Backblaze Privacy Update: Third-Party Tracking
backblaze.com
backblaze.com
> We take the privacy of our customers’ data and personal information very seriously...
It's astonishing that there is no apology of any kind on this post. Is that too much to ask for such a grievous violation?
> On March 8, 2021 at 8:39pm Pacific time, a new Facebook campaign was created that started firing a Facebook advertising pixel, intended to only run on marketing web pages. However, it was inadvertently configured to run on signed-in pages.
It went unnoticed for two weeks, with Facebook gathering information about the customers' files! And yet, no apology!
anyone know if that applies to the real world?
>a new Facebook campaign was created that started firing a Facebook advertising pixel, intended to only run on marketing web pages. However, it was inadvertently configured to run on signed-in pages.
"We take privacy very seriously" is a sign that they don't take your privacy seriously at all.
It may be that fb is doing something illegal here too - eg the whole way tracking pixel work seems difficult to square with gdpr - but the tracking pixel/service looks a bit like the drill used to force a lock - another party (like BB) must deploy it. And arguably the purpose is not to "steal" data.
This is very simple. On all dashboard and similar signed-in pages, there's exactly zero applicable third party code.
If you think otherwise you do not in any way take "the privacy of our customers’ data and personal information very seriously".
As such, you should be much more specific about what you mean with "we removed the offending code".
If you never intended for third party scripts to run on the dashboard page, well then you got some serious explaining to do as to how your deployment process let that slip.
We also subsequently removed Google Tag Manager from the private pages.
This is good. However, the question then becomes how on earth did Google Tag Manager get added to those pages to begin with?
Either you did not consider this a cause for concern, or it slipped past your code review. In either instance, how could I ever trust you with my data?
That question needs a serious answer.
"We have added protections to prevent this error occurring again"
Those sentences do - not - appear.
I've seen so much anger over this issue that it's left me confused. Questions like how they can ever be trusted now. They could never be trusted. If the information is really that important, then it should be encrypted before being passed to any other service. Companies will screw up, the question is how are you going to be on the hook for it. The great thing about services is that you can pass the blame the service than if you had dealt with it in-house.
That said, this has been an embarrassing display for Backblaze and I hope they redouble their efforts on infosecurity. But mistakes happen. If there's a pattern, then that's a different story.
They better act quick about "ensuring it doesn't happen" or I will distrust them completely.
[0]: Content-Security-Policy (setting at least connect-src) and X-XSS-Protection to start with. More here: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Co...
Silo the sales and marketing department away from the real products like the person in that other thread was saying. Sales people can't be trusted with private data.
And yet, your blog/landing site wants me to opt into sharing my 'personal data' with 20 different 'advertisement partners'. Come on.
Asking for consent means that you don't violate their privacy since they agreed to the data being collected and shared.
Using dark patterns is of course not Ok but also a different topic.
The smug tone in this joke of a response to the issue proves this.
And of course they only addressed it after they "got caught", they didn't know about their fuck up before that, if you want to sneer at them, sneer at them for not being careful enough to let this happen, not what you wrote.
I'm not trying to defend them, more like I want to protest against ungrounded casual insulting bashes like yours that seems way too freaking common nowadays. I do think they care about customer privacy, because it affects their income. (Admiteddly they were too casual about it, they were still partnering with Facebook...).
That said, this way of doing things gives so much plausible deniability that it must at least occur to people.
We've been burned on so many fronts by so many companies that it really is a learned behaviour to toxically distrust when things like this happen.
It starts with politics. They're never held accountable for lying, evwn brazenly.
I wish companies would actually mean this and apply it proactively instead of just copy and pasting this in their apology after something like this happens.
> a new Facebook campaign was created that started firing a Facebook advertising pixel
I think they actually don't give any figment of a shit of their customers data if they are adding to the Facebook hoover of personal information.
Yet the first thing I'm greeted with is a cookie consent dialog with "allow all cookies" being the only prominent button.
If I don't want to allow the privacy-invading tracking cookies I need to click a less prominent piece of text called "manage cookies" and avoid clicking on another prominent button called "accept all cookies".
They do not give a shit about my privacy.
"Any company announcing that they take their users privacy seriously does not in any way."
So a name "Facebook law of privacy" ?
HN discussion: https://news.ycombinator.com/item?id=26536019
They had time to write, post and update, and I am still not seeing any emails about it
The post title is also dishonest in saying third party tracking and not adding details — this is Backblaze that intentionally and explicitly shared sensitive data with third party tracking. It’s not as if some third party tracked Backblaze’s paying users surreptitiously.
This response is actually helpful for the competition as far as the HN audience is concerned.
Edit: I’m really curious on the extent of coverage of this issue. I searched online and found only mjtsai.com and theregister.com covering this sensitive information leak. Are there any other major tech sites that have covered it so far?
Why would I trust you this wont happen again?
After reading / comparing prices, for my needs I ended up with:
- OVH Cloud Archive: 0.0023/GB for cold storage + incoming/outgoing prices. https://www.ovhcloud.com/en/public-cloud/prices/#storage
- iDrive: $ 69.50/5TB/year https://www.idrive.com/pricing
- Wasabi: $5.99 / 1TB/month: https://wasabi.com/cloud-storage-pricing/#cost-calc
See: https://ec.europa.eu/info/law/law-topic/data-protection/refo...
this is a perfect example of how NOT to handle a PR nightmare.
A very disappointing article.