HT TECH wants to start sending you push notifications. Click allow to subscribe

Facebook says 50 million users affected by security breach

Facebook says hackers took advantage of its “View As” feature to take over user’s accounts but said it has fixed the problem

By: KUL BHUSHAN
Updated on: Aug 20 2022, 10:59 IST
The company says hackers exploited the “View As” feature on Facebook. (REUTERS)

Almost 50 million Facebook accounts were affected by a major cyber security breach, the social networking company said on Friday. Facebook said it has already fixed the vulnerability and informed law enforcement.

The company said it had discovered a loophole in the "View As" feature which allowed cyber criminals to gain control of the affected accounts. "View As" is a popular Facebook feature that allows users to see what their profiles look like to others. As a precaution, Facebook has temporarily disabled the feature.

You may be interested in

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
28% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹107,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,990₹74,999
Buy now
41% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹52,990₹89,999
Buy now
41% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹34,490₹57,999
Buy now
40% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,380₹51,990
Buy now
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹25,999
Check details
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,674₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹16,998
Check details

"On the afternoon of Tuesday, September 25, our engineering team discovered a security issue affecting almost 50 million accounts. We're taking this incredibly seriously and wanted to let everyone know what's happened and the immediate action we've taken to protect people's security," said Guy Rosen, VP of Product Management at Facebook, in a blog post.

Also read: Looking for a smartphone? To check mobile finder click here.

How did it work?

Facebook says attackers exploited a "vulnerability" in Facebook's code that impacted "View As", a feature that lets people see what their own profile looks like to someone else. This allowed them to steal Facebook access tokens which they could then use to take over people's accounts."

Access tokens are similar to digital keys that allows users to stay logged into Facebook in the background and don't need them to re-enter their password every time they launch the application on their phone or use it on a browser.

"This attack exploited the complex interaction of multiple issues in our code. It stemmed from a change we made to our video uploading feature in July 2017, which impacted "View As." The attackers not only needed to find this vulnerability and use it to get an access token, they then had to pivot from that account to others to steal more tokens," Facebook added.

Saket Modi, CEO and co-founder at Lucideus cyber security firm, explains that hackers were able to fool Facebook servers to believe they were the authorised users of the target's account, thus giving the attackers full control and access of the affected account.

"Facebook would have a log of the number of user profiles this feature was used to access, whose tokens they have reset (or the previous session has expired) as per their statement. However, we don't know for how long the vulnerability existed, who the hacker(s) were and the extent of damage that might have been caused in terms of stealing not only one's profile data(which was in the case of Cambridge Analytica) but in this case potentially, the personal messages, every picture (even the ones hidden from friends/public), chats on messenger among others," he added.

Sophos Principal Research Scientist at Chester Wisniewski said, "In something as big and complicated as Facebook, there are bound to be bugs. The theft of these authorization tokens is certainly a problem, but not nearly as big of a risk to user's privacy as other data breaches we have heard about or even Cambridge Analytica for that matter. As with any social media platform, users should assume their information may be made public, through hacking or simply through accidental oversharing. This is why sensitive information should never be shared through these platforms. For now, logging out and back in is all that is necessary. The truly concerned should use this as a reminder and an opportunity to review all of their security and privacy settings on Facebook and all other social media platforms they share personal information with."

What should users do?

Facebook says users don't need to reset their passwords as they will reset token accounts in the background if it finds more accounts affected by the breach.

"People's privacy and security is incredibly important, and we're sorry this happened. It's why we've taken immediate action to secure these accounts and let users know what happened. There's no need for anyone to change their passwords. But people who are having trouble logging back into Facebook — for example because they've forgotten their password — should visit our Help Center," said Facebook.

One of the measures that Facebook users can take right now is to log out of all sessions (if using multiple devices) and log in again. Or they can simply reset your passwords right now and add two-step verification.

Users may also revisit the privacy settings of their recent posts and photos as Facebook has disabled the "View As" feature.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 28 Sep, 22:43 IST
Tags:

Sale

Mobiles Tablets Laptops
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
11% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹79,800₹89,900
Buy now
57% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹19,999₹47,000
Buy now
28% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
27% OFF
Samsung Galaxy Tab S8
  • Silver
  • 8 GB RAM
  • 128 GB Storage
₹59,999₹81,999
Buy now
21% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹88,858₹113,098
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
22% OFF
Asus ROG Strix G15 G513RC HN085WS Laptop
  • Electro Punk
  • 16 GB RAM
  • 1 TB SSD
₹70,990₹90,990
Buy now
30% OFF
Asus ROG Strix G15 G513QY HQ032WS Laptop
  • Original Black
  • 16 GB RAM
  • 1 TB SSD
₹79,990₹113,990
Buy now
33% OFF
Asus VivoBook Go 15 OLED E1504GA NJ323WS Laptop
  • Green Grey
  • 8 GB RAM
  • 512 GB SSD
₹33,990₹50,990
Buy now