Archive for Facebook

Meta Slapped With Hefty Fine For Because Of A Data Breach

Posted in Commentary with tags on November 28, 2022 by itnerd

Ireland’s Data Protection Commission (DPC) has fined Meta $265 million USD for a data breach that affected millions of Facebook users in 2021. This information from ‘scraped data’ included phone numbers, Facebook IDs, names, locations, DOBs and email addresses.

The DPC commenced this inquiry on 14 April 2021, on foot of media reports into the discovery of a collated dataset of Facebook personal data that had been made available on the internet. The scope of the inquiry concerned an examination and assessment of Facebook Search, Facebook Messenger Contact Importer and Instagram Contact Importer tools in relation to processing carried out by Meta Platforms Ireland Limited (‘MPIL’) during the period between 25 May 2018 and September 2019. The material issues in this inquiry concerned questions of compliance with the GDPR obligation for Data Protection by Design and Default.  The DPC examined the implementation of technical and organisational measures pursuant to Article 25 GDPR (which deals with this concept).

John Stevenson, Product Director, Cyren had this to say:

“Every single one of the 533m Facebooks users whose information was published on hacking forums faced potential follow-up phishing scams exploiting their exposed PII in the pursuit of more valuable credentials. 

So, whilst the initial data leak was back in 2021, it’s nonetheless encouraging to see fines being issued retrospectively. Hopefully, the consequences here will encourage other enterprises to comply to cyber regulations and follow best practices to avoid a mercenary penalty in future, particularly given cyber insurers increasingly setting a higher bar for due diligence to avoid extortionate payouts like this one.”

Besides other enterprises complying with cyber regulation. I hope that this encourages Facebook to play by the rules for fear of being punished heavily. $265 million USD is a non-trivial amount of money, and I hope it gets their attention.

Meta To Axe 11,000 Employees

Posted in Commentary with tags on November 9, 2022 by itnerd

We were waiting for the axe to fall on Meta employees after rumours of thousands of job cuts surfaced. And now the axe has fallen:

Meta will lay off more than 11,000 employees, CEO Mark Zuckerberg told workers in a message on Wednesday. 

The layoffs will reduce the company’s workforce by about 13%, according to Meta, the parent company of Facebook, Instagram and WhatsApp. 

“I want to take accountability for these decisions and for how we got here,” Zuckerberg told employees. “I know this is tough for everyone, and I’m especially sorry to those impacted.” 

Zuckerberg said the development follows his decision to “significantly increase our investments” at the start of the pandemic. He told employees he made that decision based on the belief that e-commerce would continue to grow and provide a strong source of revenue post-pandemic — a prediction that turned out to be wrong, he said.

This is still a developing story so I will be interested to see where these cuts hit. For example, will this affect his Metaverse project? Or is that a sacred elephant that won’t be touched? Knowing details like that will give insight into where Meta is as a company, and what is important to them.

Stay tuned for more details as the come.

Meta Plans To Do Large Scale Layoffs This Week

Posted in Commentary with tags on November 7, 2022 by itnerd

The word on the street is that Meta who owns Facebook is planning to lay off thousands this week. This story has the details as we know them:

Meta is thought to be considering making thousands of employees redundant with an announcement planned as soon as Wednesday, the Journal reports.

Sources told the outlet that employees had been instructed to cancel all nonessential travel beginning this week.

At the end of September, Meta reported that it had a total of 87,000 employees.

Meta declined The Independent’s request for comment.

The company’s shares fell off a cliff as they had a weak quarter. Thus this isn’t all that surprising. It will be interesting to see what parts of Meta get affected as that will give a lot of insight into what Mark Zuckerberg thinks is important, and what he thinks he can dispose of.

I’ll be watching closely.

Russia Is Afraid Of Meta And Bans Them Under The Guise Of Being “Extremist”

Posted in Commentary with tags , on October 11, 2022 by itnerd

Clearly Meta and the companies under that umbrella has made Russia nervous. I say that because Rosfinmonitoring who is Russia’s Federal Financial Monitoring Service, has added Meta who owns Facebook, Instagram, and WhatsApp, to its list of terrorists and extremists. Keep in mind that Russia cut off Facebook in March, but this latest move by Russia is another step forward:

The battle lines between Western technology platforms and Russia were drawn months ago.

Facebook has not been missed as much as it might have been – because of the popular Russian clone, VK.

But Instagram remains huge in Russia – and the widespread use of virtual private networks (VPNs) means the ban on the platform has not actually stopped people accessing it.

This new official “terrorist” designation could change that though.

It might mean it is now a criminal offence to use Instagram, even via a VPN.

It is also unclear whether the designation includes WhatsApp. 

Banning this, the most popular messaging app in Russia, would cut citizens off from the outside world in a truly profound way.

Which is likely what Putin and his cronies want. And it’s also likely retaliation for removing all VK apps from the Apple App Store and Google Play Store.

It’s safe to say at this point that this is likely to escalate further and both sides are likely going to dig in for a much longer fight.

Meta Sues Chinese Developers Over Stealing Facebook Login Info

Posted in Commentary with tags on October 9, 2022 by itnerd

Earlier this week, I told you about Meta sending notifications to roughly a million people that they Facebook accounts were compromised by account login stealing malware that are in the Google Play Store and Apple App Store. Well, Meta has filed a lawsuit against several Chinese developers doing business as HeyMods, Highlight Mobi, and HeyWhatsApp for developing and deploying this malware starting May 2022. You can read the full details of the lawsuit here. But here are the highlights. According to Meta:

  • The threat actors created this malware and posted them on their own website, as well as the Google Play Store and other Android app download sites.
  • Once the apps were downloaded and installed, the users were prompted to enter their WhatsApp user credentials and authenticate their WhatsApp access on these applications.
  • The credentials were then sent to the threat actors.
  • Meta worked with Google to take out these apps.
  • Meta is suing the developers for breaching WhatsApp’s terms of use and Meta’s developer agreement.

Now I seriously doubt that Meta will get a cent from these developers as it is highly unlikely the Chinese government will assist a US court in holding its citizens responsible for something like this. But that’s not the point of this lawsuit. It’s meant to send a message that Meta will come after anyone who does anything to harm the company or its users. And I for one hope that this is the first of many lawsuits filed to go after threat actors like these as it will place pressure on the Chinese government to deal with these threat actors or risk losing respect in the international community.

Facebook Issues Security Warning…. Scam Apps Stole Login Credentials For 1 Million Users

Posted in Commentary with tags on October 7, 2022 by itnerd

Meta/Facebook has put out a security warning to around one million users that their login credentials may have been stolen by scam apps. That’s a bad look for Facebook. But it’s a worse look for Google and Apple where there’s apps have been hosted. Here’s the details:

Meta is warning 1 million Facebook users that their account information may have been compromised by third-party apps from Apple or Google’s stores. In a new report, the company’s security researchers say that in the last year they’ve identified more than 400 scammy apps designed to hijack users’ Facebook account credentials.

According to the company, the apps are disguised as “fun or useful” services, like photo editors, camera apps, VPN services, horoscope apps, and fitness tracking tools. The apps often require users to “Log In with Facebook” before they can access the promised features. But these login features are merely a means of stealing Facebook users’ account info. And Meta’s Director of Threat Disruption, David Agranovich, noted that many of the apps Meta identified were barely functional.

“Many of the apps provided little to no functionality before you logged in, and most provided no functionality even after a person agreed to login,” Agranovich said during a briefing with reporters.

And if you’re wondering how Facebook is addressing this, here’s how:

Agranovich said that Meta shared its findings with both Apple and Google, but that it was ultimately up to the stores to ensure the apps are removed. In the meantime, Facebook is pushing warnings to 1 million people who may have used the apps. The notifications inform users their account info may have been compromised by an app — it doesn’t name which one — and recommends resetting their passwords.

Thus if you get a warning like this, don’t ignore it. But Apple and Google who let these apps on their respective app stores need to get their act together to stop this sort of thing from happening. Specifically Apple as the company has always argued that the App Store is a safe place. But this incident proves otherwise. And I am sure some people on Capitol Hill will want to get answers about that sooner rather than later.

Health Data Tracked And Used For Facebook Ads

Posted in Commentary with tags on August 16, 2022 by itnerd

Patterns has published a peer-reviewed study on data from digital tools related to health being tracked and used on Facebook for ad purposes. The following digital health tools used third-party ad trackers to follow patients online and market to them based on their activity:

  • Color Genomics
  • Myriad Genetics
  • Invitae
  • Health Union
  • Ciitizen

Yaric Shivek, VP of Product for Neosec had this comment:

     “There is always a balance between the requirement to market a product to prospects and the security of personal data. And in certain industries, like finance and healthcare this balance is governed by compliance and the requirement to protect personal data is paramount. Ad tracking is where this balance is problematic. Most of us wouldn’t install a piece of adware on our laptop, and yet it seems that ad trackers are installed on sensitive healthcare websites, giving advertisers visibility into our transactions on these websites. This seems to circumvent HIPAA compliance. You’d hope that security permissions are more orderly in the world of APIs, but while electronic health records (EHR) companies take protecting your sensitive healthcare data seriously, this data is often being insecurely disseminated by 3rd-party aggregators and apps, whose vulnerable APIs can be easily exploited. This connected world of APIs and apps is only as strong as the weakest link. What good is a bank safe, if your courier gets robbed the minute they walk out of the bank with your cash?”

Chris Olson, CEO of The Media Trust adds this comment:

     “Data privacy violations are one of many risks associated with unsupervised third-party code like ad trackers, content recommendation algorithms, shopping cart plugins, and more. Today, up to 90% of the code across consumer-facing websites is provided by third parties – even privacy-conscious companies are often unaware of their activities which can lead to data breaches, phishing attacks and worse.

Complacency is no longer an option – in the face of emerging data privacy legislation and rising cyber risk, organizations need to commit to the digital safety of their customers by taking control of their online domains and carefully vetting third-party vendors for risky activity. This is especially true for companies that collect sensitive and personally identifiable information (PII) like health data.”

Somehow I am not shocked that Facebook is in the middle of this as you are the product when you use Facebook. And it proves that more needs to be done to rein in Facebook’s activities so that everyone’s privacy is protected.

Yet Another Reason To #DeleteFacebook…. They Paid A Republican Linked Firm To Malign TikTok

Posted in Commentary with tags on March 30, 2022 by itnerd

Facebook continues to hit new lows with their behaviour. And today’s new low is this paywalled Washington Post story (Non paywalled source here) that details how Facebook used the services of a firm linked to the Republican Party to trash TikTok:

Employees with the firm, Targeted Victory, worked to undermine TikTok through a nationwide media and lobbying campaign portraying the fast-growing app, owned by the Beijing-based company ByteDance, as a danger to American children and society, according to internal emails shared with The Washington Post.

Targeted Victory needs to “get the message out that while Meta is the current punching bag, TikTok is the real threat especially as a foreign owned app that is #1 in sharing data that young teens are using,” a director for the firm wrote in a February email.

Campaign operatives were also encouraged to use TikTok’s prominence as a way to deflect from Meta’s own privacy and antitrust concerns.

“Bonus point if we can fit this into a broader message that the current bills/proposals aren’t where [state attorneys general] or members of Congress should be focused,” a Targeted Victory staffer wrote.

The emails, which have not been previously reported, show the extent to which Meta and its partners will use opposition-research tactics on the Chinese-owned, multibillion-dollar rival that has become one of the most downloaded apps in the world, often outranking even Meta’s popular Facebook and Instagram apps. In an internal report last year leaked by the whistleblower Frances Haugen, Facebook researchers said teens were spending “2-3X more time” on TikTok than Instagram, and that Facebook’s popularity among young people had plummeted.

So, because Facebook was losing teens to TikTok, Facebook decided to use very underhanded tactics to fight back rather than improve their product so that it would be more appealing to teens. That illustrates what sort of company Facebook is. It also underlines why people should #DeleteFacebook. Clearly they are not any sort of company that has ethics, decency, or any sort of moral compass. Though at this point, everyone should know that.

Facebook Kind Of Flip Flops On Letting People Call For The Death Of Putin And Muddies The Waters In The Process

Posted in Commentary with tags , on March 14, 2022 by itnerd

Last week, I highlighted a policy change by Facebook which let a handful of countries around Russia do things like call for the death of Vladimir Putin. At the time I said this:

Not that I want to defend Putin. But if I put up a post on this blog calling for the death of US President Joe Biden, I am certain that some US law enforcement agency would be on my doorstep looking for me by the end of the day. In other words, while rules cannot be absolute, this doesn’t seem right to me. Even if its application is limited in scope as is the case here. And I have to wonder if this policy will do more harm than good. Because everything that Facebook does does more harm than good.

It now seems that Facebook has flipped flopped on this… Sort of:

Last week, Facebook temporarily relaxed its policies so that Ukrainian users could post threats of violence against the Russian military, which invaded its neighbor in late February. The change led to some public confusion as to what was allowed, and what was not, on Facebook and Instagram. Meta’s President of Global Affairs Nick Clegg posted a statement Friday saying the move is aimed at protecting Ukrainian rights and doesn’t signal tolerance for “discrimination, harassment or violence towards Russians.” On Sunday, he tried to further explain the company’s stance to employees in an internal post. “We are now narrowing the focus to make it explicitly clear in the guidance that it is never to be interpreted as condoning violence against Russians in general,” Clegg wrote in the internal post, which was reviewed by Bloomberg.

So, is that clear? You can post a threat of violence against the military but not Putin? Right. This change doesn’t help.

#Fail Facebook.

In A Significant Escalation, Russia Is Trying To Get Facebook And Instagram Labeled As Extremist

Posted in Commentary with tags , on March 11, 2022 by itnerd

Russian prosecutors have asked a court to ban Meta Platforms’s Facebook and Instagram as “extremist,” Interfax reported, the latest move in a growing crackdown on social networks:

Authorities blocked access to Facebook last week under a new media law, but the “extremist” designation, if approved by a court, would effectively criminalize all of Meta’s operations in Russia. The company’s Instagram app would also be blocked. The move comes amid increasing tension between Moscow and U.S. tech companies. Earlier Friday, the speaker of the lower house of parliament, Vyacheslav Volodin, called on prosecutors to investigate Meta after Reuters reported that the company had temporarily eased internal restrictions on calling for violence against Russian soldiers due to the invasion of Ukraine. Russia has already banned certain social media companies like Facebook and Twitter, while tech companies have demonetized Russian state-sponsored media and blocked them in Europe.

And it looks like this may have already started:

This is a major escalation in Putin’s fight against social networks who have posts that he doesn’t agree with. Though this story from earlier today has me thinking that this may not be all bad. It will be interesting to see how this plays out.