Conversations About The Internet #5: Anonymous Facebook Employee
therumpus.net
therumpus.net
For example, if you receive SMS alerts from your bank about transactions, account balance etc. there are multiple engineers in the chain who have access to the information, but should not -
* At the SMS gateway company to which the bank has outsourced the services
* Your mobile service provider
* People who run the SMSC (if the mobile operator has outsourced that)
Unfortunately, there is no way to secure it end to end in its current form. The same is applicable to a lot of services.
How about supporting public key encryption for SMS?
Oh sorry, I forgot that the government wouldn't like that too much. Everything should be out in the open so that everyone can view it to make it easier for law enforcement (at the same time making it easier for criminals to access the information of 'normal/average' people).
The protocol in its current widely deployed form does not support it.
- checked a guest named "Phil Wong" into the new Facebook office in the recent past (after the move)
- is a woman
Holy shit guys, "anonymity"? Protecting her job? I think not.
That detail is just a really poor attempt at anonymization, IMO.
Who's to say 'she' isn't a composite or fabricated anyway?
I would hope it's supposed to be anonymous to Facebook - after all, there were some fairly frank discussions on topics that aren't exactly public knowledge (e.g., Facebook tracking clicks and other little bits of things that really should be revealed by PR, not an employee in an unsanctioned conversation).
"Who's to say 'she' isn't a composite or fabricated anyway?"
Well, in that case the author never visited Facebook's offices - that's the detail that gives away the employee's identity. Given the level of detail gone into by the author, I doubt this is fabricated.
It would probably be better for everyone if it were, though, because he just made a real big boo-boo that will probably cost someone their job.
Maybe not because the information she gave was all that important (although the HPHP thing certainly is an interesting piece of information), but to make an example to other employees about babbling on about the internal workings of their enterprise.
Chief Privacy Officer Chris Kelly might be paying her a visit shortly.
Except that the employees description of the differences between "scripted" and compiled languages leads me to think that this person doesn't really know much about programming languages.
I get the feeling the PHP is probably compiled into some C or C++ format. The speed increase would work wonders for the production server, and if you didn't change HPHP too much from regular PHP, you could still run interpreted for development.
For scaling, I wouldn't be surprised if we started seeing hybrid models like this in the future.
Bonus: I'm also certain they have their own front-end engineering which is speeding up javascript. Nearly everyone else does, and getting that 0.5s page-load will certainly need this boost.
Whomever it is certainly is a Stanford graduate :-)
With gems like that, one can't help but deduce that, if anonymous employee IS a Stanford grad, Stanford is the best CS department in the world. I mean, they seem to have invented the zero-latency, infinite bandwidth internet, where all network operations are CPU bound!
The average Stanford Kid is about the same as the average MIT kid is about the same as the average CMU kid. The most brilliant Ohio State kid is likely about as smart as the most brilliant MIT kid.
[Edited to be less snarky :)]
My roommate recently interviewed with Facebook(we attend a state school in the midwest). The other candidates were going around saying where they were from, many were from Stanford, and when it came to him they basically snubbed him afterwards.
That said in programming competitions we've beaten schools like UIUC.
"PHP is an example of a scripted language. The computer or browser reads the program like a script,..."
Hard to remember the last time my browser was reading a server-side script. ( or was it just "all those beers" they were drinking? )
After all, the server is a computer, so you can replace 'computer' with server. Which makes the first evaluation true, and the word 'browser' is never evaluated, or at least irrelevant. You could even say that either the server or my pet ferret reads the program like a script...
But seriously... the guy/girl was talking generically about scripting, not specific to server-side web scripts. So the statement is accurate.
Since the discussion before this line was about PHP, I think it tends to trip you up.
Are there better ways of doing this, rather than having a global admin backdoor password? Is there a recommended "best practice" for logging in as a user, to see what they see when they use the app? I get a decent number of support requests where the user is seeing something in particular, and my being able to see it would be useful. At the same time, there's a pretty serious risk that's opened up by having this in place.
Anyone have any thoughts / suggestions?
So you could differentiate between RandomGuy actually logging in, Hexstream logging in as RandomGuy and MetaNull logging as RandomGuy. No need to fuck with passwords, guys!
It might just be acceptable though, since almost nobody would guess that a hashed password would be accepted as a password. That is, unless they have access to the controller source code too, and check it out (as you'd assume since the database itself has been compromised).
A better solution may be to create a second temporary password, hashed in another field in the database, and wipe it out when you're done.
It's fine to use an extremely long master password too, making sure it's stored as a bcrypt hash or something. Just run the calculations to make sure that it couldn't be broken in 2^999 years.
Your dynamically-generated temporary password is probably a better way to go about it. Or the hashed master password.
Thanks.
How about allowing the contents of the hash column in the database as the password?
It only takes one incompetent engineer to sometimes store the raw password in the database, and it takes two to make that work to log in somewhere (presumably an easy defense is to only allow "verbatim logins" using something the same length as a hash).
As a plus for non-Stanford/Harvard grads, it means if you don't want to work for Facebook, you have less competition from Stanford/Harvard grads!
The author clearly doesn't understand what he is talking about and doesn't try too hard to understand it; he wants to be sensational instead. Oh well.
Keeping information that almost anyone would think of as private (search history for Google, list of purchased goods for Amazon) is insane. Literally. This kind of data can sort people by political opinion and sexual preferences, for one thing. This kind of data has already been used to spot or incriminate dissent. At the scale of these companies, this can go very wrong.
How they are using this data right now isn't relevant. The fact that every big internet company is doing it doesn't make it acceptable. The fact that no one bother doesn't make it normal.
The risks are just too high.
I don't know if this use of data is "insane", but companies doing it get a clear competitive advantage over the rest. If governments decide to restrict it with some kind of regulation, there would be a clear cost in a less efficient economy. People are willing to give up privacy in order to gain convenience, otherwise they wouldn't be using these services. All these factors say we are going to see more data gathering in the future.
Plus, I disagre about people willingly giving up privacy. I think most of them either undervalue their privacy or don't know they are giving it up.
Either this person had the questions in advance, the interview is an elaborate hoax, or she just happens to be really articulate and alert after a few beers.
In some countries -- for instance the UK -- data protection laws mean that viewing personal data without a specific business reason is itself illegal, even if that data is not manipulated (this may be why the new user switching system requires a reason to be entered). Even if this casual viewing was done before they opened a data center in the UK, this seems a pretty shocking admission to make so casually.
I doubt there's any company that has user data that this doesn't happen at. I bet it happened a hundred years ago at mail order companies. A claim that it had never happened somewhere would be suspicious.
I think their foster mother has tried to make them grow up a little.
In terms of identity, this is facebook, I'm sure they could work out what employee it was (if it was an employee) without the office visit details.
Well, at least we know the end of facebook is coming then ;)