US computer security firm Symantec has said that Facebook accidentally left a door open for advertisers to access profiles, pictures, chat and other private data at the social network. Facebook told AFP that there was no evidence anyone stepped through that door and swiped any information from the accounts of its more than 500 million members. Symantec discovered that certain Facebook applications leaked tokens that act essentially as "spare keys" for accessing profiles, reading messages, posting to walls or other actions. Facebook applications are Web software programs that are integrated onto the leading online social network's platform. Symantec said that 20 million Facebook applications, such as games, are installed every day. "We appreciate Symantec raising this issue and we worked with them to address it immediately," Facebook said in response to an AFP inquiry. The tokens were being leaked to third-party applications including advertisers and analytics platforms, allowing them to post messages or mine personal information from profiles, according to Nishant Doshi of Symantec. "Fortunately, these third-parties may not have realized their ability to access this information," Doshi said in a blog post. "We have reported this issue to Facebook, who has taken corrective action to help eliminate this issue." Symantec estimated that as of April, nearly 100,000 applications were giving away keys to Facebook profiles. "We estimate that over the years, hundreds of thousands of applications may have inadvertently leaked millions of access tokens to third parties," Doshi said. Facebook confirmed the problem, which was discovered by Doshi and Symantec colleague Candid Wueest, according to the computer security firm. But Facebook said the Symantec report had a few "inaccuracies." There was no evidence that the problem resulted in private information being gleaned from Facebook members' accounts, according to the California-based social networking service. "In addition, this report ignores the contractual obligations of advertisers and developers which prohibit them from obtaining or sharing user information in a way that violates our policies," Facebook said. There was no reliable estimate of how many tokens have been leaked since the release of Facebook applications in 2007. Despite whatever fix Facebook has put in place, token data may still be stored in files on third-party computers, Symantec warned. "Concerned Facebook users can change their Facebook passwords to invalidate leaked access tokens," Doshi said. "Changing the password invalidates these tokens and is equivalent to 'changing the lock' on your Facebook profile."
GMT 17:42 2018 Wednesday ,31 October
Launch of cargo spacecraft Progress MS-10 to ISS set for 16 NovemberGMT 14:18 2018 Saturday ,27 October
First launch of Soyuz-FG booster after Oct 11 incident scheduled on 16 NovGMT 16:58 2018 Monday ,22 October
Report on Soyuz-FG vehicle malfunction to be approved on 30 OctoberGMT 22:05 2018 Friday ,19 October
NASA chief believes human mission to Mars should become international projectGMT 16:31 2018 Monday ,15 October
Roscosmos chief to inform NASA and ESA on probe into Soyuz booster incidentGMT 18:09 2018 Thursday ,11 October
Russia to provide NASA with full information on Soyuz emergency landingGMT 16:09 2018 Thursday ,11 October
President Putin to receive report on aborted Soyuz space launch to ISSGMT 10:49 2018 Friday ,19 January
Amazon narrows list of 'HQ2' candidates to 20Maintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2021 ©
Maintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2021 ©
Send your comments
Your comment as a visitor