Audio By Carbonatix
Facebook has moved quickly to shut down a loophole which made some accounts accessible without a password.
The bug was exposed in a message posted to the Hacker News website.
The message contained a search string that, when used on Google, returned a list of links to 1.32 million Facebook accounts.
In some cases clicking on a link logged in to that account without the need for a password. All the links exposed the email addresses of Facebook users.
Throwaway account
The message posted to Hacker News used a search syntax that exposed a system used by Facebook that lets users quickly log back in to their account.
Email alerts about status updates and notifications often contain a link that lets a user of the social network respond quickly by clicking it to log in in to their account.
In a comment added to the Hacker News message, Facebook security engineer Matt Jones said the links were typically only sent to the email addresses of account holders. Links sent in this way can only be clicked once.
"For a search engine to come across these links, the content of the emails would need to have been posted online," he wrote. Mr Jones suspected this is what happened as many of the email addresses exposed were for throwaway mail sites or for services that did a bad job of protecting archived messages.
Most of the million or so links exposed would already have expired, said Mr Jones.
"Regardless, due to some of these links being disclosed, we've turned the feature off until we can better ensure its security for users whose email contents are publicly visible," he said.
Mr Jones added that Facebook had taken steps to secure the accounts of people who had been exposed by the flaw. Many of the exposed accounts were in Russia and China.
Facebook has yet to issue an official comment on the bug.
DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
Tags:
DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
Latest Stories
-
Govt revives PBC, CPC; orders 50% of cocoa beans for local processing – Ato Forson
4 minutes -
Govt orders immediate payment to cocoa farmers, plans new COCOBOD bill
21 minutes -
2026 World Cup: Mohammed Salisu ruled out with ACL injury – Dr Pambo confirms
23 minutes -
Ghana’s growth slows to 4.2% in November as industry falters
27 minutes -
ECG intensifies bushfire prevention campaign in Volta and Oti Regions
34 minutes -
‘Empty promises’ and environmental peril: Bogoso-Prestea mine host communities demand removal of Heath Goldfields
38 minutes -
Contractor on Takoradi-Agona Nkwanta dualisation project bemoans persistent attacks on workers Â
39 minutes -
Keta Municipal Assembly intensifies community clean-up exercise with strong public participation
40 minutes -
Voting in The Hague: Chemical weapons and principles
47 minutes -
Ghana AIDS Commission to distribute condoms nationwide on February 13 ahead of Val’s Day
51 minutes -
MOFFA shuts down Winneba, Cape Coast and Abura-Dunkwa Hospital morgues over safety breaches
57 minutes -
95% of family businesses fail before the third generation – IFC urges governance reforms
60 minutes -
Foreign Affairs Ministry, Nuclear Power Ghana deepen cooperation on energy diplomacy
1 hour -
Trade, Finance Ministers engage cocoa processors on new value-addition reforms
1 hour -
Ashanti RCC tightens rules on mining area levies following ‘galamsey tax’ exposé
1 hour
