IDNetters Forums

Technical News & Discussion => Windows News & Discussion => Topic started by: DorsetBoy on May 11, 2011, 18:37:51

Title: Facebook caught exposing millions of user credentials
Post by: DorsetBoy on May 11, 2011, 18:37:51
  App bug overrides user privacy settings (http://www.theregister.co.uk/2011/05/10/facebook_user_credentials_leaked/)


QuoteFacebook has leaked access to millions of users' photographs, profiles and other personal information because of a years-old bug that overrides individual privacy settings, researchers from Symantec said.

The flaw, which the researchers estimate has affected hundreds of thousands of applications, exposed user access tokens to advertisers and others. The tokens serve as a spare set of keys that Facebook apps use to perform certain actions on behalf of the user, such as posting messages to a Facebook wall or sending RSVP replies to invitations. For years, many apps that rely on an older form of user authentication turned over these keys to third parties, giving them the ability to access information users specifically designated as off limits.

The Symantec researchers said Facebook has fixed the underlying bug, but they warned that tokens already exposed may still be widely accessible..... (more)
Title: Re: Facebook caught exposing millions of user credentials
Post by: Rik on May 11, 2011, 18:40:32
Another reason not to like the thing. ;)
Title: Re: Facebook caught exposing millions of user credentials
Post by: Simon on May 11, 2011, 19:38:16
Oops!
Title: Re: Facebook caught exposing millions of user credentials
Post by: Rik on May 12, 2011, 08:47:31
That's being kind.  :)
Title: Re: Facebook caught exposing millions of user credentials
Post by: Glenn on May 12, 2011, 08:56:48
Don't run Facebook on an Apple, or you could have a Flasher Mac  :out: :hide:
Title: Re: Facebook caught exposing millions of user credentials
Post by: Rik on May 12, 2011, 09:10:40
:grn:
Title: Re: Facebook caught exposing millions of user credentials
Post by: Gary on May 12, 2011, 09:29:08
Facebook deny it of course, but just changing the password sorts the issue, and its apps that caused it, if you dont use them, you were fine. Not a reason to not like it, but another reason to use your brain a bit, changing passwords often helps anyway, I use 1Password for the Mac, great thing to have.
Title: Re: Facebook caught exposing millions of user credentials
Post by: Simon on May 12, 2011, 10:06:51
:clever: ;D