Select date

May 2024
Mon Tue Wed Thu Fri Sat Sun

EVERYTHING YOU NEED TO KNOW ABOUT THE 50 MILLION FACEBOOK ACCOUNTS THAT WERE RECENTLY HACKED

30-9-2018 < SGT Report 142 674 words
 

by Geoffrey Grinder, Now The End Begins:


Facebook is cleaning up after a major security incident exposed the account data of millions of users. What’s already been a rocky year after the Cambridge Analytica scandal, the company is scrambling to regain its users trust after another security incident exposed user data.


Last summer, hackers pulled off a huge hack on over 50 million Facebook accounts. You may have noticed that today you could not access your account, had trouble getting in, or received a message from Facebook telling you about an issue. This is the reason for all the commotion.



Even if your account is not of the ones affected, now would be a good time to do things like change your password, switch to two-step authentication, and other housekeeping cleanup you may have been neglecting.


WHAT HAPPENED?


Facebook says at least 50 million users’ data were confirmed at risk after attackers exploited a vulnerability that allowed them access to personal data. The company also preventively secure 40 million additional accounts out of an abundance of caution.


WHAT DATA WERE THE HACKERS AFTER?


Facebook CEO Mark Zuckerberg said that the company has not seen any accounts compromised and improperly accessed — although it’s early days and that may change. But Zuckerberg said that the attackers were using Facebook developer APIs to obtain some information, like “name, gender, and hometowns” that’s linked to a user’s profile page.



WHAT DATA WASN’T TAKEN?


Facebook said that it looks unlikely that private messages were accessed. No credit card information was taken in the breach, Facebook said. Again, that may change as the company’s investigation continues.


WHAT’S AN ACCESS TOKEN? DO I NEED TO CHANGE MY PASSWORD?


When you enter your username and password on most sites and apps, including Facebook, your browser or device is set an access tokens. This keeps you logged in, without you having to enter your credentials every time you log in. But the token doesn’t store your password — so there’s no need to change your password.


IS THIS WHY FACEBOOK LOGGED ME OUT OF MY ACCOUNT?


Yes, Facebook says it reset the access tokens of all users affected. That means some 90 million users will have been logged out of their account — either on their phone or computer — in the past day. This also includes users on Facebook Messenger.


WHEN DID THIS ATTACK HAPPEN?


The vulnerability was introduced on the site in July 2017, but Facebook didn’t know about it until this month, on September 16, 2018, when it spotted a spike in unusual activity. That means the hackers could have had access to user data for a long time, as Facebook is not sure right now when the attack began.


WHO WOULD DO THIS?


Facebook doesn’t know who attacked the site, but the FBI is investigating, it says.


However, Facebook has in the past found evidence of Russia’s attempts to meddle in American democracy and influence our elections — but it’s not to say that Russia is behind this new attack. Attribution is incredibly difficult and takes a lot of time and effort. It recently took the FBI more than two years to confirm that North Korea was behind the Sony hack in 2016 — so we might be in for a long wait.


HOW DID THE ATTACKERS GET IN?


Not one, but three bugs led to the data exposure.


In July 2017, Facebook inadvertently introduced three vulnerabilities in its video uploader, said Guy Rosen, Facebook’s vice president of product management, in a call with reporters. When using the “View As” feature to view your profile as someone else, the video uploader would occasionally appear when it shouldn’t display at all. When it appeared, it generated an access token using the person who the profile page was being viewed as. If that token was obtained, an attacker could log into the account of the other person.


Read More @ NowTheEndBegins.com





Loading...




Print