EU privacy regulator fines Meta 91M euros over password storage
reuters.com
reuters.com
I'm not sympathetic to Meta making security mistakes, more curious how the punishment was decided, in lieu of causing any problems.
I wonder if it was a poorly thought out request log line or what.
If there were damages, that’d be dealt with separately by the courts (EU countries don’t do punitive damages, mostly; this sort of regulator action is used for punishment instead).
- Meta discovered the discovered internally.
- Meta fixed the issue without delay.
- Meta took steps to show "absence of evidence" of abuse. (Does not mean "evidence of absence" though.)
- The reuters article says "Issue was disclosed voluntarily to the regulator." but the actual source [1] announces a breach of GDPR Article 33(1), for failing to notify.
- Meta was still fined 91 M€ for failing to build "data protection by design and by default" (my understanding of the fine, Articles 5 and 32 of the GDPR).
This is a positive step for security: companies being fined for being sloppy about security, even if they dutifully clean up after they mess up.
[1] https://www.dataprotection.ie/en/news-media/press-releases/D...
If they come forward they should be punished more lightly, but if not at all it only encourage "we'll just apologize latter" sort of thinking.
Meta put their customers at risk through negligent actions. A fine in the range you propose would be lower than any investment required to improve security (e.g. by hiring a single additional person). What company in their right mind would do anything to improve security in that case?
So again, why would this make sense?
It's similar to just about any other violation, really: if I injure someone accidentally—even through negligence—I'm going to get a much more lenient punishment if I don't try to cover it up or run away from it.
The fact that such a case even has reporting requirements at all seems nuts to me.
See how that works out for the person who didn’t report it.
The EU is implying that it is illegal to accidentally write vulnerable code. Pure insanity, nearly every software company would go out of business overnight if this was a stance they actually enforced.
For the better, if your attitude is the “healthy SDLC”.
Security reviews are part of a healthy SDLC. You catch vulnerabilities as part of security reviews as they would be totally unnecessary if people simply wrote perfect code to begin with.
I am not gonna go out of my way to "whistleblow on vulnerabilities to the EU" after I have done my job and reported everything to legal.
But, it is also important for the fines to be reduced when taking the right steps to improve. Balancing this will probably be quite difficult.
What executive is going to brush something under the rug when they know their employees can whistle blow and if so, the executive will go to jail.
The egregious nature of the issue seems to undermine any measures they may have done to retroactively fix it.
A first year CS student could tell you this is a fundamentally bad idea. For a FANG company this is inexcusable. Fine is justified.
A company of such size will have to disclose it purely because if an employee left and blew a whistle -- the fine would have been much more. They cut their losses and will accept responsibility.
It was hundreds of millions of passwords.
Everyone was really busy working on the new layout our UI designer had come up with, so nobody gave a shit about the plain text passwords.
I can only guess they're still doing this, but don't know for sure because I was fired a little while later for being a poor culture fit. They don't do business in EU.
GDPR mandates the regulator be informed within 72 hours of the breach being discovered.
The official link you provided confirms that Meta informed the regulator voluntarily, in March of 2019. That page also includes a link to Facebook's press release, which says they discovered the issue in January. That's a time lag of around two months, which is around two months longer than the law permits. So yes, failure to follow the law mandating notification.
All things considered this is a small fine. Three orders of magnitude smaller than their usual GDPR fines.