Ex-Meta worker investigated for downloading 30k private Facebook photos
bbc.com
bbc.com
But the point is: Facebook attracts these employees, it doesn’t breed them.
Is there a better way to do seller verification? It does seem like an information leak to me. Craigslist and eBay don’t share my identification as a potential buyer. I don’t love the marketplace being tied to a social network, but it’s what many people are using these days.
the only people i would really not want to find out that i look at their profile are spammers and scammers (oh, and stalkers).
so both sides have a fair reason. so guess, if you can, choose the social network that works the way you prefer.
but that person had to put their info into the website, themselves, by choice, and then chose to let their privacy settings be such that others can view them.
if you pin your photo up to a cork board, don't be surprised if people see it
with more and more illegitimate tracking being done, informing those being tracked seems a benefit, not a drawback.
there is a difference however between one institution tracking who all the people are that i am looking at, vs the person i am looking at finding out for themselves who is looking at them.
0 trust in that company, 0 trust in its employees.
>The engineer, who lives in London, is believed to have designed a program to be able to access personal pictures on the site while avoiding security checks.
> A Meta spokesperson told the BBC the breach was discovered over a year ago, after which the firm said it immediately fired the suspected employee and "referred the matter to law enforcement".
> A spokesperson for the Metropolitan Police said a man in his 30s was arrested in November 2025 on suspicion of unauthorised access to computer material.
WTF? I thought that on 2010 already people were diligent enough to avoid even sending the password and instead just hashed it locally before even sending it.
If you do hash locally (not sure I’ve seen any big players do this), you also need to be hashing server side (or else the hash is basically a plain text password in the database!)
That said, I’m not sure why companies don’t adopt this double hashing approach. Complexity maybe? I know it could limit flexibility a little as some services like to be able to automatically attempt capitalization variations (eg. caps lock inverse) on the server. Anyways in 2026 we should all be using passkeys (if they weren’t so confusing to end-users, and so non-portable)
The communication with the server must be secure, the extra hash only provides the ability for the server's data getting leaked without compromising the password through server logs. The usual setup I'd say is to salt the password in the server and store (salt, hash(pw+salt)), but that still handles text-plain password that might get logged by mistake.