Facebook social media app logo on log-in, sign-up registration page on mobile app screen on iPhone smart devices in business person’s hand at work from Shutterstock.com

Facebook users were shocked as the news spread about how nearly 50 million Facebook accounts were compromised by an attack that gave hackers the ability to take over users’ accounts.

Social-media giant, Facebook shared that its company’s engineers discovered the breach on Tuesday (25 September).

In a blog post, Facebook stated that a vulnerability in the site’s “View As” feature, which lets users see what their profile looks like from someone else’s view, allowed an attacker to steal access tokens, a kind of security key that allows users to stay logged into Facebook over multiple browsing sessions without entering their password every time.

Access tokens are the equivalent of digital keys that keep people logged in to Facebook so they don’t need to re-enter their password every time they use the app.

Due to the hack, Facebook has already reset these access tokens.

The company stated that this means that if you were affected by the hack, you’ll notice that you have been automatically logged out of your Facebook account, as well as any other apps that use Facebook to login.

On the blog post, Guy Rosen, VP of Product Management, stated that the company has reset the access tokens of the almost 50 million accounts which were affected to protect their security.

Facebook also taking the precautionary step of resetting access tokens for another 40 million accounts that have been subject to a “View As” look-up in the last year.

As a result, the Facebook said that around 90 million people will now have to log back in to Facebook, or any of their apps that use Facebook Login. After they have logged back in, people will get a notification at the top of their News Feed explaining what happened.

Although you will to have to log back into your account, you do not have to change your passwords, Facebook added.

However, several Business Insider reporters who were required to log back into their accounts told the media that they did not see any type of message upon reentry.

The company then stated that the source of the vulnerability, the “View As” feature, has been disabled for the time being, adding that the feature became open to attack in July 2017 when Facebook edited its video uploading.

If you try to access the “View As” feature now, an error message appears saying that it has been “temporarily disabled”.

The incident is believed to be the largest in Facebook’s history.

On Friday morning, Facebook CEO Mark Zuckerberg held a press conference regarding the matter.

“I’m glad we found this and fixed the vulnerability. But it definitely is an issue that this happened in the first place. I think this underscores the attacks that our community and our services face,” Mr Zuckerberg said.

Mr Zuckerberg also wrote a post on his Facebook account regarding the matter.

“We face constant attacks from people who want to take over accounts or steal information around the world. While I’m glad we found this, fixed the vulnerability, and secured the accounts that may be at risk, the reality is we need to continue developing new tools to prevent this from happening in the first place,” he wrote.

The vice-president of product management, Guy Rosen, also spoke on the conference, saying that the company has notified and was working with the FBI. However, he did not comment on whether national security agencies were involved in the investigation.

“The investigation is early, and it’s hard to discover who is behind this. We may never know,” Mr Rosen said, adding that he did note that the scale and complexity of the hack would have required “a certain level” of expertise.

Mr Rosen, however, did not provide any details on the location of users affected, saying only that the attack seemed “broad” and investigators had not determined whether there were particular targets.

According to news media, the company has notified the Irish Data Protection Commission (DPC) about the breach. The implementation of Europe’s General Data Protection Regulation (GDPR) meant that Facebook was required to notify data protection authorities within 72 hours if any affected users were in the European Economic Area.

Subscribe
Notify of
0 Comments
Inline Feedbacks
View all comments
You May Also Like

马国:禁从中国港口离境、过境邮轮入马

马来西亚政府宣布,禁止任何中国港口离境或过境的邮轮,入境马国。 迄今马国的武汉冠状病毒确诊病例已增至22起。马国此前禁止任何不愿与执法单位分享重要资讯的外国船只入境。 与此同时,马国政府也不允许那些仍在柬埔寨的“威士特丹号”乘客,进入我国。 “威士特丹号”本月1日从香港出发,载有2257名乘客,包括1455名乘客和802名船员。 但连日来“威士特丹号”遭多国政府拒绝靠岸。直至13日才成功获得柬埔寨政府允准停靠柬埔寨西哈努克港。一些乘客则获安排转机到马国,准备返国。不过飞到马国的145名乘客中,其中一名83岁美国女乘客经测试确诊患病,致使多达六人被拒登机。 不过其余六名乘客(4名美国人和2名荷兰人)对武汉新冠病的检测,皆呈阴性。

鄞义林:比较台湾和新加坡的公共医疗服务

鄞义林撰文,北雁译 在亚洲新闻台看到一篇文章,提到名为Serynn Guay的34岁女青年,她其中一项烦恼,是“无法预测”的医疗开销。 她说,“我们不知道当我们年纪大些时,究竟需要多少才够用… 我们能安稳地退休吗?我们的积蓄是否足够?” 她补充,“有可能接下来20年都要继续工作,即使孩子已经大学毕业,我们还要继续为储蓄退休和其他生活开销打拼。” 这里让我和大家分享台湾的情况。 在台湾,医疗保健是免费的,在现有的国家保健和退休计划下,一个从现在起工作40年的人,大约能以现有薪资的60巴仙养老。 所以,台湾人不会感受到新加坡人一样的忧虑。他们知道只要身体不适,都能接受有素质的医疗服务,无需感到恐惧,或担心负担不起而不敢去看医生。 他们也知道,到了退休年龄就真的可以退休,他们也很向往退休生活。 但是在我国,国人缴税、也支付保健储蓄和终身健保,但是还是很怕看医生。 在台湾,员工只需为医疗保险支付薪资的一巴仙,就能享有免费医疗保健。但是在新加坡,我们把薪资的8-10.5巴仙都放入保健储蓄,也不能享有完全免费的医保。而且,还要自掏腰包负担最昂贵的医疗服务。…

CCCS issues Infringement Decision against the exchange of commercially sensitive information between competing hotels

An Infringement Decision (“ID”) against the owners or operators of Capri by Fraser…

Minister Desmond Lee refutes the claim that Singapore isn’t doing enough to reduce inequality

Social & Family Development Minister Desmond Lee responded to the recently released…