f5-nz logo
Story image

Experts and execs comment on Facebook data leak

05 Apr 2019

Yesterday, cybersecurity company UpGuard broke the news of 540mil Facebook user records being exposed on the Internet due to misconfigured AWS servers.

The leak is another strike in a long list of Facebook’s faults as it scrambles to maintain its reputation.

Here is what cybersecurity experts and executives had to say about the data leak:

Tenable co-founder and CTO Renaud Deraison

Seems like every other week a security issue is discovered in the Facebook ecosystem.

Facebook is giving third-party app developers access to user data.

That means the company’s massive trove of data is in the hands of potentially thousands of third parties all over the world.

App developers are focused mainly on bringing new offerings to market quickly - it’s what consumers have come to expect.

It looks like Facebook doesn’t have enforced guidelines when it comes to how its partners handle cybersecurity.

Ping Identity Asia Pacific chief technology officer Mark Perry

The latest reports of user passwords exposed in plaintext on public servers by Facebook is lamentable, but all too common event in the technology industry.

Tech companies are the custodians of user credentials and other personally identifiable information, a valuable resource in today's world.

Ping Identity's message to tech companies is simple: encrypt user data at rest and in transit; use up to date, off-the-shelf password hashing algorithms; don't write your own security code; monitor attack vectors like APIs using modern, threat-aware solutions; and control access to your services and applications using multi-factor authentication and fine-grained access control for everyone that touches them: end users, developers and system administrators.

CQR Consulting chief technology officer and co-founder Phil Kernick

The most recent breach of Facebook data only underscores the reality of the business models of social media platforms – the users are not the customers, they are the product.  

Your data is collected, filtered, aggregated and then sold to any business that agrees to comply with Facebook’s policy of not storing it unprotected. 

Whether these third parties actually comply is a contractual matter with Facebook and the user’s whose data is compromised have no say in the matter. 

While Facebook has recently made announcements that they will take a privacy-first approach to user data, this seems to be more a response to avoiding Government oversight than genuine care for their users. 

They’ve made these promises before. 

They’ve broken these promises before. 

Aura Information Security general manager Peter Bailey

As far as data privacy and security goes, Facebook is having a particularly bad run and the company is fast becoming the poster child for what not to do. 

First the Cambridge Analytica saga, then the security flaw that allowed hackers to access 50 million Facebook accounts… and now this.  

It’s becoming increasingly apparent that Facebook simply isn’t taking their duty of care in regards to the privacy of the data of its users seriously enough. 

Social media platforms like Facebook are about trust, if users don’t feel they can use them safely, we’re going to see more people leave the platform.

WatchGuard Technologies A/NZ regional director Mark Sinclair

Organisations need to be very careful when sharing sensitive data with other third-party organisations. 

Third parties are often a much easier target and, once compromised, can also act as a launching pad for a cyber-attack on the original organisation.  

Any organisation that shares data should be reviewing their API's to ensure controls are in place to limit sensitive data and regular audits be done on the third parties to ensure compliance to privacy regulations and IT security standards.

Digital Guardian cloud services security architect Naaman Hart

In the age of GDPR companies must realise that when they collect data they are responsible for it, regardless of whether they share it onwards or keep it themselves. 

It will be interesting to see whether litigation springs from this as I expect it might. 

In that case, the financial and reputational damage to Facebook might prompt them to ensure the companies they do business with are held to their own security standards. 

Story image
Hands-on review: JBL Quantum One headset
The JBL Quantum One headset is a premium product that delivers excellent sound no matter what device you use it on. It’s also very comfortable and one of the best headsets I have ever used. More
Story image
Game review: Borderlands Legendary Collection on Nintendo Switch
I was pleasantly surprised when I opened Borderlands (2009) and the highly stylised art direction and animation didn’t seem like it was from the same year that Barack Obama first took office.More
Story image
Hands-on review: OPPO A72, the budget phone with killer cameras
I never expect budget phones to come with a fast charger, but this is another area where OPPO made sure to take care of the consumer. More
Story image
Hands-on review: JBL Tune 220TWS
Another great part of the design is the earbuds themselves. Most other earbuds on the market can’t be worn for more than two hours at a time because of the amount of pressure they put on ear canals. Thankfully, the JBL Tune 220 were designed with all-day wear in mind. More
Story image
Hands-on review: 13-inch MacBook Pro - the butterfly keyboard is finally dead
With the typing experience improved and the insides bumped up and the Apple ecosystem now better than ever, the MacBook Pro is now an even more reliable tool.More
Story image
Apple unveils iPadOS 14, with redesigns for Siri, Search, widgets and more
“With iPadOS 14, we’re excited to build on the distinct experience of iPad and deliver new capabilities that help customers boost productivity, be more creative, and have more fun.”More