants or the NSA moving in is nearly impossible. So you end up with a misappropriated circus of Big Compliance issuing fines over no wrongdoing and internal audits finding no wrongdoing when you rarely hear about this type of internal abuse unless someone is careless enough to brag about it to their Tinder date.