Your post is unclear on one point. Did you see this screen BEFORE confirming via SMS that you were in possession of the mobile number you entered? If it was after confirmation, that's a very different thing.
Your post is unclear on one point. Did you see this screen BEFORE confirming via SMS that you were in possession of the mobile number you entered? If it was after confirmation, that's a very different thing.
1. I'm not concerned about harm to users from this issue, I don't pretend to be. That should be Facebook's role.
2. This isn't a bug or a vulnerability, it's something you've actually coded - a feature. It doesn't 'accidentally' match up the number I've just entered with other people's phonebooks, you've programmed it to do that. Fine, that's a commercial choice made by Facebook (value of engaging new users vs concerns over publicising people's phonebooks) - but reporting it through those links would be nothing more than a complaint letter.
(edit: removed snark)
If every decision had to get approval from the management team, then progress would grind to a halt, and Facebook would end up like Microsoft.
Insightful: while it's seemingly simple and obvious, everyone I know has fallen prey to the opposite belief, myself included.
And because of that we should hold it with less responsibility than a single person? Even though it holds an order of magnitude more power than a single person?
Yeah, how about, no.
And about your other remark, that is nonsense. It is very possible to keep those checks to a reasonable level of responsibility and many corporations do so, with proper software engineering principles, without "turning into Microsoft".
When dealing with people's private information, one should err on the side of caution, not on the side of $$$, and it is obvious which route facebook took.
In fact, they are already in violation of several EU privacy laws, just because their privacy-pissing database has grown out of hand, they collect more data than they have the internal corporate infrastructure for to deal with this amount of private data of EU citizens in a legal manner in Europe. They went way overboard, maybe not in the US, but they are also incorporated in the EU and cannot oblige by our privacy laws because they collected too much data.
As far as I'm concerned, Facebook is on the verge of criminal negligence as EU laws for citizen privacy are concerned. So personally, yeah, I think nothing wrong with headlines of "Facebook privacy fuckup", as long as they're behaving like that, singular conscience or not.
That's why we have such laws, to keep corporations responsible.
Also, I see no need to respond to your hyperboles. I mean, "criminal negligence"? C'mon.
You assume malicious intent. It might be. But it also might be a engineer who thinks "this would be a cool feature" without stopping to think about the ramifications of this.
Happens all the time; think of the Google engineer who decided that Buzz should auto-follow your most emailed contacts publicly or the NetFlix competition that outed a lesbian in small town America.
Not that I'm saying it's ok if that's the case; it's still a fuck up that needs to be fixed and in general companies need to be better about this - it happens to often.
Just saying I would have reported it to FB first and seen what they did. Responsible Disclosure, and all that.
The potential privacy compromise here is that people who might've not wanted the user to know that they had them in their synced-to-Facebook phonebook, or may have a secret profile connected to said phonebook, could be unwittingly exposed to the user. As your example of the friend with the hidden gay profile shows, that can have alarming results. I'd say that example's bad enough and worth addressing (even if the answer is just better messaging about how synced phonebooks can be used) and that the PI/law enforcement talk is just muddying the waters.
As time went by, it seems that Facebook left behind their mantra of exclusivity and private social circles. They are vigorously facilitating the opposite when you see 'features' like this.
For example, if you tag a photo with a friend's name, all of that friend's friends can see this photo, even if you restrict who can see your photos. You cannot change this, which means you have now lost control of your own privacy. I do not want strangers seeing my photos, but I can't prevent this unless I stop tagging photos, which is what I have done.
More importantly, I'm moving away from Facebook because they don't give a fuck about privacy.
Just because a company is big doesn't mean it has to sell out and stop caring about user privacy.
Yeah me too, I deleted my profile last week.
Good point, but it's not a very different thing, it's a slightly different thing. SMS confirmation would not have stopped FB outing his gay friend to the author. The only different thing is that it would have stopped others abusing this. This is still something that can be abused and should be fixed.
Preventing harm to users is your job, not ours.
Associates of mine have made SEVERAL complaints to FB about security concerns through your standard "hoops" (including /whitehat), and have received exactly ZILCH, NADA in response.
Please also remember that not every report actually pans out. I can't say we should have prevented this because I don't yet know if there is something to prevent. It now appears that the behavior the OP is calling a "fuckup" happened after he confirmed ownership of the phone number. This might change things a bit.
Preventing harm is our responsibility. But if you happen to find an open door, or what might look like an open door, it's more helpful to get all the facts first, report to the vendor, and disclose later if you think the reporting process is unsatisfactory.
For instance, if you have not heard a response from /whitehat, please email me and I will see what I can find out. Or disclose it. I can't stop you.
When it comes to the rules of disclosure, I'm well aware that where you stand depends on where you sit, but I personally think these kinds of firedrills aren't the right way to do it.