4 ms·
"Meta notified at least 20,225 people that their accounts had been compromised. [...] The compromises allowed the hackers to take over the person's entire Inst
by johnyzee 4mo ago
"Meta notified at least 20,225 people that their accounts had been compromised. [...]
The compromises allowed the hackers to take over the person's entire Instagram and any linked accounts, including obtaining contact information, dates of birth, and profile information, as well as the ability to access the person's posts, direct messages, and account activity [...]
the hacks began around April 17 and lasted until this week [...]"
This is staggering.
- sieabahlpark 4mo ago[dead]
- Lionga 4mo agoOne can only hope EU gives them a GDPR fine very close to the limit of 4% of global turnover. But when EU is actually need to protect customer I think they will fail.
- mvkel 4mo agoIncidents like this show how unenforceable GDPR is, and how it's been a net negative for users since its inception. It's idealogical back-patting, toothless when it matters.
- Gigachad 4mo agoAfter the GDPR every website added an option to export your personal data and to delete your account. Something most were missing at the time. It was an immediate and massive win.
- hn773746483 4mo agoRight, but nothing stops companies from refusing SARs on baloney grounds. Complain to a DPA? They tell you to go through ADR or outright ignore you. Complain to Ombudsman? They'll tell you the same. (In my experience, the Dutch do this) Company ignores ADR? Sure, now you can go through the legal route and spend copious amounts of money all because a multi billion dollar company knows the game and how to navigate the bureaucratic mess better than you.
- mvkel 4mo agoThis. In reality, GDPR isn't preventative, nor punitive enough for any meaningful user protection. We get cookie banners everywhere and user data harvesting companies happily pay the negligible fines
- zelphirkalt 4mo agoYep, this is how they do it. The domain registrar netcup did something like this to me.I went through their parent company (?) too, without success. They will put forth any reason to not have to delete your data. I suspect, that they either are trying to reduce work for themselves, or their platform is so crap internally, that they would have to get someone coding to delete the data.
- mvkel 4mo agoYou don't have to have a fb account for meta to fingerprint every little page you visit, perfectly legally.
- dbbk 4mo agoHow is this unenforceable? If any EU citizens were hacked they're gonna come down like a ton of bricks on Meta Dublin.
- smrtinsert 4mo agoThis could avoid flagging by Meta explicitly allow bot traffic to do stuff with impunity on its services. Don't tell me an army of people went through and compromised acct by acct.
- simpaticoder 4mo agoNo fan of Meta, but I think "staggering" is properly determined by the percent of users affected rather than the absolute number. It's staggering to an SMB with 100k customers; it's bad, but not "staggering" to an internet juggernaught with 3B MAU.
- Gigachad 4mo agoTwenty _thousand_ people had their personal data stolen, many of them relied on these accounts to run their business, many put at risk of hackers impersonating them. Meta in a fair world should be forced to financially compensate these people. They built a world where many people basically have to use their products for their jobs and then failed to look after the data because they wanted to replace customer support with a vibe coded AI tool.
- simpaticoder 4mo agoOver forty _thousand_ people die every year in the US from car accidents. Plenty of other preventable injustices happen in all areas of life. I wonder how many fathers are unjustly taken away from their children by a corrupt family court system, how many people die of treatable diseases denied treatment by insurance companies, how many kids lose interest in school because of bad teachers, how many customer service workers endure daily abuse because they need the job. It's not that the breach isn't bad, or that Meta is a sympathetic company. It's bad and they're not. I just find it hard to feel outraged about this particular incident affected 1 out of every 10k users of a social media site when we live in a world with citizen's united, qualified immunity, and $300 insulin.
- Gigachad 4mo agoThe US car deaths stat is also completely insane and way higher than other countries. I can recognize that at scale, securing every account is a very difficult task, but with scale comes responsibility. Meta plays fast and loose rushing in unsupervised vibeslop agents to save a penny. They should be significantly penalized for such a massive failure, particularly for how long this exploit was live and for how the victims were unable to get in contact with any human at Meta to restore their account.