Home » Hack, Privacy

Facebook Fixes Privacy Issue – Full Disclosure of User Information

Submitted by on August 15, 2010 – 1:22 AMNo Comment
Facebook Fixes Privacy Issue – Full Disclosure of User Information

On August 11, 2010, a researcher post information about a bug in Facebook’s login process that revealed the full name, email address and profile picture of all 500 plus million Facebook account holders regardless of your privacy setting. The bug has recently been repaired by Facebook, but posed enormous privacy threat for Facebook users prior to the fix being implemented.

The issue stemmed from how Facebook assist the user when they attempt to login after an unsuccessful attempt. Facebook returns a special “Please re-enter your password” page, which includes the Facebook photo and full name of the person associated with their email address.  This information can be used by hackers to obtain proper information about Facebook user and can be scripted to automate the process.

What made it more interesting this bug allowed anyone, even those without an account, to obtain this information about Facebook users.

Share

Leave a comment!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.