Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

MacRumors

macrumors bot
Original poster
Apr 12, 2001
63,537
30,847



Facebook this morning announced that its engineering team on Tuesday discovered that hackers have exploited a vulnerability in its code, allowing hackers to steal Facebook access tokens for almost 50 million accounts.

According to Facebook, hackers took advantage of security flaws in its "View As" code, which is a feature designed to let people see what their profile looks like to someone else. The Facebook access tokens that were stolen are digital keys that allow people to stay logged in to Facebook.

facebooksecurity-800x499.jpg
This attack exploited the complex interaction of multiple issues in our code. It stemmed from a change we made to our video uploading feature in July 2017, which impacted "View As." The attackers not only needed to find this vulnerability and use it to get an access token, they then had to pivot from that account to others to steal more tokens.
It is not clear whether the accounts affected were misused or have had information accessed at this time, and Facebook does not know who executed the attacks.

Facebook says that the vulnerability has been patched at this time, and authorities have been informed. Facebook has reset the access tokens of the nearly 50 million accounts that were affected along with another 40 million accounts that have been subject to a "View As" lookup in the last year.

Customers who have been logged out of their apps will receive a message about what happened once they log back in.

While a security review is conducted, Facebook is turning off the "View As" feature that was used for the hack.

Facebook says that it is "sorry this happened" and that people's privacy and security "is incredibly important." No one needs to change their passwords, according to Facebook, but those concerned can visit the "Security and Login" section in settings to log out of all devices at once.

Today's Facebook hack comes just a day after Facebook was found to be using phone numbers that customers provided for 2-factor authentication for ad targeting purposes and shadow contact building.

Article Link: Facebook Uncovers 'Security Issue' Affecting Nearly 50 Million Accounts
 

w5jck

Suspended
Nov 9, 2013
1,517
1,935
I just came from my Facebook account and was wondering why I had to log back in. BTW, they did NOT give me a message explaining why. Those lying sacks a flaming poop at FB are the biggest liars and data minors in the world, except for Google...
 

TooDarkPark

Suspended
Nov 23, 2017
85
20
I've always known there has been something going on with FaceBook over the past few years. Many times when I wouldn't use FaceBook for several months, there would be a post that I supposedly made that had my first name with the word who as a question. It's like someone was testing something to see what they could get away with but yet my activity log and logins only showed it was me logged in and posting yet the activity log never showed I posted that.
 

w5jck

Suspended
Nov 9, 2013
1,517
1,935
Stop using Facebook people! There is a better and safer alternative to each fb feature. I can't think of a single good reason to still be on Facebook - there are none.

If that were only possible, but you are naive to think that the average FB user will switch. We techie types would love to, but in this day and age convincing the majority of your family and friends to abandon FB is not going to happen, so we are stuck with FB or with little or no contact with family and friends. That is just the way it is, like it or not. Everyone is used to FB now, and expecting them all to agree to switch to another single platform is so naive as to be laughable. So if you are a loner, then switch if you want to. But if you have a lot of family and friends on FB, you are pretty much stuck with it for now, assuming you want to stay in contact with them.
 

arkitect

macrumors 604
Sep 5, 2005
7,078
12,495
Bath, United Kingdom
If that were only possible, but you are naive to think that the average FB user will switch. We techie types would love to, but in this day and age convincing the majority of your family and friends to abandon FB is not going to happen, so we are stuck with FB or with little or no contact with family and friends. That is just the way it is, like it or not. Everyone is used to FB now, and expecting them all to agree to switch to another single platform is so naive as to be laughable. So if you are a loner, then switch if you want to. But if you have a lot of family and friends on FB, you are pretty much stuck with it for now, assuming you want to stay in contact with them.
Agree 100%

As much as I would like to have an alternative that is not going to happen — unless FaceBook itself implodes and disappears.

This is the only one-stop-shop for myself and extended family and friends around the globe.

Such is life… but damn, FaceBook… why let your users down again and again?
 
  • Like
Reactions: Shanghaichica

keysofanxiety

macrumors G3
Nov 23, 2011
9,539
25,302
LOL there are dank memes in Slack! There are so many plugins/add-ons there. Oh and Slack has a free tier, which the tech community here in TN uses.

But on Facebook I have the option to ignore all my friends and just have a feed full of poop-posting pages. Can Slack do that?!

(FWIW we do use Slack too, but that’s for proper “issues”. The FB chat is more casual — change shift patterns etc.) :)
 
  • Like
Reactions: TokMok3

brian3uk

macrumors 6502
Sep 15, 2016
393
1,362
to the folks saying delete your account. they have your data even if you delete, or never had one to begin with. sure they'll have less data if delete but it wont fix the problem. i only stay on there becuase my family is spread throughout the US, UK, and Sweden so it is easy to keep in touch. but i post significantly less than i did 5 years ago.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.