Hacker News new | ask | show | jobs
by sakisv 636 days ago
Honest question: How was it discovered?

Was it reported by a pentester? (ex-)employee? Facebook itself? How do we know that it goes back to 2012?

I know in the public sector you have to disclose such things to ICO, but does that also apply to private companies? Who is going to hold them accountable?