With so much to lose and so little to gain internal leaks of this sort are extremely rare.
With so much to lose and so little to gain internal leaks of this sort are extremely rare.
#1 - There's always a back door. I did some medical records stuff for a while. I looked myself up, just to confirm for myself how trivial it was to do. Yup, there I was. Which is why I insist that all data at rest is encrypted. (I have yet to win this argument.)
#2 - Our "portal" product had access logs for auditing. Plus permissions, consent trees, delegation. The usual features. Alas. We also had a "break the glass" scenario, ostensibly for emergency care, but was more like the happy path. And to my knowledge, during my 6 years, none of our customers ever audited their own logs.
#3 - My SO at the time worked in a hospital and went to another disconnected hospital for care because she knew her coworkers routinely, illegally looked up patient records, and she didn't want them spying on her.
Ironically, you're undermining your own point. The fact that they would be fired afterwards in no way contradicts the notion that they could access such data, and in fact suggests they can (hence the firing policy).
You asked about the "average employee" having access to user data, and the answer is unequivocally "no", with both technical and disciplinary safeguards.
There are only a few roles (moderation) who can access the relevant tools, and while engineers may technically have programmatic access (how would you expect things to work if nobody did ?), this is thoroughly logged and you'd better have an ironclad justification not to get fired on the spot.
> You asked about the "average employee" having access to user data, and the answer is unequivocally "no", with both technical and disciplinary safeguards.
(a) How do you know, and (b) so what is your explanation of stories like [1]? They're just hoaxes?
> and while engineers may technically have programmatic access (how would you expect things to work if nobody did ?)
Again you are wording this in quite a vague, lawyer-y manner, which again raises my eyebrows. "May" as in "might", or as in "do"? And "engineers" as in what fraction of them? There is a lot of wiggle room between "nobody" and "all engineers". It's quite strange that I can't get a straightforward, crystal-clear denial to a non-weasel-worded claim from you who seem to be confidently contesting what I'm saying. Please don't keep muddying the waters.
As for why no one is giving you a clear answer it is because there is no reason for anyone to tell some random person deep details about security policy and procedure. The people building the internal controls and defenses are smarter than you, they know what needs to be protected and are rather devious about thinking up attack scenarios and possible paths of compromise, and eventually get tired of repeating the same answers. Want to know more? Too bad.
Where did I ask for "deep details about security policy and procedure"?
> Want to know more? Too bad.
No, but thanks.
> There is some data that an average employee just cannot get to.
"Some data" means nothing. I'm sure this is true in many, many companies, ranging from the most competent to the most incompetent.
> For some data a dev can access it but the pattern of access and amount of data accessed will be audited and anomalies will raise an alarm.
This is yet again consistent with what I've said.
At the end of the day, the data is there - they have it. Possession is arguably MORE than 9/10 of the law in this situation. They can access it whenever they want -- trivially if they are rogue or have no concern for keeping their job. but this is true of just about any huge company that employs a lot of people-- but they're not going to say they can. Why would they?
For goodness's sake, please stop these straw-man arguments. I said this above once, but it seems I have to say it again: nobody ever asked for that level of detail. People have been struggling with far more basic issues. No current or ex-employee or intern has even come along to try to say something simple like "as far as I know, the average Facebook intern simply cannot access private user data regardless of any business reasons"; indeed, we've gotten anecdotes that that the opposite has actually happened. How you suddenly deduce that I'm looking for specific descriptions of what teams can access what data is just beyond me.
That could be answered with something vague like "yes, this requires permissions from a small team of trusted individuals, which are granted only if the issue is severe/cannot otherwise get immediate attention/cannot be addressed by that team/etc., and it's never granted to most interns". No need for jumping to "X-dev-team #1 has access to X, Y, and Z".
Everything is logged, so if you might have looked at anything you shouldn’t have, it’s flagged and you’re audited; if you didn’t have permission (from a user and/or manager) and a valid business reason, then (we were told during onboarding) you’re likely to be fired and possibly sued.
The reality is that huge amounts of personal data were harvested by third parties through app permissions - apparently with FB’s knowledge and support.
No one needs back door hacks to get into a vault when the front door is wide open.
The 'We will log your access and fire you' line of defense prevents nothing from someone who only has a job for the purpose of moving data out.
Someone in that position would be much better off building a back door into the system. But if they could also build a backdoor into iCloud, or scrape Gmail data from within Google.
I assume that Facebook has mechanisms to check that new hires (especially foreign nationals) are legitimate.
This is the best resource I've found for protecting such things:
Translucent Databases: Confusion, Misdirection, Randomness, Sharing, Authentication And Steganography To Defend Privacy http://a.co/eLgQACC
Maybe differential privacy stuff will supersede, compliment these techniques. I'm keeping an open mind.
Everything you’re describing sounds like it’s either incredibly fly by night, not in the US, or substantially out of date. If the last two aren’t true, you have a situation that is literally illegal.
In the USA, there is no way to encrypt medical records at rest and permit data interchange. Because in the USA we do not have universal MRNs (PIDs, GUIDs, whatever). Meaning that if demographic data is encrypted, the system cannot match records across org boundaries, meaning care providers aren't 100% sure they have the correct medical history for the patient, meaning prescription errors, cutting off the wrong arm, misdiagnosis, etc.
Some enclaves like Medicare and VA can encrypt their own data for their own usage, but that protection is moot the moment data is shared with other orgs. It's been a while since I've checked, but I doubt they do encrypt, because that's a bottom up design decision.
-Former custodiet of the custodes
1. http://www.zdnet.com/article/leaked-audio-facebook-security-...
This does not ring true to me at all.
Yes, because Google is not your average company. It takes security extremely seriously... in fact it's about as awful of an example as you can give for a blanket statement you made about "most companies".
I'd also say it's the norm among most Fortune 500 non-tech companies.
That’s not to say I disagree with you, but the data collected is (to me) orders of magnitude less sensitive.
*disclosure: I toil in the adtech mines.
Which is to say... Google and Amazon?
2012: Google staffs up ‘Red Team’
And this was literally just a Google away: https://nakedsecurity.sophos.com/2012/08/24/google-red-team-...
The job even lists insider threat as part of their responsibility.
While this is certainly true, you've admitted elsewhere not knowing anything specifically about either Google or Facebook's security process, so how can you compare them ? You seem to just "know" Facebook doesn't take security seriously (which is of course a ludicrous thing to say)
You already misquoted me once and I already replied to you. Why do you ignore it and do it again? Like I said: no, I never "admitted elsewhere not knowing anything specifically about either Google or Facebook's security process". You are misquoting me again just like you already did in [1], and it's quite improper that you choose to do this when I have already responded to you and called out your misrepresentation there. If you are looking for a response, see that post. If you are not, then please stop.
People like me or [1] have called you out because you keep contrasting Google and Facebook's internal security processes for no good reason, making definitive assertions like "[Google] takes security very seriously" [2], suggesting that Facebook doesn't and should do "Whatever Google does" [3]. And you're doing this not based on any specific knowledge of what the internal security process looks like at either company, but on your (flawed) perception of what engineering interns might or might not be able to do.
When people like esman1 who actually have that knowledge and context, volunteer to explain to you [4] some of the safeguards in place (and he told you the truth), instead of taking the point, you won't have any of what he says and keep going at it stubbornly.
I think this is the point where reasonable people stop arguing, and anyone else who cares can check your comments in this thread and make their own opinion.
[1] https://news.ycombinator.com/item?id=16675843 [2] https://news.ycombinator.com/item?id=16675508 [3] https://news.ycombinator.com/item?id=16675707 [4] https://news.ycombinator.com/item?id=16675670
Without evidence we're both just guessing. Perhaps someone else will chime in with direct knowledge of how FB works.
Do I understand correctly that you just admitted that your (extremely confident!) factual statement here:
> most companies have pretty strict internal controls for this sort of thing
was actually "just guessing"?
1) my direct knowledge of similar companies
2) the fact that no large scale leak from internal sources has happened from FB which is evidence that they have at least some internal controls or procedures to prevent one
It's _probably_ true that things in general have gotten better since then, and it's probably true that they're better at _some_ companies like Google, Facebook, and Amazon - but I'd tend to agree that it's very unlikely to be true for "most companies".
Who watches the watcher indeed.
Source: I interviewed with their security team once and got a fair idea of how their various security teams are organized.
It's certainly not true at financial institutions. By financial institutions I mean Fortune 100 financial institutions, as well as smaller financial institutions.
If by "pretty strict internal controls" you mean they can, like Prince Potemkin, point to such things existing in some chimeric form, then yes, I suppose you are right. But in any real sense, no, there are no effective controls in the real world.
About 25 years ago I assumed it was early days for a lot of these things and they would sooner or later be closed up, but they haven't been. Things are wide open - as the recent Facebook/Analytics things have shown. In a very small and indirect way at that.
The first major book on this broad subject was Donn Parker's "Crime by Computer" published in 1976. The book opens by saying that a company's biggest enemies in terms of computer crime is its own employees. This is still true 40+ years later - the biggest enemy of the people who own companies are the people who do the work at them.
There were few effective internal controls. The obstacles to lookups were
1 - all info keyed by cookie. Which users can clear, and is very difficult to get identified. That is, to look you up, I need the cookie from your machine.
1a - most devs are not allowed to run the cluster jobs to look up data. Only on the appropriate teams.
2 - but what about stapling? We required partners to pass us blind uids. Certainly nothing like emails.
3 - no data export. The business is to run ads on the customer's behalf, so there's no way built to export data except targeting lists to the exchanges.
I recently downloaded my Facebook archive [1]. If it were legal, I would certainly pay thousands if not tens of thousands of dollars for certain peoples' archives. I can think of several practical contexts in which an unethical actor would find it profitable to pay a Facebook employee a million dollars for someone's Facebook archives.
Really? For what purpose?
On the upside, any case where one is engaging in high-value transactions (broadly speaking). Knowing a negotiating counterpart's likes, dislikes, communication style, et cetera can help one avoid mistakes, build a personal connection and draft (and frame) terms correctly on the first try.
More seedily, such information about a political opponent (whether a politician, rival on a commercial or non-profit board, or commercial competitor) is useful.
As a risk mitigation tool, such data would find a natural home in a due diligence file. Prospective executives, board members, business partners, political donation recipients, et cetera expose one to reputational risks. Catching those in advance is already worth tens of thousands of dollars of legal time.
I would hate to live in a country where the above is legal. We should recognize the value of the information every single single Facebook employee has routine access to.
Well, apart from post-factum incarceration.
wait, what?
There's quite a lot to be gained. Enough to incentivize a very powerful attacker, possibly even a nation-state level actor who can extract the mole and protect / reward them.
The stakes are not low here; I can't imagine why you've said that.
What do you think the number is at facebook? At google? At your bank? At your healthcare provider?
That's not enough by any means (edit: and as [1] pointed out, I don't even think it's true). There needs to be more to security than mere deterrence. I'm pretty sure at Google, etc. it's simply impossible for a single rogue employee to mess with customer data (except for a few in very privileged positions), and my impression has been that Facebook is not like this at all (unless it has changed recently).
Having never worked there, I can't speak to how it works at FB but I would imagine that there are a lot of limitations on what rank and file employees can do. I guess I could be wrong. Perhaps someone with direct knowledge will chime in.
Cool, now read this: https://news.ycombinator.com/item?id=16675503
Any changes to your thoughts?
Still egregious if that sort of early stage stuff hung around that long, but not the same as it being there today.
companies that move fast and break things don't give a shit.
I want more companies of the first type and less of the second.