Not that it _did_, but it certainly could, and will do so if it thinks it has good enough reason.
Not that it _did_, but it certainly could, and will do so if it thinks it has good enough reason.
Whatever user groups they create are only ever going to be an artificial construct - it's all just lists of stuff
Yahoo could do that and include even all the emails their users 'deleted'.
At one time, back in the 'olden days, everyone operated on the net as if this was a very real possibility.
I work for one of the large ecommerce tech companies - we have some great devs and run a pretty efficient cdci pipeline, stuff ships fast. There are multiple layers of unit testing, automated testing, manual testing and peer review in place to prevent this sort of thing.
Despite that, I can totally see how it wouldn't take much for a changeset in one area of the site that affected the default option in a drop-down in another to creep under the radar.
Companies that don't protect unsophisticated users from simple mistakes or inaccurate mental models will get a reputation for being insecure and lose sales. This is regardless of whether the user "should have known better."
With facebook, you are not anonymous, many of your posts would contain private information, and many of them could be pushed to people you didn't want to share with.
I don't know what threat models you find compelling. But the damage HN could do to someone with the info they have from an account holder is an order or two of magnitude less than the damage facebook could do.
You made me curious. For what exactly could Facebook be fined, and how much would that fine be?
Software changes are rather easy at Facebook (although that particular tool would surely have a ton of people monitoring it, including quantitative social scientists who don’t monitor a lot of pages). Changing the graph (stored information) is pretty much impossible without a lot of checks. That distinction is key to understand control at Facebook.
Sure they have internal controls so a rogue engineer can't do it. But if Facebook, as a company, decides it wants to mess with your settings, it can, and it does.
This event is an existence proof of that.
And also making private anything you legitimately wanted made public, because they couldn't tell the difference.
Regarding the other point - the fact it took them 5 days to revert the privacy status on weeks' worth of posts of some ~14million users just points to them being thorough and _not_ doing it in a hacky manner. A hackish solution could have been done in an hour or two, most likely.
584,203,510,091,521 records updated