The style is also all off.
denying contact access haven't worked since 2018
on android you can work around by adding all contacts via wa.me/+1... urls on the browser and then allowing to open with app (or constructing the activity, but that's even harder for regular users)
either way, that's for 0.00000000001% of users. as i said, they have dark patterns which work.
Created in 2011, that's quite a long con...
Someone else mentioned two xx in the Medium name, there are two xx in the email in this post: https://news.ycombinator.com/item?id=40335319
So the existence of another Medium account with one x is a fairly weak argument for the case so many people are making here. I'm not sure on what basis you all are coming to the conclusion you're coming to.
Edit: this is fairly persuasive, however: https://x.com/Vjeux/status/1837639825203384412
That had not been posted when I wrote this, just a brand new green-name account talking about an unused Medium account with one of two variations on the name which Vjeux uses online.
It does seem more likely at this point that his HN account, and not his Twitter account, is the compromised one.
You'd already been shown that this post was not present on the author's blog, nor linked to on their active Twitter account. Both of these things were noted in the GP. Whose account is not green, and whom you were implying was making up a conspiracy theory about this post being fake.
As for the post itself, it was on an otherwise empty Medium blog (you didn't need to look into how many xs the name had, just note that this blog had no other posts at all).
On the other hand, the only link to legitimacy the post had was that it was posted by an old HN account. But it's also not a very active account.
It's easy to see why and how somebody who had hijacked the HN account would use to to give legitimace to the fake. Your alternate theory that the Twitter account was actually compromised is preposterous. There's no motive for it, and it's hard to see how the timing would work out (the attacker using the HN account for misinformation gets to choose the timing of the misinformation; an attacker hacking a Twitter account to suppress the post doesn't).
This is a lot of effort, what was the end-goal?
– Christopher Chedeau (Ex-Meta Engineer)
In any case, yeah Facebook is an immoral company, has been (very obviously) for a long time, and I strongly doubt it was just naivety that lured you in ($$$).
> A hidden mechanism exists within the code base that allows Meta to bypass any user-facing controls, enabling them to access personal data even if you’ve set your privacy settings to the most restrictive levels.
This isn't clear how it isn't just normal system architecture, just with substandard controls to prevent employees snooping on production data. (Of course Meta has access to all the data that is put into the system; that's how pretty much all these systems work, occasionally excluding payment data.)
But if we read to later in the piece, it alludes to ongoing effort into some intentional backdoor, for the use of unspecified parties, and which is hush-hush.
Maybe the writer was weighing what they can and can't say, and the process load of that tends to result in unclear communication (e.g., harder to track the mind of the reader, across edits and mental deliberations). Or maybe they were just stressed or fatigued, around a big career/life change like this.
Anyway...
If it's something illegal, then you have the option of contacting authorities. (Or, if there's a reason that won't work, and you're willing to have your life to possibly suck even harder than that whistleblowing mode, then you could contact a good journalist.) They can investigate and, if appropriate, communicate effectively about the problem.
If it's not something illegal, then maybe there's an employment NDA that applies. Appreciate the FAANG cushion to your finances, and make ethics/transparency/impact/whatever a bigger factor in what company you go to next.
Until you actually do something to counter it, as in, actively counter it, you’ve just given up a very prized chair that millions of people would gladly fill. And haven’t improved the status quo whatsoever. The rate of population and new software devs being minted far exceeds the throughput rate of people resigning from Meta due to privacy concerns.
Also, this isn’t the first “I’m leaving meta because privacy” blog post we’ve seen. Others came before you, and others will come after you. Seems like no one actually does anything other than leave. And then get quickly replaced.
So let me ask you - how many years were you there for, and how much money did you make before ethics suddenly became a concern? You going to hand all that money back to Zuck or what’s the score?
While concerning, this is worded so vaguely that it could conceivably apply to any code that changes at runtime. You could be referring to anything from an iOS/Android CVE to a poorly-programmed Javascript library. Without serious details it's hard to say what you're talking about, and therefore it's hard to judge the threat you're whistleblowing.
If it's not exploitable outside of Meta, I am not sure it would be called a backdoor in the front-end, but perhaps more of an internal Meta tool that they probably needed for law enforcement and things.
Isn't that just how the vast majority of platforms work? To not have this capability requires deliberate design like end-to-end encryption, and that's always going to be advertised as a feature.
We all know it's a shit company with no ethics. Why didn't you?