Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

7/15/2019
03:00 PM
100%
0%

FTC Reportedly Ready to Sock Facebook with Record $5 Billion Fine

The fine, for the social media giant's role in the Cambridge Analytica scandal, would be the largest ever against a tech company.

The Federal Trade Commission (FTC) and Facebook have reached a settlement over the 2015 Cambridge Analytica privacy scandal, according to reports in The Wall Street Journal and other news outlets.

The fine, at approximately $5 billion, is the largest against a tech company in the FTC's history, surpassing the $22.5 million levied against Google in 2012. That fine also was for failures in privacy practices.

While the settlement has not been formally announced, legislators are already speaking out on the subject, with those on both sides of the aisle criticizing the amount – approximately 9% of Facebook's 2018 revenue – as insufficient.

The proposed settlement must be reviewed by the Department of Justice before it's finalized. No date has been announced for the conclusion of that review.

Read more here and here.

 

Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions, and service providers in the Business Hall. Click for information on the conference and to register.

 

 

 

 

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
CameronRobertson
50%
50%
CameronRobertson,
User Rank: Moderator
7/22/2019 | 4:57:07 AM
Slap on the wrist.
It seems like the amount is great, but considering the kind of money that Facebook makes, and the amount of people that are already reliant on what it does for them, that 5 billion really isn't going to be making a dent in their earnings at all if you ask me! I reckon that it would barely even be considered painful since they could make the money back easily in the coming year with all the acquisitions and development they're doing!
UdyRegan
50%
50%
UdyRegan,
User Rank: Apprentice
7/22/2019 | 3:45:07 AM
No such thing as privacy
In view of this hefty fine amount, how can online users now rest assured that they are truly safe online? Every action that we perform online, there will be at least a single entity that will be watching our every move. Though we do not perform anything illegal, we still feel as though our basic privacy is being invaded. However, there is just too much data online that we need to gain access to so I guess privacy is a small price to pay?
spann182
50%
50%
spann182,
User Rank: Apprentice
7/17/2019 | 4:09:11 PM
Re: Fine Money
California and Colorado have already been looking into this for the states. What we do not need is individual complainces for each state. This should be just the US version of GDPR for ALL states. 

I work in Security and the last think I want to do is remember which states differer in the verbage. 
chadtc
50%
50%
chadtc,
User Rank: Apprentice
7/17/2019 | 2:16:50 PM
Fine Money
What will the FTC do with five billion dollars? Help establish a GDPR for the U.S.? Although GDPR lacks controls it'd be a good start for the US.
drewinutah
50%
50%
drewinutah,
User Rank: Apprentice
7/16/2019 | 2:17:03 PM
FTC fines will herald GDPR Ambulance Chasers!
While this FTC fine of $5 billion "feels" excessive, given the level of scrutiny on both sides of the Pond and because of an increasingly hostile sector of miscreants trying to go where they're not invited, I would expect the GDPR Police to be watching very carefully--especially for a big, fat American-based company, to look to level a big, fat American-sized fine on a GDPR violation--somebody who they know is out in the open and easily pegged as not coloring within the lines (McD? Coke? Pepsico? are you listening?)
tdsan
50%
50%
tdsan,
User Rank: Ninja
7/16/2019 | 12:19:18 PM
This is excessive
I do think that facebook will fight this because this is unprecedented. Per the article, Google was fined 12 million but 5 billion is way over the limit.

What they could do, is to allocate that money to improve their security posture over a number of years. But this is extremely excessive.

T
COVID-19: Latest Security News & Commentary
Dark Reading Staff 10/30/2020
'Act of War' Clause Could Nix Cyber Insurance Payouts
Robert Lemos, Contributing Writer,  10/29/2020
6 Ways Passwords Fail Basic Security Tests
Curtis Franklin Jr., Senior Editor at Dark Reading,  10/28/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How to Measure and Reduce Cybersecurity Risk in Your Organization
In this Tech Digest, we examine the difficult practice of measuring cyber-risk that has long been an elusive target for enterprises. Download it today!
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-27652
PUBLISHED: 2020-10-29
Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
CVE-2020-27653
PUBLISHED: 2020-10-29
Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
CVE-2020-27654
PUBLISHED: 2020-10-29
Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands via port (1) 7786/tcp or (2) 7787/tcp.
CVE-2020-27655
PUBLISHED: 2020-10-29
Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via inbound QuickConnect traffic.
CVE-2020-27656
PUBLISHED: 2020-10-29
Cleartext transmission of sensitive information vulnerability in DDNS in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via unspecified vectors.