HomeinetFacebook hacked, be careful, change your password

Facebook hacked, be careful, change your password

An unusually high traffic on the site's processes alerted Facebook engineers that something might be wrong. After investigating the increased activity, they discovered a massive security breach on the largest social network.Facebook
Facebook confirmed this (loosely) earlier todayin a press release. The company said that hackers managed to steal tokens from about 50 million users.
Access tokens are alphanumeric codes that are generated when a user logs in and are stored simultaneously in the user's browser and on Facebook's servers. They are used to allow users to access Facebook without the user having to log in each time they visit. Access tokens, or access tokens, are controlled by Facebook's servers.
Facebook said earlier that today hackers managed to obtain access tokens for 50 million users by exploiting a vulnerability in "View As," a feature on every Facebook user's profile that allows you to see what your account looks like to someone else.
According to Facebook engineers, the social network made a code change in July 2017 to the “View as” feature. The exploit was first reported on September 16. September 16 is the day Facebook believes hackers began exploiting the flaw to gain access to the “View As” feature and obtain access tokens for users’ accounts.
The access token harvesting feature caused a massive spike in traffic on Facebook’s servers. In addition to the traffic, Facebook engineers realized what was happening on September 26. They began investigating it on September 27, and announced their findings this morning.
Facebook held a conference call with reporters this morning and answered general questions. Nathaniel Gleicher, head of security policy, and Guy Rosen said that the vulnerability in the View As feature was actually a combination of three bugs.
“The vulnerability we fixed was the result of three separate bugs and was disclosed in July 2017.”
“The first bug was when you were using the View As product, the video uploader shouldn’t have been showing up at all, but in a very specific case, on posts that encouraged people to wish Happy Birthday, it was showing up.
Now, the second bug was that this video uploader was incorrectly using SSO to create an access token that granted permissions to the Facebook mobile app. Of course, that’s not how SSO was intended to be used.
The third problem was that when the video uploader was previously showing up as View As, which it didn’t, except in the case of the first bug, then it was creating an access token, which again shouldn’t have been granted. The second bug was creating the access token not for you as a viewer, but for some other user.
“So it’s the combination of those three bugs that created a vulnerability,” Rosen said. “This vulnerability was discovered by hackers and they used it to obtain access credentials. Then, every time they had an access ID, they used it and received more tokens from the user’s friends who had accessed their account.
Of course, after all of the above, you shouldn’t wait. Log in to your account and check Security and login. The page will show you all the devices connected to your account, as well as their geographical location. Disconnect any you don’t know and change your password as a precaution.
_____________

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS