Apr 4, 2019

The data trash-pile blame game

Illustration: Aïda Amer/Axios

The tale of the latest Facebook data spill, announced Wednesday by security outfit Upguard, has a unique new twist: No one is shouldering responsibility for the half a billion user records that were exposed on a public server.

Driving the news: The story broke yesterday when Upguard reported it had found two troves of Facebook user data sitting on publicly accessible Amazon Web Services S3 "buckets" — cloud storage containers used mostly by backend programmers.

  • The first belonged to a Mexico-based media company, Cultura Colectiva, and contained 540 million user records.
  • The second contained a backup by the apparently defunct Facebook app "At the Pool," which, though much smaller, included more sensitive information, including plain text passwords for 22,000 users.

The data originated with Facebook. But Facebook maintains that fault lies not with its own practices but rather with the developers of the apps that carelessly stored their data.

  • "Facebook's policies prohibit storing Facebook information in a public database," the company told Axios. "Once alerted to the issue, we worked with Amazon to take down the databases. We are committed to working with the developers on our platform to protect people's data."

The data lived on Amazon's cloud servers. But Amazon says that responsibility for securing data stored with it lies with the companies that put it there.

  • AWS's S3 is like the internet's data warehouse. The programmers for tons of widely used apps and services use it as a cheap, flexible, on-demand source of storage. S3 buckets are set private by default but some are made publicly accessible so users can download data directly.
  • "AWS customers own and fully control their data," Amazon said. "When we receive an abuse report concerning content that is not clearly illegal or otherwise prohibited, we notify the customer in question and ask that they take appropriate action, which is what happened here."

The data was held by the app makers.

  • But one of them, "At the Pool," seems to be out of business.
  • The other, Cultura Colectiva, offered no apology in a statement that circulated among journalists on Twitter, but said that the data it was storing came from "the fanpages we manage" and was "public, not sensitive," information.

Our thought bubble: Everything these companies say may be correct, but none of it is satisfying.

  • App makers who are aggregating hundreds of millions of data points about their users owe it to them to protect the resulting databases from random downloaders, not leave them out like a stagnant data dump.
  • Amazon may reasonably let its customers decide whether data should be public or private. But it could also take more proactive measures to alert storage users about what information they've exposed to the whole internet. The world's biggest digital landlord has a role in cleaning up the dumps on its property.
  • Facebook rightly points out that it has tightened up its policies on sharing user data with app makers since last year's Cambridge Analytica debacle. But its lax privacy practices leaked user information to other companies for years. Incidents like this one will continue to erode public trust in Facebook until the company creates something like a digital Superfund to help clean up the messes it has made.

The bottom line: Facebook and Google have turned user data into advertising gold. But that data can also end up as garbage left out on the net in abandoned "buckets" for mischief-makers and criminals to pilfer. When that happens, "not our fault" won't reassure anyone.

Go deeper

In photos: India welcomes president with massive "Namaste Trump" rally

First Lady Melania Trump, President Trump and India's Prime Minister Narendra Modi attend the "Namaste Trump" rally at Sardar Patel Stadium in Motera, on the outskirts of Ahmedabad, on Monday. Photo: Mandel Ngan/AFP via Getty Images

President Trump told a massive crowd at a rally in Ahmedabad, northwest India, Monday he hopes to reach a trade deal with his ""true friend" Prime Minister Narendra Modi during his two-day visit to the country "except he's a very tough negotiator."

Why it matters: The countries are forging deeper ties, particularly in the military dimension, as India’s location, size and economic growth making it the "obvious counterweight to China" for American policymakers, per Axios' Dave Lawler and Zachary Basu. Prime Minister Narendra Modi demonstrated the importance of the visit with a "Namaste Trump Rally" at a packed 110,000-capacity Sardar Patel Stadium in Ahmedabad — the world's largest cricket venue.

Go deeperArrowUpdated 22 mins ago - World

Coronavirus spreads to more countries as cases in South Korea surge

Data: The Center for Systems Science and Engineering at Johns Hopkins, the CDC, and China's Health Ministry. Note: China numbers are for the mainland only and U.S. numbers include repatriated citizens.

Afghanistan, Kuwait and Bahrain each reported their first cases of the novel coronavirus, Al Jazeera first reported, as infections in South Korea, Italy and mainland China continued to increase on Monday.

The big picture: As South Korea and Italy stepped up emergency measures in efforts to thwart the spread of the virus, World Health Organization officials expressed concern about infections with no clear link to China. COVID-19 has killed at least 2,619 people and infected almost 80,000 others, with all but 27 deaths occurring in mainland China.

Go deeperArrowUpdated 34 mins ago - Health

Sanders reveals free childcare plan for preschoolers

Democratic presidential candidate Sen. Bernie Sanders speaks during a campaign rally on Saturday in El Paso, Texas. Photo: Cengiz Yar/Getty Images

Democratic presidential candidate Sen. Bernie Sanders announced on CBS' "60 Minutes" Sunday a new plan to guarantee free child care and pre-kindergarten to all American children from infancy to age four.

Details: In the wide-ranging interview, Sanders told Anderson Cooper he planned to pay for universal childcare with a wealth tax. "It's taxes on billionaires," he said.

Go deeperArrowUpdated 6 hours ago - Politics & Policy