Meta Employees, Security Guards Fired for Hijacking User Accounts (wsj.com) 31
Meta has fired or disciplined more than two dozen employees and contractors over the last year whom it accused of improperly taking over user accounts, in some cases allegedly for bribes, The Wall Street Journal reported Thursday, citing people familiar with the matter and documents. From the report: Some of those fired were contractors who worked as security guards stationed at Meta facilities and were given access to the Facebook parent's internal mechanism for employees to help users having trouble with their accounts, according to the documents and people familiar with the matter. The mechanism, known internally as "Oops," has existed since Facebook's early years as a means for employees to help users they know who have forgotten their passwords or emails, or had their accounts taken over by hackers.
As part of the alleged abuse of the system, Meta says that in some cases workers accepted thousands of dollars in bribes from outside hackers to access user accounts, the people and documents say. The disciplinary actions are part of a lengthy internal probe led by Meta executives, according to the documents and one of the people. "Individuals selling fraudulent services are always targeting online platforms, including ours, and adapting their tactics in response to the detection methods that are commonly used across the industry," said Meta spokesman Andy Stone. He added that the company "will keep taking appropriate action against those involved in these kinds of schemes."
As part of the alleged abuse of the system, Meta says that in some cases workers accepted thousands of dollars in bribes from outside hackers to access user accounts, the people and documents say. The disciplinary actions are part of a lengthy internal probe led by Meta executives, according to the documents and one of the people. "Individuals selling fraudulent services are always targeting online platforms, including ours, and adapting their tactics in response to the detection methods that are commonly used across the industry," said Meta spokesman Andy Stone. He added that the company "will keep taking appropriate action against those involved in these kinds of schemes."
merely "fired"? (Score:5, Insightful)
They were merely fired?
Seems they should be arrested. Breaking into somebody's account is a crime under the Computer Fraud and Abuse Act.
Re: (Score:1)
At a minimum, name and shame, so my lawyers can reach out. The loss caused here is real $$.
Re: (Score:2)
Even if you're not directly affected, every granny with a retirement account based in the stock market should be suing, since FB carries such a big weight in the markets.
Re: (Score:3)
Re: (Score:2)
In California, you can citizen's arrest someone who has committed a felony, even if you were not a direct witness.
Also, I came across this quote: "In general, the ability to perform a citizen’s arrest is the same for a regular person as it is for a police officer without a warrant."
Now, obviously, it's still up to the courts to charge the perpetrator, and habeas corpus still applies.
Re: (Score:2)
Re: (Score:2)
I'd really prefer if Meta didn't start up its own police force and start arresting people it knows have committed felonies.
Re: (Score:2)
It's legally very dangerous to effect a citizen's arrest. Unlike a police officer, private citizens do not have qualified immunity. Any mistake with the myriad technicalities involved in the arrest can expose them to a lawsuit or even criminal prosecution.
Re: merely "fired"? (Score:2)
True. But qualified immunity doesn't change the standards for the arrest, only the penalty for breaking those standards.
Re: (Score:2)
Thing is, if you're wrong about the individual having committed the crime (or can't prove you're right) then it's a false arrest. Which is a crime. At which point it's nice to have qualified immunity against unintentional breaches of law.
You don't even have to be wrong about them actually committing the crime. If you don't have probable cause, which is a intricate and tricky legal standard, it's a false arrest. A policeman has immunity for that unless he knows up front that he's making a false arrest. You d
Re: (Score:2)
In California, you just shout "CITIZENS ARREST!", while the offender has to pull out the phone and Google whether that's actually a legal thing to be done. In this time, you'd hope the actual police put down their donuts long enough to arrive.
Security Guards? (Score:1)
... contractors who worked as security guards stationed at Meta facilities and were given access to the Facebook internal mechanism for employees to help users having trouble with their accounts
WTF? So, people can walk in off the street and ask a security to help with their Facebook account?
Or is this just another Slashdot story where the description is completely wrong and doesn't make sense?
Re: Security Guards? (Score:2)
is this just another Slashdot story where the description is completely wrong and doesn't make sense?
Well, that's right from the wall street journal article, so you decide.
Re: (Score:2)
No, any Facebook employee can walk up to security and ask for help with their corporate Facebook account. It just happens that the permission set extends to any Facebook account.
When hired, every Facebook employee is warned that the accessing another's Facebook account through such means is recorded and closely monitored and that accessing an account without the owner's explicit permission is a first-time firing offense. The warning (and the fact you'll be fired for it) is repeated at the time of access too
Re: (Score:2)
They were merely fired?
Seems they should be arrested. Breaking into somebody's account is a crime under the Computer Fraud and Abuse Act.
It's META. Whatever happens in the MetaVerse stays in the MetaVerse, right?
Re: (Score:3)
It appears to be a feature left over from the days when Facebook was just a bunch of college kids. This "Oops" feature is being described as a mechanism for employees to help their friends with password issues. Security guards were given access because all/most employees are given access to the feature.
It seems like a very dumb feature which shouldn't exist, but has been left alone partly to fill in gaps in how poor user access management is on Facebook.
Re: It makes no sense (Score:3)
Re: (Score:2)
You give security guards access to the tools so that when a Facebook employee gets locked out of their corporate account the guard can help them get back in. The guard is someone physically accessible to the employee and qualified to check the employee's identity documents.
Facebook's public systems and internal systems are more tightly tied together than is commonplace.
Security Guard Admin? (Score:5, Insightful)
Since when does a security guard (let alone a contractor security guard) get access to the Admin portal? That is a corporate structure failure.
is the door card system linked to the IT ADMIN sys (Score:2)
is the door card system linked to the IT ADMIN / Facebook admin system?
And do they need user reset rights to basic door card system work?
Re: (Score:1)
I love corporate irony (Score:2)
Re: (Score:2)
Re: I love corporate irony (Score:2)
If you think about it, there is nothing "fun" about the term. Unless you actually like dog food.
Maybe it's just me... (Score:1)
But if I have a company that needs security guards in its buildings I don't want them distracted from their duties by having to help anyone with an network/service/whatever account problem.
Re: Maybe it's just me... (Score:2)
This is my shocked face (Score:2)