This is a security hole and nothing more. Developers make mistakes. This is not some vast conspiracy by Facebook to undermine your privacy. Why, of all places, is HackerNews unable to comprehend this?
If you see a comment that makes it sound like there's a vast conspiracy, please post in reply to that comment. I don't see any such comment. HN appears to be comprehending just fine.
No. This shows that Facebook has no robust security model at all.
Either they do not have any mandatory access control for private data, or someone approved of circumventing such access control measures for this feature.
Both is in my opinion inacceptable for a company holding so much potentially sensitive data.
One example of a hole does not make a bucket into a sieve.
For a company of FBs size and personal data contents, I agree, they have a rather scary track record. But saying <symptom of X> implies <X> is fallacious, especially when it's also a symptom of <AAA> through <ZZZ>.
A security hole is where some attack vector within the code is overlooked (ex: injection attacks, overflows). A negligent feature is one where the steps to exploit the service were put in explicitly.
What one does this fall into?
At some point a developer coded in a resource that bypasses any privacy data, had it approved by management/coworkers (not sure what model they use) and published it live. I'm certain many people have been exploiting this longer than that forum post existed.
Honestly? I'm willing to chock this up to a mistake. A reasonable series of circumstances for this would also be that they missed a single permissions check on an otherwise private-only method. It's probably a single line of code, and one that exists in thousands of other places, surrounded by at least hundreds of other lines of code. An easy thing to overlook.
That's not how security should work. The default should be no-access, so that missing a line of code or making a small mistake leads to too much restriction rather than not enough. That would also help the developer notice the mistake, since the feature wouldn't work.
Agreed, but you'd be hard-pressed to find any site that has that as the standard (much less a social site, with so many inter-weaving connections), that isn't crammed down their throat by laws. Even then it's still hard to get (and keep) it correct 100% of the time, and stands in the way of making changes and new features, which are what keep social sites alive and competitive.
I think it's a stretch to call this "just" a mistake. First of all, there isn't any malicious code that has to be run to execute it, it's a simple as clicking a few buttons in the UI.
Secondly, Facebook is a site with hundreds of millions of users managing billions of private photos. With the amount of revenue & number of developers they have, it's inexcusable that they can't think through a simple process like this without considering what happens if two users aren't friends.
Granted, they're probably not "trying" to undermine privacy. But they're doing a very poor job at maintaining it.
I'm downvoting you for saying I think it's a stretch to call this a mistake
If it wasn't on purpose, it was a mistake. Period.
It might be inexcusable, as you later pointed out, but it was still unintentional. Everyone likes to hate on Facebook. If this was a YC startup, I suspect people would be more forgiving.
That's true, if it was a group of three young people starting a new business, I would be more forgiving than about a multi billion dollar corporation with hundreds of engineers and millions in resources.
It was a mistake, but another word for a mistake is 'negligence'. The fact that something like this can happen illustrates systemic shortcomings at the company. Millions of people are depending on them to enforce the privacy restrictions Facebook claims to enforce. Facebook encourages you to store highly personal data, and as such, they have a responsibility to be more careful. Facebook prides themselves on constantly pushing changes to their software. More safeguards, testing, and perhaps slowing down the software development cycle a little would not be a bad idea.
Fair enough, I mean to say 'what you may call a mistake, I call negligence'. A pattern of making gross errors adds up to negligence... or incompetence.
I think the problem is that calling it a mistake downplays the issue. I'd say this is grave negligence, because besides the feature itself, it shows a lack of access control systems.
> If this was a YC startup, I suspect people would be more forgiving.
Evidence to the contrary: the Dropbox security fiasco (which sounded worse but was resolved in hours with claims of no malicious activity) prompted several HN entries. HNers aren't so biased as to be blind to inexcusable negligence (esp. because a large majority of us are users of those services and have personal stake.)
Facebook has a history of such "mistakes", a founder who thinks FB users are "dumb fucks" (and has reportedly maliciously used FB's password log), and all the motive in the world to be "negligent" as it's a way they can make money (as long as we don't find out).
The foolish thing to do is to assume this is still a mistake after repeated history of such "mistakes".
aammm... you omited the word 'just' which archio stressed.
Sure, if you take away THE important word of a sentence, then you might as well downvote it.
'a mistake' puts this at the same level of seriousness as other problems. This is at least a big mistake.
I think people know that this is a mistake. But it shouldn't have happened. Facebook is a massive, wealthy company that has many many programmers. Bugs like this should not have happened, considering that privacy is one of the biggest media problems Facebook has.
There is a lot of muscle memory to overcome here. It's like Jeffrey Dahmer accidentally killing someone. You can't blame people for jumping to conclusions.
Is Facebook not hiring some of the most talented developers in the industry? This is a ridiculous mistake that should have been tested for prior to production.
No. I went to school with someone who now works at Facebook. To describe him as "most talented" at anything would be a mistake. However, he did have no regard for others or their work.