Facebook failed to warn users of known risks before 2018 breach: court filing

By Katie Paul (Reuters) - Facebook users suing the world's largest social media network over a 2018 data breach say it failed to warn them about risks tied to its single sign-on tool, even though it protected its employees, a court filing on Thursday showed. Single sign-on connects users to third-party social apps and services using their Facebook credentials. The lawsuit, which combined several legal actions, stems from Facebook Inc's worst-ever security breach in September, when hackers stole login codes - or 'access tokens' - that allowed them to access nearly 29 million accounts.

Reuters August 16, 2019 06:05:21 IST
Facebook failed to warn users of known risks before 2018 breach: court filing

Facebook failed to warn users of known risks before 2018 breach court filing

By Katie Paul

(Reuters) - Facebook users suing the world's largest social media network over a 2018 data breach say it failed to warn them about risks tied to its single sign-on tool, even though it protected its employees, a court filing on Thursday showed.

Single sign-on connects users to third-party social apps and services using their Facebook credentials.

The lawsuit, which combined several legal actions, stems from Facebook Inc's worst-ever security breach in September, when hackers stole login codes - or "access tokens" - that allowed them to access nearly 29 million accounts.

"Facebook knew about the access token vulnerability and failed to fix it for years, despite that knowledge," the plaintiffs said in a heavily redacted section of the filing in the U.S. District Court for the Northern District of California in San Francisco.

"Even more egregiously, Facebook took steps to protect its own employees from the security risk, but not the vast majority of its users."

Facebook did not immediately respond to a request for comment.

Judge William Alsup told Facebook in January he was willing to allow "bone-crushing discovery" in the case to uncover how much user data was stolen.

Facebook has revealed few details since initially disclosing the attack, saying only that it affected a "broad" spectrum of users without breaking down the numbers by country.

The attackers took profile details such as birth dates, employers, education history, religious preference, types of devices used, pages followed and recent searches and location check-ins from 14 million users.

For the other 15 million users, the breach was restricted to name and contact details. In addition, attackers could see the posts and lists of friends and groups of about 400,000 users.

They did not steal personal messages or financial data and did not access users' accounts on other websites, Facebook said.

(Reporting by Katie Paul; Editing by Richard Chang)

This story has not been edited by Firstpost staff and is generated by auto-feed.

Updated Date:

TAGS:

also read

France, Germany to agree to NATO role against Islamic State - sources
| Reuters
World

France, Germany to agree to NATO role against Islamic State - sources | Reuters

By Robin Emmott and John Irish | BRUSSELS/PARIS BRUSSELS/PARIS France and Germany will agree to a U.S. plan for NATO to take a bigger role in the fight against Islamic militants at a meeting with President Donald Trump on Thursday, but insist the move is purely symbolic, four senior European diplomats said.The decision to allow the North Atlantic Treaty Organization to join the coalition against Islamic State in Syria and Iraq follows weeks of pressure on the two allies, who are wary of NATO confronting Russia in Syria and of alienating Arab countries who see NATO as pushing a pro-Western agenda."NATO as an institution will join the coalition," said one senior diplomat involved in the discussions. "The question is whether this just a symbolic gesture to the United States

China's Xi says navy should become world class
| Reuters
World

China's Xi says navy should become world class | Reuters

BEIJING Chinese President Xi Jinping on Wednesday called for greater efforts to make the country's navy a world class one, strong in operations on, below and above the surface, as it steps up its ability to project power far from its shores.China's navy has taken an increasingly prominent role in recent months, with a rising star admiral taking command, its first aircraft carrier sailing around self-ruled Taiwan and a new aircraft carrier launched last month.With President Donald Trump promising a US shipbuilding spree and unnerving Beijing with his unpredictable approach on hot button issues including Taiwan and the South and East China Seas, China is pushing to narrow the gap with the U.S. Navy.Inspecting navy headquarters, Xi said the navy should "aim for the top ranks in the world", the Defence Ministry said in a statement about his visit."Building a strong and modern navy is an important mark of a top ranking global military," the ministry paraphrased Xi as saying.