zlacker

[parent] [thread] 7 comments
1. coldco+(OP)[view] [source] 2018-09-28 16:56:54
Did not mention what was leaked/taken or how 50M and not everyone.
replies(3): >>redlor+q >>jjjjjj+m1 >>microw+B1
2. redlor+q[view] [source] 2018-09-28 17:00:25
>>coldco+(OP)
It said anyone who has used the "view as" may have been accessed
3. jjjjjj+m1[view] [source] 2018-09-28 17:07:23
>>coldco+(OP)
> Since we’ve only just started our investigation, we have yet to determine whether these accounts were misused or any information accessed. We also don’t know who’s behind these attacks or where they’re based. We’re working hard to better understand these details — and we will update this post when we have more information, or if the facts change. In addition, if we find more affected accounts, we will immediately reset their access tokens.

From the press release[0] posted elsewhere in this thread

[0] https://newsroom.fb.com/news/2018/09/security-update/

4. microw+B1[view] [source] 2018-09-28 17:08:50
>>coldco+(OP)
Or why FB waited almost a week to tell us.
replies(3): >>arturs+V1 >>r3bl+x2 >>kregas+Z2
◧◩
5. arturs+V1[view] [source] [discussion] 2018-09-28 17:11:03
>>microw+B1
I think a week is pretty reasonable. They were probably investigating to even get an initial understanding of what happened.
◧◩
6. r3bl+x2[view] [source] [discussion] 2018-09-28 17:15:40
>>microw+B1
> On the afternoon of Tuesday, September 25, our engineering team discovered a security issue affecting almost 50 million accounts.

Now it's 28th, meaning that they've disclosed the breach within 72 hours, as requested by at least one regulation (Article 33 of the GDPR).

That's clearly not even half a week.

replies(1): >>microw+bk
◧◩
7. kregas+Z2[view] [source] [discussion] 2018-09-28 17:18:40
>>microw+B1
Worth noting that GDPR requires 72 hours from discovery to disclosure; and whether Facebook's timetable matches these rules.
◧◩◪
8. microw+bk[view] [source] [discussion] 2018-09-28 19:09:53
>>r3bl+x2
Over 50M accounts are compromised and we're going to split hairs on the proper way to divide up a week? The optimal number of days to alert your 50 million users that their accounts have been compromised is zero. Think about how many businesses that use FB and the thousands of 3rd party sites that use Facebook's API to authenticate users. I don't feel Facebook should get to be sole arbiter on deciding the severity of the incident when if affects so many and has so much potential to financially impact other businesses. They should have immediately sent out an alert when they discovered it.
[go to top]