Random Things

Posts on anything and everything

Labels

Airlines Amazon Auto Electronics Entertainment Faith FB Finance Fix Things Food Gaming Geography Google HaHa's Health Information Mac Microsoft Military Movies Music News Personal Photography Politics Recalls Reviews Riddle Science Security SM Space Sports Tech Terms Thoughts Tools Travel Trivia Videos VR World News

Friday, September 28, 2018

FB Hacked; 50M People


Did You Get Logged Out of Facebook? It’s Because 50 Million People Got Hacked

LOWELL HEDDINGS  @lowellheddings 


The bad news for Facebook’s users just won’t end. Today Facebook had to admit that the accounts for 50 million people were somehow accessed by hackers abusing a little-known feature.

The “View As” feature gives you the ability to see what your profile looks like to somebody else—so you can check to see whether your privacy settings are being correctly applied, for example.
Hackers were able to abuse a security hole in this feature to steal access tokens to take over people’s accounts—basically, the login cookies that keep you logged in. This is not unlike the session hijacking attacks that were starting to be prevalent a number of years ago by people sniffing network traffic at hotspots. It’s one of the reasons you’d always want to use a VPN, and why the web has been switching to HTTPS. Except, in this case, the bug was in Facebook’s code so nothing could protect you.
The problem appeared to be in a video uploader for sending messages, which shouldn’t have shown on the View As page, but it did. Once that video uploader was opened, the bug would then essentially log the hacker in as the account that the profile was being viewed as. So they could then harvest everybody’s friends list, exploiting the bug to login as every single friend of a friend until 6 degrees of Kevin Bacon later, they had accessed 50 million accounts.

What You Need to Know

Details on this debacle are very thin at this point, but here are the things that we do know:
  • 50 million accounts were accessed.
  • Facebook logged out 90 million people to be safe.
  • This bug was fixed.
  • Taking over a session cookie will not let an attacker access your password.
  • We don’t know anything about how much data they were able to access or whether it affects third-party apps that use Facebook logins.
  • You’ll get a notice at the top of Facebook letting you know what happened.
  • There’s really nothing else you can do at this point.
Facebook has completely disabled the View As feature while they investigate how it all happened, how much data was lost, and how they can solve the problem going forward.
This data breach, combined with the recent news that Facebook is collecting shadow profiles and using your email address to target ads, is going to ramp up calls for GDPR-style regulation over these internet giants. As well it should.
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

Facebook Badge

Jim White

Create Your Badge

Followers

Subscribe To Random Things

Posts
Atom
Posts
Comments
Atom
Comments

Blog Archive

  • ►  2019 (697)
    • ►  April (23)
    • ►  March (166)
    • ►  February (188)
    • ►  January (320)
  • ▼  2018 (4481)
    • ►  December (343)
    • ►  November (346)
    • ►  October (385)
    • ▼  September (373)
      • Large, Aggressive Mosquitoes
      • Rare Two-headed Snake
      • FB uses Your Contacts
      • Coke Eying New Drinks
      • 'Softer' Music in the Gym
      • Financial News
      • Calorie-Burning Car
      • 4K Roku
      • Present
      • Lessons from a Superhero
      • Stay Focused
      • Your Identity
      • Movie Review - Smallfoot
      • Oldest Bronze Sculpture
      • World News
      • Artificial Tire Reefs
      • More Legroom
      • Get Better Sleep
      • College Football
      • Comcast Wins Bid
      • Beetle Is Dead
      • 504 Gateway Timeout Error
      • Elbows & Ears
      • Pure
      • A Spiritual Workout
      • FB Hacked; 50M People
      • World’s Busiest Airlines
      • Hat Could Be Worth Nothing
      • Biker Gang President
      • Fire w/out Trigger
      • Double-Front-Wheel 
Motorcycle
      • Family as Seriously as Work
      • New vs. Used Smartphones
      • Office 2019
      • Your Pay Going Down
      • Solution to Riddle of the Week
      • Go Away
      • Today's Encouragement
      • Fri Devotional
      • Movie Review - Night School
      • Freshman Blunder
      • No More Passwords
      • Amazon 4-star
      • Fed's Raise Rates
      • Snapchat & Amazon
      • President's New Limo
      • Movie Preview - Night School
      • Kind of Giving
      • Today's Encouragement
      • Thur Devotional
      • Chrome & Android
      • 3K Cashierless Stores
      • Hydrogen-Powered Trains
      • Stressed Out?
      • Dunkin' Donuts Change
      • Entertainment News
      • Michael Kors Buys Versace
      • Movie Preview - Smallfoot
      • Do You Pray?
      • Today's Encouragement
      • Wed Devotional
      • Alexa vs. Google vs. Siri
      • Box That Traps Light
      • Keto Diet
      • SiriusXM to Buy Pandora
      • Weight Watchers Name Change
      • Stealthy, Robotic Tankers
      • Movie Preview - Hell Fest
      • Netflix Running Ads?
      • Wise People
      • Today's Encouragement
      • Tues Devotional
      • Donated Coke
      • Scrabble Adds New Words
      • Internet Split
      • Drone Shot Down Drone
      • Entertainment News
      • Riddle of the Week
      • Weekend Box Office Results
      • Pushing the Red Button
      • Today's Encouragement
      • Monday Devotional
      • Movie Review - Assassination Nation
      • PlayStation Classic
      • Airlines Raise Fees
      • Internet Meme's
      • Cities Are Paying People
      • Overpriced Items
      • Health News
      • Entertainment News
      • Lightning Bolts
      • Bubbles
      • Grow
      • What You Should Do
      • JD Power's Best Airports 2018
      • Financial News
      • Personality Types
      • Gas-Powered Bike Hyperloop
      • Weekend in Las Vegas
      • Wild Electric Futuremobile
    • ►  August (386)
    • ►  July (385)
    • ►  June (359)
    • ►  May (378)
    • ►  April (384)
    • ►  March (396)
    • ►  February (353)
    • ►  January (393)
  • ►  2017 (4506)
    • ►  December (389)
    • ►  November (382)
    • ►  October (399)
    • ►  September (368)
    • ►  August (406)
    • ►  July (386)
    • ►  June (378)
    • ►  May (383)
    • ►  April (354)
    • ►  March (374)
    • ►  February (337)
    • ►  January (350)
  • ►  2016 (3443)
    • ►  December (353)
    • ►  November (360)
    • ►  October (365)
    • ►  September (338)
    • ►  August (329)
    • ►  July (331)
    • ►  June (332)
    • ►  May (356)
    • ►  April (342)
    • ►  March (316)
    • ►  February (21)

Who I B

Dubs
View my complete profile
Picture Window theme. Powered by Blogger.

Translate