- The 2020 guide to live TV streaming for cord cutters 1 Year Ago
- Popular dating app Growlr just suspended its users 1 Year Ago
- Apple warns coronavirus expected to cause iPhone ‘supply shortages’ Monday 7:59 PM
- Will ‘The Bachelor’ end without an engagement? Monday 7:44 PM
- This ‘Little Women’ scene just became a meme Monday 7:03 PM
- Playable version of Blizzard’s ‘StarCraft: Ghost’ leaks online nearly 15 years after cancelation Monday 6:31 PM
- This Twitter extension can block unsolicited nudes from your inbox Monday 6:01 PM
- Jeffree Star wears cornrows after being accused of cultural appropriation Monday 4:49 PM
- Jeff Bezos says he’ll commit $10 billion to combat climate change Monday 4:18 PM
- A TikTok user went on a mission to turn his urine blue by chugging food coloring Monday 3:55 PM
- YouTuber’s vacation in ‘Bali’ was actually staged at Ikea Monday 3:14 PM
- Video shows liquor store manager calling employee ‘f*cking worthless’ Monday 1:16 PM
- Instagram influencer scams followers out of $1.5 million Monday 12:22 PM
- Why did the Israeli military tweet this thirst trap? Monday 10:43 AM
- Jake Paul wants you to have financial freedom… by paying him a monthly fee Monday 10:40 AM
Facebook announced Friday that it discovered a data breach affecting at least 50 million users. While the company has figured out how the attackers exploited the site, the identity and location of this Facebook data breach, which happened on Tuesday, Sept. 25, are still under investigation.
The hackers were able to penetrate Facebook thanks to a bug in its “view as” tool. This feature lets users view their Facebook profile as if they were a stranger or a particular friend—a security measure for checking profile privacy settings.
According to the New York Times, that bug was paired with another in the app’s video-uploading system (a happy birthday video uploading tool, to be specific). This let attackers steal access tokens to user accounts. (Facebook explains that access tokens “are the equivalent of digital keys that keep people logged in to Facebook so they don’t need to re-enter their password every time they use the app.”) Once the hackers obtained these keys, they gained the ability to take over other user accounts.
Since discovering this Facebook data breach, the company has fixed the vulnerability. As a precautionary measure, the company also logged out and reset the access tokens of 90 million users Friday morning, requiring them to log back in and reconnect Facebook-connected apps. Once affected users log back in, a notice at the top of their feed will explain the situation. Users don’t need to reset their passwords—at this point, there’s no evidence that passwords were compromised, only user access tokens.
Facebook has reported the data breach to authorities as it continues to investigate its origins and extent. In the meantime, it’s switched off the “view as” feature while it undergoes a security review.
“Since we’ve only just started our investigation, we have yet to determine whether these accounts were misused or any information accessed,” Facebook VP of Product Management Guy Rosen wrote in a blog post. “We also don’t know who’s behind these attacks or where they’re based. We’re working hard to better understand these details.”
Since the Cambridge Analytica scandal surfaced earlier this year, Facebook has been scrambling to polish its image and regain user trust. It’s run a series of ads apologizing for its past behavior, and made efforts to make its privacy controls more simple and clear to understand.
H/T the New York Times
Christina Bonnington is a tech reporter who specializes in consumer gadgets, apps, and the trends shaping the technology industry. Her work has also appeared in Gizmodo, Wired, Refinery29, Slate, Bicycling, and Outside Magazine. She is based in the San Francisco Bay Area and has a background in electrical engineering.