Breaches still occasionally happen, but you're more likely to see data breaches from these data broker companies because they didn't secure their elasticsearch DBs or something dumb like that.
Well, historically, bad actors haven't needed to "hack" Facebook because it has made it possible for them to access user data without hacking.
https://www.npr.org/2021/04/09/986005820/after-data-breach-e...
> In response to the reporting, Facebook said in a blog post on Tuesday that "malicious actors" had scraped the data by exploiting a vulnerability in a now-defunct feature on the platform that allowed users to find each other by phone number.
It's not a vulnerability, it's a "feature".
I think Google's watershed moment was this: https://www.gawker.com/5637234/gcreep-google-engineer-stalke... By the time I got there, it seemed like standard practice for engineers to not be able to read "their own" databases -- every piece of data would be encrypted by a per-user key that only arrives at your application when the user's session is present (or by heavily-audited special exceptions; breakglass, batch jobs, etc.) Much attention was paid to not making data available too widely. (For example, on Google Fiber our hardware knew the MAC addresses of devices that wanted to use WiFi. That's a requirement for 802.11 to work. We modified the Linux kernel, wpa_supplicant, etc. to not log these, explicitly so that someone couldn't collect the logs and do a mapreduce to see who takes their iPhone to their friend's house and intuit a social network. We did that because it was the right thing to do; we only wanted information that was required to operate the service effectively, not to be a dragnet for anything potentially interesting. I'd personally be fascinated to see that information, but it's not the right thing to do.)
I have to imagine that any other large tech company has similar access controls and privacy focus -- even Facebook. Where it gets scary are governments and large non-tech companies that just email around spreadsheets with personal information in them. Yesterday there was an article about Missouri exposing teachers' social security numbers in HTML comments. If you tried to write that code with a data storage system like Google's, it simply wouldn't work. Your code wouldn't have the decryption key for those rows, and you wouldn't be able to output them as HTML comments.
Are we talking about the same Facebook? The mob with some bloke called Zuck are hell bent on selling ads. They absolutely use you.
Please explain 8)
"Walled garden" is a fairly common colloquial phrase, often applied to the iOS ecosystem in the context of the app store (genuinely not sure what you meant by your comment otherwise).
Was that CNN style reporting where Dr. Zuckerberg sells users' personal data left and right in bulk quantities and seems privacy-friendly at same time? Or just NBC style Let's Go Brandon?
> GDPR
Also, I blame Dr. Zuckerberg for constantly getting caught brown-handed while selling data to private intelligence firms. His miserable failures to do shady business in shady way resulted in this extremely idiotic legislation which rendered a significant number of US websites inaccessible to, say, Frankfurt VPDN endpoint and polluted the rest with ridiculous cookie police which is even more annoying than popup and animated porn banners.
This has always been the case since before the digital age (hollywood, cable, video game, sports, even news). These industries feed on humans paying attention to things that don't matter in their life.