50M Facebook Accounts Exposed Due to Software Vulnerability

  /     /     /  
Publicated : 23/11/2024   Category : security


50M Facebook Accounts Exposed Due to Software Vulnerability


A vulnerability in Facebooks View As feature could have exposed the personal information of 50 million of the social networks users.



Facebook is facing yet another controversy over how the social media company protects and secures the personal data of its users.
On Friday,
the company announced
that a vulnerability in the platforms View As feature exposed the data of about 50 million Facebook users to attackers. This feature allows users to view their Facebook profile as someone else.
The vulnerability allowed the attackers to steal the access tokens of users and take over those accounts and profiles. These access tokens are the digital keys that allow users to keep their profiles open without having to re-login into the site.
(Source:
Flickr
)
In its September 28 announcement, Facebooks Guy Rosen, vice president of Product Management, wrote that the investigation remains in its early stages and that law enforcement has been notified about the breach.
Security researchers at Facebook first noticed the security flaw on Tuesday, Sept. 25 and a patch has already been applied.
Facebook has already reset the tokens of the 50 million users targeted in the attack. In addition, the company reset the tokens of an additional 40 million users, meaning that some 90 million users will not have to re-log back in when going to their Facebook page.
All told, Facebook has about
2.23 billion users
worldwide.
Finally, Facebook is shutting down View As for the time being until the companys security review is complete. While its not clear what happened yet, Rosen wrote that an update the company rolled out to its video uploading feature in July 2017 created the vulnerability in the platform.
Since weve only just started our investigation, we have yet to determine whether these accounts were misused or any information accessed, Rosen wrote in a blog post. We also dont know whos behind these attacks or where theyre based. Were working hard to better understand these details -- and we will update this post when we have more information, or if the facts change. In addition, if we find more affected accounts, we will immediately reset their access tokens.
Chris Morales, the head of security analytics at Vectra, a San Jose-based provider of automated threat management tools, noted in an email that these types of vulnerabilities are common in software and that the more complex the platform, the more flaws there are. He added that Facebook did the right thing by alerting users as soon as possible.
All code has these forms of flaw that allow unintended use of software, and the more complex the software gets the more likely these type of flaws exist, Morales wrote in an email to Security Now. I do commend Facebook for identifying and responding to the compromise so quickly. It is unfortunate for users however, and it is also unfortunate for Facebook at a time when they under intense scrutiny along with the recent
departure of Facebooks CSO, Alex Stamos
.
Since the start of the year, Facebook has come under increasing scrutiny for how it secures and uses the vast trove of data it collects from its 2 billion users. Most recently, Facebooks
COO Sheryl Sandberg appeared before a congressional committee
to answer questions about election interference, how the company uses its data and how it moderates the online content users create.
Related posts:
Login With Facebook & Watch Your Personal Data Leak
Facebook Privacy Policy Is Under Investigation by FTC
In Facebook Debacle, More Than Zuckerberg to Blame
How to Access the Voter Information Dirt Cambridge Analytica Has on You
— Scott Ferguson is the managing editor of Light Reading and the editor of
Security Now
. Follow him on Twitter
@sferguson_LR
.

Last News

▸ IoT Devices on Average Have 25 Vulnerabilities ◂
Discovered: 23/12/2024
Category: security

▸ DHS-funded SWAMP scans code for bugs. ◂
Discovered: 23/12/2024
Category: security

▸ Debunking Machine Learning in Security. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
50M Facebook Accounts Exposed Due to Software Vulnerability