Facebook social media app logo on log-in, sign-up registration page on mobile app screen on iPhone smart devices in business person’s hand at work from Shutterstock.com

Facebook users were shocked as the news spread about how nearly 50 million Facebook accounts were compromised by an attack that gave hackers the ability to take over users’ accounts.

Social-media giant, Facebook shared that its company’s engineers discovered the breach on Tuesday (25 September).

In a blog post, Facebook stated that a vulnerability in the site’s “View As” feature, which lets users see what their profile looks like from someone else’s view, allowed an attacker to steal access tokens, a kind of security key that allows users to stay logged into Facebook over multiple browsing sessions without entering their password every time.

Access tokens are the equivalent of digital keys that keep people logged in to Facebook so they don’t need to re-enter their password every time they use the app.

Due to the hack, Facebook has already reset these access tokens.

The company stated that this means that if you were affected by the hack, you’ll notice that you have been automatically logged out of your Facebook account, as well as any other apps that use Facebook to login.

On the blog post, Guy Rosen, VP of Product Management, stated that the company has reset the access tokens of the almost 50 million accounts which were affected to protect their security.

Facebook also taking the precautionary step of resetting access tokens for another 40 million accounts that have been subject to a “View As” look-up in the last year.

As a result, the Facebook said that around 90 million people will now have to log back in to Facebook, or any of their apps that use Facebook Login. After they have logged back in, people will get a notification at the top of their News Feed explaining what happened.

Although you will to have to log back into your account, you do not have to change your passwords, Facebook added.

However, several Business Insider reporters who were required to log back into their accounts told the media that they did not see any type of message upon reentry.

The company then stated that the source of the vulnerability, the “View As” feature, has been disabled for the time being, adding that the feature became open to attack in July 2017 when Facebook edited its video uploading.

If you try to access the “View As” feature now, an error message appears saying that it has been “temporarily disabled”.

The incident is believed to be the largest in Facebook’s history.

On Friday morning, Facebook CEO Mark Zuckerberg held a press conference regarding the matter.

“I’m glad we found this and fixed the vulnerability. But it definitely is an issue that this happened in the first place. I think this underscores the attacks that our community and our services face,” Mr Zuckerberg said.

Mr Zuckerberg also wrote a post on his Facebook account regarding the matter.

“We face constant attacks from people who want to take over accounts or steal information around the world. While I’m glad we found this, fixed the vulnerability, and secured the accounts that may be at risk, the reality is we need to continue developing new tools to prevent this from happening in the first place,” he wrote.

The vice-president of product management, Guy Rosen, also spoke on the conference, saying that the company has notified and was working with the FBI. However, he did not comment on whether national security agencies were involved in the investigation.

“The investigation is early, and it’s hard to discover who is behind this. We may never know,” Mr Rosen said, adding that he did note that the scale and complexity of the hack would have required “a certain level” of expertise.

Mr Rosen, however, did not provide any details on the location of users affected, saying only that the attack seemed “broad” and investigators had not determined whether there were particular targets.

According to news media, the company has notified the Irish Data Protection Commission (DPC) about the breach. The implementation of Europe’s General Data Protection Regulation (GDPR) meant that Facebook was required to notify data protection authorities within 72 hours if any affected users were in the European Economic Area.

Subscribe
Notify of
0 Comments
Inline Feedbacks
View all comments
You May Also Like

Reader says ST edited his letter out of context to support Govt's call not to wear masks if one is well

In Jan this year when the coronavirus outbreak started to unfold, a…

HDT Singapore Taxi to double its fleet by June

Newcomer taxi operator, HDT Singapore Taxi, has announced that it will double…

受性骚扰国际生分享经历 “沉默只助打造犯罪者避风港”

性骚扰课题不只限于我国,且无孔不入,不分地点、对象的发生性骚扰事件,是全球共同面对的新挑战。一名香港大学的前国际学生就在其Instagram上分享过她的经历、感受和想法,而且对校方、对同窗的举止感到寒心和感慨。她说了, “你的沉默,为那些潜在犯罪者在手握权力并持续滥用时,制造了安全的避风港。” 这名前国际学生目前已离开香港,她之前在港大牙科就读,而被指肇案者却是她的导师,是首批自港大毕业的牙医,曾任部门的代理主管,并且在学院中教学多年,教科主任也曾是他的学生。 网上分享经过却无人关注 受害者在决定分享其经历之前,也是有挣扎的,“我数周前就想发布这帖文了,但是退缩了:我很害怕。密友一直告诉我,如果我要公布它,我必须站起来;如果我希望它具影响力,我必须成为背后的声音,让人们能够更好地联系起来” 。 事实上,她曾再Instagram分享了部分故事,但未获得很多关注,只有四人分享。她唯有直接联系看过帖文的朋友,请他们帮忙将故事分享到脸书上。 但她也理解到,在香港这个享有“抗议之城”名称的国家,人们对于性骚扰课题,却似乎显得非常胆怯和沈默。而她的内心深处,也觉得自己是个失败者,甚至要腆着脸去求别人分享自己被性骚扰的事迹。 自责自问为何不叫对方停手 她指出被性骚扰后,肇事者的存在就令她感到毛骨悚然。受害者指肇事者盯着她胸部看的方式、抓着她肩膀的方式、猥亵的笑话或语言,甚至指受害者应找个已婚男,并暗示自己就是已婚男的种种,都令她脊椎发冷。“不是我太过拘谨,但是我的直觉告诉我他这么做是不适合的,尤其他身为一名教师。当我看到他在诊所喝酒、看似沉醉时,我对他的恐惧加剧了,我告诉我的护士,不要让我一个人、没人看顾。” 根据她的文章中,她也分享了受到性骚扰后的影响。她在受到骚扰时似乎被吓呆了,一度以为是自己反应过度、怀疑是自己的问题,甚至自责、自问为什么没叫对方停手等,感到愤怒和沮丧。 在面对这个创伤时,一部分的她感觉像是受害者、一部分觉得自己像白痴,还有一部分要求正义获得声张。她当时自责,也觉得需要负责任。她不仅因此感到被羞辱,内心深处也感到非常羞愧,因为不能为了自己站起来,并且无法控制一切所发生的。“因为我觉得无助和无力,我失眠、没胃口、哭着睡觉、周末不愿外出、心跳加速并且在想到会在校外遇见他时,感到不能呼吸。我无法专注。”…

Dr Tan Cheng Bock calls Minister K Shanmugam a “bully” in the way he addressed PSP’s Leong Mun Wai in Parliament

The chairman of Progress Singapore Party (PSP) Dr Tan Cheng Bock has…