Categories: General

Facebook security breach: Up to 50m accounts attacked

Image copyright
Reuters

Facebook has said “almost 50 million” of its users were left exposed by a security flaw.

The company said attackers were able to exploit a vulnerability in a feature known as “View As” to gain control of people’s accounts.

The breach was discovered on Tuesday, Facebook said, and it has informed police.

Users that had potentially been affected were prompted to re-log-in on Friday.

The flaw has been fixed, wrote the firm’s head of security, Guy Rosen, adding all affected accounts had been reset, as well as another 40 million “as a precautionary step”.

Facebook – which saw its share price drop more than 3% on Friday – has more than two billion active monthly users.

Who has been affected?

The firm would not say where in the world the 50 million users are, but it has informed Irish data regulators, where Facebook’s European subsidiary is based.

Users that had potentially been affected were prompted to re-log-in on Friday. However, the company said users did not have to change their passwords.

“Since we’ve only just started our investigation, we have yet to determine whether these accounts were misused or any information accessed. We also don’t know who’s behind these attacks or where they’re based. “

He added: “People’s privacy and security is incredibly important, and we’re sorry this happened.”

What is ‘View As’?

Facebook’s “View As” function is a privacy feature that allows people to see what their own profile looks to other users, making it clear what information is viewable to their friends, friends of friends, or the public.

Attackers found multiple bugs in this feature that “allowed them to steal Facebook access tokens, which they could then use to take over people’s accounts”, Mr Rosen explained.

“Access tokens are the equivalent of digital keys that keep people logged in to Facebook so they don’t need to re-enter their password every time they use the app,” he added.

What does this mean for Facebook?

The breach comes at a time when the firm is struggling to convince lawmakers in the US and beyond, that it is capable of protecting user data.

Facebook founder Mark Zuckerberg said on a conference call on Friday that the firm took security seriously, in the face of what he said were constant attacks by bad actors.

But Jeff Pollard, vice-president and principal analyst at Forrester, said the fact Facebook held so much data meant it should be prepared for such attacks.

“Attackers go where the data is, and that has made Facebook an obvious target,” he said. “The main concern here is that one feature of the platform allowed attackers to harvest the data of tens of millions of users.

“This indicates that Facebook needs to make limiting access to data a priority for users, APIs, and features.”


Has your Facebook account been affected? You can share your experience by emailing haveyoursay@bbc.co.uk.

Please include a contact number if you are willing to speak to a BBC journalist. You can also contact us in the following ways:



Source by [author_name]

Share
Published by

Recent Posts

TEST: Living Like a RockStar: Get in Front of YOUR Money (Part 4)

TEST... If it is alright with you, would it not be better to make it…

2 years ago

TEST: Living Like a RockStar: Zero Fear Selling & Having it YOUR Way (Part 5)

TEST... Would it be okay with you if selling was just easy? Would you be…

2 years ago

TEST: Where To Get No Cost Royalty Free Music For Your Videos

TEST... Adding music to your videos can help to increase engagement, sales and more. We…

2 years ago

TEST: Today We Talk About Needs in Ben’s Ride Along video

TEST... This is very rarely discussed. And it is one of the most powerful things…

2 years ago

TEST: Sell These Videos For $500 or More Each?

TEST... In this video, I show you (Watch Over My Shoulder Style) how you can…

2 years ago

TEST: The “Shell Shock Habit” – RockStar Entrepreneur

TEST... More times than not, you may find that the thing holding you back has…

2 years ago