Facebook has reset the passwords of 90 million of its user accounts after discovering a very serious vulnerability in the “view as” feature. View as is a feature on each user’s profile that allows them to see what their profile will look like when visited by a friend.

According to Guy Rosen, Facebook's vice president of product management, the vulnerability was discovered on September 25 and affected nearly 50 million accounts. He said that using the view as feature could steal access tokens, which could then be used to gain access to other accounts.
“Access tokens are something similar to the password that each user must enter when logging in. Access tokens are used when the user does not log out when leaving the website, so that on their next visit they are already logged in.”
Rosen confirmed that the vulnerability has been fixed, and access tokens have been changed for 50 million accounts, as well as another 40 million accounts as a precaution.
“This vulnerability was the result of several security holes in our code. Hackers could initially “steal” an account through their own account, and then, by logging into the stolen account, steal others using the same technique.” He admitted that he did not know how many accounts were compromised in this way, but said that the authorities have been informed.
This bad news comes at the end of a pretty bad week for Facebook, after Instagram founders left the company due to a disagreement with Zuckerberg.
