- Trump retweeted a QAnon supporter during his Twitter bender Today 1:24 PM
- Katrina Pierson supports Trump tweeting more about Fox than New Zealand shooting Today 1:19 PM
- PewDiePie’s alt-right ties are impossible to ignore Today 1:05 PM
- With this blade, I protect this meme Today 12:48 PM
- Lead actress in ‘The Color Purple’ revival criticized for homophobic post Today 12:39 PM
- ‘Arrested Development’ ends the same way it did the first time—unceremoniously Today 12:10 PM
- Alleged gunman tried to rob YouTuber Adam22 during livestream Today 11:32 AM
- Turkish president used New Zealand shooting footage at campaign rallies Today 11:09 AM
- 8 adorable tea infusers that will warm you with cuteness Today 10:26 AM
- The Super Nintendo Pro is the wireless controller of your dreams Today 10:25 AM
- Lori Loughlin reportedly dropped from ‘Fuller House’ final season Today 10:10 AM
- The Legend of Zelda Encyclopedia Deluxe Edition is a true treasure Today 10:00 AM
- Even Republicans are angry with the GOP’s anti-Beto tweet Today 10:00 AM
- ‘Egg Boy’ vows to send GoFundMe money to mosque shooting victims Today 9:55 AM
- Noom is a weight loss program that prioritizes your mental health Today 9:10 AM
TY Lim/Shutterstock (Licensed)
If you got logged out of your account this morning, you were affected.
Facebook announced Friday that it discovered a data breach affecting at least 50 million users. While the company has figured out how the attackers exploited the site, the identity and location of this Facebook data breach, which happened on Tuesday, Sept. 25, are still under investigation.
The hackers were able to penetrate Facebook thanks to a bug in its “view as” tool. This feature lets users view their Facebook profile as if they were a stranger or a particular friend—a security measure for checking profile privacy settings.
According to the New York Times, that bug was paired with another in the app’s video-uploading system (a happy birthday video uploading tool, to be specific). This let attackers steal access tokens to user accounts. (Facebook explains that access tokens “are the equivalent of digital keys that keep people logged in to Facebook so they don’t need to re-enter their password every time they use the app.”) Once the hackers obtained these keys, they gained the ability to take over other user accounts.
Since discovering this Facebook data breach, the company has fixed the vulnerability. As a precautionary measure, the company also logged out and reset the access tokens of 90 million users Friday morning, requiring them to log back in and reconnect Facebook-connected apps. Once affected users log back in, a notice at the top of their feed will explain the situation. Users don’t need to reset their passwords—at this point, there’s no evidence that passwords were compromised, only user access tokens.
Facebook has reported the data breach to authorities as it continues to investigate its origins and extent. In the meantime, it’s switched off the “view as” feature while it undergoes a security review.
“Since we’ve only just started our investigation, we have yet to determine whether these accounts were misused or any information accessed,” Facebook VP of Product Management Guy Rosen wrote in a blog post. “We also don’t know who’s behind these attacks or where they’re based. We’re working hard to better understand these details.”
Since the Cambridge Analytica scandal surfaced earlier this year, Facebook has been scrambling to polish its image and regain user trust. It’s run a series of ads apologizing for its past behavior, and made efforts to make its privacy controls more simple and clear to understand.
H/T the New York Times
Christina Bonnington is a tech reporter who specializes in consumer gadgets, apps, and the trends shaping the technology industry. Her work has also appeared in Gizmodo, Wired, Refinery29, Slate, Bicycling, and Outside Magazine. She is based in the San Francisco Bay Area and has a background in electrical engineering.