If you are truly concerned about harm to users, did you try reporting this to facebook.com/security or facebook.com/whitehat? FWIW, I've alerted some people.
Your post is unclear on one point. Did you see this screen BEFORE confirming via SMS that you were in possession of the mobile number you entered? If it was after confirmation, that's a very different thing.
For context of readers, I note you are a FB engineer. Thanks for looking at this.
1. I'm not concerned about harm to users from this issue, I don't pretend to be. That should be Facebook's role.
2. This isn't a bug or a vulnerability, it's something you've actually coded - a feature. It doesn't 'accidentally' match up the number I've just entered with other people's phonebooks, you've programmed it to do that. Fine, that's a commercial choice made by Facebook (value of engaging new users vs concerns over publicising people's phonebooks) - but reporting it through those links would be nothing more than a complaint letter.
/whitehat is not a "complaint letter". It goes directly to the security team oncall, whose job is to keep users safe even if it means killing things written by other engineers at Facebook that had unintended consequences.
A company doesn't have a single conscience. It may have been a conscious choice by an engineer, or it may have been an unintended consequence of some other code change. Either way, I highly doubt it involved the check-off from a director-level employee.
If every decision had to get approval from the management team, then progress would grind to a halt, and Facebook would end up like Microsoft.
And because of that we should hold it with less responsibility than a single person? Even though it holds an order of magnitude more power than a single person?
Yeah, how about, no.
And about your other remark, that is nonsense. It is very possible to keep those checks to a reasonable level of responsibility and many corporations do so, with proper software engineering principles, without "turning into Microsoft".
When dealing with people's private information, one should err on the side of caution, not on the side of $$$, and it is obvious which route facebook took.
In fact, they are already in violation of several EU privacy laws, just because their privacy-pissing database has grown out of hand, they collect more data than they have the internal corporate infrastructure for to deal with this amount of private data of EU citizens in a legal manner in Europe. They went way overboard, maybe not in the US, but they are also incorporated in the EU and cannot oblige by our privacy laws because they collected too much data.
As far as I'm concerned, Facebook is on the verge of criminal negligence as EU laws for citizen privacy are concerned. So personally, yeah, I think nothing wrong with headlines of "Facebook privacy fuckup", as long as they're behaving like that, singular conscience or not.
That's why we have such laws, to keep corporations responsible.
> 2. This isn't a bug or a vulnerability, it's something you've actually coded - a feature. It doesn't 'accidentally' match up the number I've just entered with other people's phonebooks, you've programmed it to do that
You assume malicious intent. It might be. But it also might be a engineer who thinks "this would be a cool feature" without stopping to think about the ramifications of this.
Happens all the time; think of the Google engineer who decided that Buzz should auto-follow your most emailed contacts publicly or the NetFlix competition that outed a lesbian in small town America.
Not that I'm saying it's ok if that's the case; it's still a fuck up that needs to be fixed and in general companies need to be better about this - it happens to often.
Just saying I would have reported it to FB first and seen what they did. Responsible Disclosure, and all that.
That FB responded 2 hours after the post here on HN speaks for itself. I had logged some bug reports the regular way, and FB got back after one year. Yes, one year.
Then "privacy fuckup" is a somewhat hyperbolic choice of phrase for this, isn't it? And it's misleading to mention private investigators and law enforcement when the friend list is only shown after the phone number has been verified.
The potential privacy compromise here is that people who might've not wanted the user to know that they had them in their synced-to-Facebook phonebook, or may have a secret profile connected to said phonebook, could be unwittingly exposed to the user. As your example of the friend with the hidden gay profile shows, that can have alarming results. I'd say that example's bad enough and worth addressing (even if the answer is just better messaging about how synced phonebooks can be used) and that the PI/law enforcement talk is just muddying the waters.
Exactly. It's timely to discuss where the line is drawn in sharing user data. Trickling here and there amounts to what can be summed up as gaping holes.
As time went by, it seems that Facebook left behind their mantra of exclusivity and private social circles. They are vigorously facilitating the opposite when you see 'features' like this.
Facebook does not care about user privacy. They have gone on record saying this multiple times (and then quickly recanted it). They do not care about user privacy because it goes against everything that Facebook needs in order to grow.
For example, if you tag a photo with a friend's name, all of that friend's friends can see this photo, even if you restrict who can see your photos. You cannot change this, which means you have now lost control of your own privacy. I do not want strangers seeing my photos, but I can't prevent this unless I stop tagging photos, which is what I have done.
More importantly, I'm moving away from Facebook because they don't give a fuck about privacy.
I really hate how Facebook killed the competition because there's no place to go besides G+, and that seems to be targeting a different audience than Facebook. :(
Just because a company is big doesn't mean it has to sell out and stop caring about user privacy.
> Your post is unclear on one point. Did you see this screen BEFORE confirming via SMS that you were in possession of the mobile number you entered? If it was after confirmation, that's a very different thing.
Good point, but it's not a very different thing, it's a slightly different thing. SMS confirmation would not have stopped FB outing his gay friend to the author. The only different thing is that it would have stopped others abusing this. This is still something that can be abused and should be fixed.
Fair enough, I won't quibble. In the absence of a bug report, and having to do this in public, I'm trying to get what information I can. I'm also trying to respond to the author's claims about private investigators, etc.
Apologies for not answering your question - I misunderstood your meaning. This was after entering the SMS code - so it's certainly not an issue where you can enter a phone number you don't control.
You know, buddy, I think from FB we could all use a little more "thanks for pointing out this problem that we at FB should have prevented or refused to implement" and a little less of sarcastic "if you are truly concerned...jump through our hoops."
Preventing harm to users is your job, not ours.
Associates of mine have made SEVERAL complaints to FB about security concerns through your standard "hoops" (including /whitehat), and have received exactly ZILCH, NADA in response.
I get what you're saying and I'm sorry if I was snarky. On the subject of politeness, I myself don't enjoy reading posts titled "Facebook privacy fuckup" at 5am on a Sunday.
Please also remember that not every report actually pans out. I can't say we should have prevented this because I don't yet know if there is something to prevent. It now appears that the behavior the OP is calling a "fuckup" happened after he confirmed ownership of the phone number. This might change things a bit.
Preventing harm is our responsibility. But if you happen to find an open door, or what might look like an open door, it's more helpful to get all the facts first, report to the vendor, and disclose later if you think the reporting process is unsatisfactory.
For instance, if you have not heard a response from /whitehat, please email me and I will see what I can find out. Or disclose it. I can't stop you.
When it comes to the rules of disclosure, I'm well aware that where you stand depends on where you sit, but I personally think these kinds of firedrills aren't the right way to do it.
Thanks for your response, but frankly you are presenting a textbook example here of continuing to impolitely blame the messenger(s). If you don't enjoy reading posts entitled "Facebook privacy fuckup" at 5am on a Sunday, then perhaps FB should start to take privacy more seriously. I'm sure the fact that people are more than a little suspicious of FB in numerous ways and that many have made repeated privacy complaints is hardly news to you, at 5am or otherwise. FB privacy is your firedrill, not ours.
Comments
If you are truly concerned about harm to users, did you try reporting this to facebook.com/security or facebook.com/whitehat? FWIW, I've alerted some people.
Your post is unclear on one point. Did you see this screen BEFORE confirming via SMS that you were in possession of the mobile number you entered? If it was after confirmation, that's a very different thing.
For context of readers, I note you are a FB engineer. Thanks for looking at this.
1. I'm not concerned about harm to users from this issue, I don't pretend to be. That should be Facebook's role.
2. This isn't a bug or a vulnerability, it's something you've actually coded - a feature. It doesn't 'accidentally' match up the number I've just entered with other people's phonebooks, you've programmed it to do that. Fine, that's a commercial choice made by Facebook (value of engaging new users vs concerns over publicising people's phonebooks) - but reporting it through those links would be nothing more than a complaint letter.
/whitehat is not a "complaint letter". It goes directly to the security team oncall, whose job is to keep users safe even if it means killing things written by other engineers at Facebook that had unintended consequences.
(edit: removed snark)
Well, what I am wondering is: is this actually an unintended consequence or a conscious choice that has been made?
A company doesn't have a single conscience. It may have been a conscious choice by an engineer, or it may have been an unintended consequence of some other code change. Either way, I highly doubt it involved the check-off from a director-level employee.
If every decision had to get approval from the management team, then progress would grind to a halt, and Facebook would end up like Microsoft.
> A company doesn't have a single conscience.
Insightful: while it's seemingly simple and obvious, everyone I know has fallen prey to the opposite belief, myself included.
> A company doesn't have a single conscience.
And because of that we should hold it with less responsibility than a single person? Even though it holds an order of magnitude more power than a single person?
Yeah, how about, no.
And about your other remark, that is nonsense. It is very possible to keep those checks to a reasonable level of responsibility and many corporations do so, with proper software engineering principles, without "turning into Microsoft".
When dealing with people's private information, one should err on the side of caution, not on the side of $$$, and it is obvious which route facebook took.
In fact, they are already in violation of several EU privacy laws, just because their privacy-pissing database has grown out of hand, they collect more data than they have the internal corporate infrastructure for to deal with this amount of private data of EU citizens in a legal manner in Europe. They went way overboard, maybe not in the US, but they are also incorporated in the EU and cannot oblige by our privacy laws because they collected too much data.
As far as I'm concerned, Facebook is on the verge of criminal negligence as EU laws for citizen privacy are concerned. So personally, yeah, I think nothing wrong with headlines of "Facebook privacy fuckup", as long as they're behaving like that, singular conscience or not.
That's why we have such laws, to keep corporations responsible.
No, I was simply offering a potential explanation for why things happen.
Also, I see no need to respond to your hyperboles. I mean, "criminal negligence"? C'mon.
or Apple?
> 2. This isn't a bug or a vulnerability, it's something you've actually coded - a feature. It doesn't 'accidentally' match up the number I've just entered with other people's phonebooks, you've programmed it to do that
You assume malicious intent. It might be. But it also might be a engineer who thinks "this would be a cool feature" without stopping to think about the ramifications of this.
Happens all the time; think of the Google engineer who decided that Buzz should auto-follow your most emailed contacts publicly or the NetFlix competition that outed a lesbian in small town America.
Not that I'm saying it's ok if that's the case; it's still a fuck up that needs to be fixed and in general companies need to be better about this - it happens to often.
Just saying I would have reported it to FB first and seen what they did. Responsible Disclosure, and all that.
That FB responded 2 hours after the post here on HN speaks for itself. I had logged some bug reports the regular way, and FB got back after one year. Yes, one year.
I'm sorry you had a bad experience. Were you reporting bugs (eg X doesn't work), or a security vulnerability? Where did you report?
Then "privacy fuckup" is a somewhat hyperbolic choice of phrase for this, isn't it? And it's misleading to mention private investigators and law enforcement when the friend list is only shown after the phone number has been verified.
The potential privacy compromise here is that people who might've not wanted the user to know that they had them in their synced-to-Facebook phonebook, or may have a secret profile connected to said phonebook, could be unwittingly exposed to the user. As your example of the friend with the hidden gay profile shows, that can have alarming results. I'd say that example's bad enough and worth addressing (even if the answer is just better messaging about how synced phonebooks can be used) and that the PI/law enforcement talk is just muddying the waters.
Exactly. It's timely to discuss where the line is drawn in sharing user data. Trickling here and there amounts to what can be summed up as gaping holes.
As time went by, it seems that Facebook left behind their mantra of exclusivity and private social circles. They are vigorously facilitating the opposite when you see 'features' like this.
You did not answer his second question: was this before or after you confirmed through SMS that the phone number is actually yours?
Facebook does not care about user privacy. They have gone on record saying this multiple times (and then quickly recanted it). They do not care about user privacy because it goes against everything that Facebook needs in order to grow.
For example, if you tag a photo with a friend's name, all of that friend's friends can see this photo, even if you restrict who can see your photos. You cannot change this, which means you have now lost control of your own privacy. I do not want strangers seeing my photos, but I can't prevent this unless I stop tagging photos, which is what I have done.
More importantly, I'm moving away from Facebook because they don't give a fuck about privacy.
I really hate how Facebook killed the competition because there's no place to go besides G+, and that seems to be targeting a different audience than Facebook. :(
Just because a company is big doesn't mean it has to sell out and stop caring about user privacy.
> More importantly, I'm moving away from Facebook because they don't give a fuck about privacy.
Yeah me too, I deleted my profile last week.
> Your post is unclear on one point. Did you see this screen BEFORE confirming via SMS that you were in possession of the mobile number you entered? If it was after confirmation, that's a very different thing.
Good point, but it's not a very different thing, it's a slightly different thing. SMS confirmation would not have stopped FB outing his gay friend to the author. The only different thing is that it would have stopped others abusing this. This is still something that can be abused and should be fixed.
Fair enough, I won't quibble. In the absence of a bug report, and having to do this in public, I'm trying to get what information I can. I'm also trying to respond to the author's claims about private investigators, etc.
Apologies for not answering your question - I misunderstood your meaning. This was after entering the SMS code - so it's certainly not an issue where you can enter a phone number you don't control.
You know, buddy, I think from FB we could all use a little more "thanks for pointing out this problem that we at FB should have prevented or refused to implement" and a little less of sarcastic "if you are truly concerned...jump through our hoops."
Preventing harm to users is your job, not ours.
Associates of mine have made SEVERAL complaints to FB about security concerns through your standard "hoops" (including /whitehat), and have received exactly ZILCH, NADA in response.
I get what you're saying and I'm sorry if I was snarky. On the subject of politeness, I myself don't enjoy reading posts titled "Facebook privacy fuckup" at 5am on a Sunday.
Please also remember that not every report actually pans out. I can't say we should have prevented this because I don't yet know if there is something to prevent. It now appears that the behavior the OP is calling a "fuckup" happened after he confirmed ownership of the phone number. This might change things a bit.
Preventing harm is our responsibility. But if you happen to find an open door, or what might look like an open door, it's more helpful to get all the facts first, report to the vendor, and disclose later if you think the reporting process is unsatisfactory.
For instance, if you have not heard a response from /whitehat, please email me and I will see what I can find out. Or disclose it. I can't stop you.
When it comes to the rules of disclosure, I'm well aware that where you stand depends on where you sit, but I personally think these kinds of firedrills aren't the right way to do it.
Thanks for your response, but frankly you are presenting a textbook example here of continuing to impolitely blame the messenger(s). If you don't enjoy reading posts entitled "Facebook privacy fuckup" at 5am on a Sunday, then perhaps FB should start to take privacy more seriously. I'm sure the fact that people are more than a little suspicious of FB in numerous ways and that many have made repeated privacy complaints is hardly news to you, at 5am or otherwise. FB privacy is your firedrill, not ours.