after boot camp, all engineers get access to live DB (comes with standard lecture about “with great power comes great responsibility” and a clear list of “fire-able offenses”, e.g., sharing private user data)
This is through a third-party, so I'm not shaking the finger at Facebook outright yet, but the wording of that — sharing private user data — is kind of frightening. What about merely accessing private user data? Like you mentioned, I know Google is super-paranoid about even simple data access.
And now someone from Facebook chimes in and replies to this and talks more about their developer privacy safeguards and makes us all feel better. Go!