1 month from now, compare what they've said to what they said this week.
1 month from now, compare what they've said to what they said this week.
I don't doubt that setting was involved, but it's obvious by now that this wasn't equivalent to the others - there's no "View As" which will show you someone's search and location history. This isn't just a public/private breakdown but an actual breach of Facebook's internal-only data, and unlike the prior stories this ought to seriously challenge people's reliance on features like Facebook-based app sign-ins.
Not in the UI, no. But once you have the token, which is what this was, then you can request that from many of the UI API interfaces facebook provides.
When this first leaked, anyone who worked with auth systems immediately assumed it was a game over scenario.
I had only followed general-consumption reports here, and hadn't seen that the attack involved obtaining a token that allowed the attacker to authenticate as the user, and I didn't realize that the API included support for pulling search history data. Given that, I understand much better why this was a disaster from the beginning, and why people are so mistrustful of the rolling "and also this..." disclosures.
First they said, "exposure of information from nearly 50 million of its users" and now it's "directly affected 29 million people on the social network".
John Gruber claimed the same thing a couple weeks ago:
https://daringfireball.net/linked/2018/09/28/facebook-hack
Surprisingly quiet this time since it doesn't fit the narrative he wanted.
Each time you load the page, it’s a separate publication about a different 50 million /s.