This does not ring true to me at all.
This does not ring true to me at all.
Yes, because Google is not your average company. It takes security extremely seriously... in fact it's about as awful of an example as you can give for a blanket statement you made about "most companies".
I'd also say it's the norm among most Fortune 500 non-tech companies.
That’s not to say I disagree with you, but the data collected is (to me) orders of magnitude less sensitive.
*disclosure: I toil in the adtech mines.
Which is to say... Google and Amazon?
2012: Google staffs up ‘Red Team’
And this was literally just a Google away: https://nakedsecurity.sophos.com/2012/08/24/google-red-team-...
The job even lists insider threat as part of their responsibility.
While this is certainly true, you've admitted elsewhere not knowing anything specifically about either Google or Facebook's security process, so how can you compare them ? You seem to just "know" Facebook doesn't take security seriously (which is of course a ludicrous thing to say)
You already misquoted me once and I already replied to you. Why do you ignore it and do it again? Like I said: no, I never "admitted elsewhere not knowing anything specifically about either Google or Facebook's security process". You are misquoting me again just like you already did in [1], and it's quite improper that you choose to do this when I have already responded to you and called out your misrepresentation there. If you are looking for a response, see that post. If you are not, then please stop.
People like me or [1] have called you out because you keep contrasting Google and Facebook's internal security processes for no good reason, making definitive assertions like "[Google] takes security very seriously" [2], suggesting that Facebook doesn't and should do "Whatever Google does" [3]. And you're doing this not based on any specific knowledge of what the internal security process looks like at either company, but on your (flawed) perception of what engineering interns might or might not be able to do.
When people like esman1 who actually have that knowledge and context, volunteer to explain to you [4] some of the safeguards in place (and he told you the truth), instead of taking the point, you won't have any of what he says and keep going at it stubbornly.
I think this is the point where reasonable people stop arguing, and anyone else who cares can check your comments in this thread and make their own opinion.
[1] https://news.ycombinator.com/item?id=16675843 [2] https://news.ycombinator.com/item?id=16675508 [3] https://news.ycombinator.com/item?id=16675707 [4] https://news.ycombinator.com/item?id=16675670
Without evidence we're both just guessing. Perhaps someone else will chime in with direct knowledge of how FB works.
Do I understand correctly that you just admitted that your (extremely confident!) factual statement here:
> most companies have pretty strict internal controls for this sort of thing
was actually "just guessing"?
1) my direct knowledge of similar companies
2) the fact that no large scale leak from internal sources has happened from FB which is evidence that they have at least some internal controls or procedures to prevent one
It's _probably_ true that things in general have gotten better since then, and it's probably true that they're better at _some_ companies like Google, Facebook, and Amazon - but I'd tend to agree that it's very unlikely to be true for "most companies".
Who watches the watcher indeed.
Source: I interviewed with their security team once and got a fair idea of how their various security teams are organized.
It's certainly not true at financial institutions. By financial institutions I mean Fortune 100 financial institutions, as well as smaller financial institutions.
If by "pretty strict internal controls" you mean they can, like Prince Potemkin, point to such things existing in some chimeric form, then yes, I suppose you are right. But in any real sense, no, there are no effective controls in the real world.
About 25 years ago I assumed it was early days for a lot of these things and they would sooner or later be closed up, but they haven't been. Things are wide open - as the recent Facebook/Analytics things have shown. In a very small and indirect way at that.
The first major book on this broad subject was Donn Parker's "Crime by Computer" published in 1976. The book opens by saying that a company's biggest enemies in terms of computer crime is its own employees. This is still true 40+ years later - the biggest enemy of the people who own companies are the people who do the work at them.
There were few effective internal controls. The obstacles to lookups were
1 - all info keyed by cookie. Which users can clear, and is very difficult to get identified. That is, to look you up, I need the cookie from your machine.
1a - most devs are not allowed to run the cluster jobs to look up data. Only on the appropriate teams.
2 - but what about stapling? We required partners to pass us blind uids. Certainly nothing like emails.
3 - no data export. The business is to run ads on the customer's behalf, so there's no way built to export data except targeting lists to the exchanges.