News: 1618948271

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Would be so cool if everyone normalized these pesky data leaks, says data-leaking Facebook in leaked memo

(2021/04/20)


Facebook wants you to believe that the scraping of 533 million people’s personal data from its platform, and the dumping of that data online by nefarious people, is something to be “normalised.”

A blundering Facebook public relations operative managed to send a journalist a copy an internal document detailing the antisocial network's strategy for containing the leaking of 533 million accounts – and what the memo contained was infuriating though unsurprising.

[1]

Belgian tech journalist Pieterjan van Leemputten asked the Mark Zuckerberg-owned company some questions about [2]the theft and dumping online of account data earlier this month.

Miscreants had helped themselves to 70GB of names, phone numbers, dates of birth, email addresses, and more from people's Facebook profiles, thanks to a security weakness in the platform. Having stolen the data in 2019, crims bought and sold it among themselves before one shared it via a Tor-hidden site in early April, inviting anyone to come and help themselves to it all.

[3]

Yet when van Leemputten asked Facebook’s mouthpieces to respond, what he got in return was quite unexpected. As he told The Register : “Facebook accidentally sent me an internal email where they literally state that they will frame the recent 533 million data leak as a ‘broad industry issue’ and that they want to normalize this.”

Flabber suitably ghasted, van Leemputten [4]wrote it up (in Flemish). The key part of the email he received stated:

Longer term, though, we expect more scraping incidents and think it’s important to both frame this as a broad industry issue and normalize the fact this activity happens regularly. To do this, the team is proposing a follow-up post in the next several weeks that talks more broadly about our anti-scraping work and provides more transparency around the amount of work we’re doing in this area.

The Belgian journalist also pointed out that Facebook’s claims that the data-leaking vulnerability only existed during 2019 may have been untrue: two years before that date, a bug hunter called Inti de Ceukelaire [5]wrote about uncovering private phone numbers uploaded to Facebook – and also wrote that Facebook’s security team dismissed his findings, saying “it doesn’t expose any additional user information which wasn’t already public.”

Facebook says dump of 533m accounts is old news. But my date of birth, name, etc haven't changed in years, Zuck [6]READ MORE

We asked Facebook if it wanted to comment on their blunder, and a spokesperson said: "It shouldn’t surprise anyone that our internal documents reflect what we’ve said publicly.

"As LinkedIn and Clubhouse have shown, data scraping is an industry-wide challenge which we are committed to tackling and educating users about. We understand people's concerns, which is why we continue to strengthen our systems to make scraping from Facebook without our permission more difficult and go after the people behind it."

According to the email, Facebook execs want their website to be seen as something that sits above little people like governments and regulators. Pointing out that press coverage of Facebook’s mealy-mouthed non-apology earlier this month for the scraped data being stolen and then posted online summed up the web giant's position as “evasive” and “a deflection of blame,” the email’s sender wrote:

These pieces are often driven by quotes from data experts or regulators, keen on criticizing the company’s response as insufficient of [sic] framing the copmany’s assertion that the information was already public as misleading.

[7]

Facebook’s next statement about “data portability,” aka “the thing that triggered [8]the Cambridge Analytica farce ,” is scheduled for April 22. So said the email, anyway. ®

Get our [9]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YH9O9g-NhhpvTW1NBhjQSwAAABA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.theregister.com/2021/04/05/facebook_data_dump_update/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YH9O9g-NhhpvTW1NBhjQSwAAABA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://datanews.knack.be/ict/nieuws/interne-mail-toont-hoe-facebook-veiligheidsproblemen-wil-normaliseren/article-news-1724927.html

[5] https://medium.com/intigriti/how-i-got-your-phone-number-through-facebook-223b769cccf1

[6] https://www.theregister.com/2021/04/05/facebook_data_dump_update/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YH9O9g-NhhpvTW1NBhjQSwAAABA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2020/10/08/ico_cambridge_seo/

[9] https://whitepapers.theregister.com/

Tactics of the ...

b0llchit

Lets see, can I write a story about the problems we are facing. Dear sir, we are vigorously defending the privacy of all our customers and will...

LOOK OVER THERE! See that cute cat? We love to see cats on our platform. Everybody likes cats. Many sites have cute cats and we have the best cute cats of 'm all.

The problem we are facing is a common industry problem. We are only a diminishing small part of that problem. We are currently in talks with our partners and industry leaders to see how we effectively can solve any possible and potential issues. By the way, we have also been discussing how we can make sharing our cute cats more easy between platforms and will make a public announcement soon.

--

Yes, I hate it too, this sarcasm thingy, but it almost writes itself, doesn't it?

Re: Tactics of the ...

Anonymous Coward

What was that? I loved the pictures of cats!!!!!

The nitty gritty

Chris G

Is this: "make scraping from Facebook without our permission more difficult and go after the people behind it."

Because they don't care about people's privacy or even their their data being stolen, as long as it is Feacebook doing the stealing and so long as they can monetise it when that data is exposed to the world.

A quote from WebMD:

Some experts see sociopaths as “hot-headed.” They act without thinking how others will be affected. Psychopaths are more “cold-hearted” and calculating. They carefully plot their moves, and use aggression in a planned-out way to get what they want.

FB are certainly the latter.

time for some joy

James O'Shea

http://www.joyoftech.com/joyoftech/joyarchives/2793.html

Let's just say that the guys behind The Joy of Tech are NOT fans of Facebook or Zuckerbgorg.

Let's do it.
-- Gary Gilmore, to his firing squad