49
Threads collects so much sensitive information it’s a ’hacker’s dream,’ experts say
(nationalpost.com)
This magazine is dedicated to discussions on the latest developments, trends, and innovations in the world of technology. Whether you are a tech enthusiast, a developer, or simply curious about the latest gadgets and software, this is the place for you. Here you can share your knowledge, ask questions, and engage in discussions on topics such as artificial intelligence, robotics, cloud computing, cybersecurity, and more. From the impact of technology on society to the ethical considerations of new technologies, this category covers a wide range of topics related to technology. Join the conversation and let's explore the ever-evolving world of technology together!
Sorry, but this is just bad web design from the hospitals. This pixel tool doesn't magically appear on websites without being put there deliberately. Literally any tracking tool can capture this stuff on any page that a developer puts it on. This is 100% the fault of the programmer at the hospital (or the admin that made them do it) that decided to put tracking cookies on sensitive pages.
The hospital administrators decided it was more important to get their precious reports on usage from Meta's portal than protecting their patients.
I'm pissed that I've had to defend Meta here, but this one isn't on them.
If I leave my door unlocked while I'm gone, and you come in and steal my laptop, it's still theft. Yes, I'm an idiot, but you're still a criminal.
That being said, I fully agree with you that the hospitals should bear equal fault - the lack of protections around patient records is criminal, and I'd really like to see those whose records were exposed sue both the hospitals at fault and Meta, or better yet, a criminal case from the FTC and the Department of Health.
Not likely, I know, but I'm a dreamer.
Not trying to be a hater, but that analogy isn't quite right. The web designers didn't leave their door unlocked. They invited Meta in, put their laptop in Meta's hands, and then said "Please take this. Enjoy." They weren't idiots. They chose to give Meta that data deliberately.
Medical institutions need to be held to account as much as Meta does for everything they do. I agree with that completely.
So now you got me digging into this because I take an absurd amount of pride in my analogies, and it looks like the Meta Pixel tech they embedded was basically like the standard Google Analytics tracking tag on most websites. The hospitals were stupid to install it on their password protected pages, but they were also misled in the fact that Meta's Pixel took far more data than a standard tracking tag, claimed they weren't tracking sensitive data when they were, then claimed to filter the data even though their engineers admitted they couldn't:
So, to perfect the analogy, this would be like a hotel installing security cameras in their rooms, and then finding out the company that makes the cameras and runs the network is selling porn starring its customers. Not only that, now that the porn is in their system, it can't be adequately filtered or removed.
The hotel is stupid and liable, but the security company is just flat out vile.
Ok, I'm done. Have an upvote for putting up with that ;)
Someone on my Mastodon feed put this best: People who aren't tech saavy STILL deserve privacy, security and safety.
Hospitals are full of people who understand medicine, not tech. Because that's what they are. Administrators don't even know what to ask to hire a good tech person, and when a tech person gets in there any change they make has a danger of disrupting livesaving systems so they can't do anything anyway. It sucks, but HIPAA still says those records are private and you're not supposed to be looking at them without having a good reason to. The hospitals are liable for not protecting them properly, but Meta is still in the wrong and still breaking the law by scarping for them.
Ultimately, this is everyone's fault but the patients and the patients are the people who are wronged by it.
Can't say I disagree with your take.