Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Charlie Kirk shot dead
  • Nepal protests
  • Russia-Poland tension
  • Israeli strikes in Qatar
  • Larry Ellison
  • Apple event
  • Sunjay Kapur inheritance row
fp-logo
How three bugs allowed hackers to compromise over 90 million Facebook accounts
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit

How three bugs allowed hackers to compromise over 90 million Facebook accounts

Anirudh Regidi • October 1, 2018, 19:39:14 IST
Whatsapp Facebook Twitter

Facebook states that the hacker took advantage of three bugs in Facebook’s systems.

Advertisement
Subscribe Join Us
Choose
Firstpost on Google
Choose
Firstpost on Google
How three bugs allowed hackers to compromise over 90 million Facebook accounts

On 28 September, Facebook reported that a hacker had gained access to over 50 million Facebook accounts and that another 40 million users could have been affected. The breach is just one in a long list of privacy issues affecting a platform that is home to the personal data of just about every internet-connected being on this planet. The hacker seems to have taken advantage of Facebook’s “View As” feature, which is, ironically, a privacy feature designed to let you view your profile as someone else. The feature lets you fine-tune the access that other people have to your account data. [caption id=“attachment_5296531” align=“alignnone” width=“1024”]Cardboard cutouts of Facebook CEO Mark Zuckerberg. Image: Reuters Cardboard cutouts of Facebook CEO Mark Zuckerberg. Image: Reuters[/caption] Facebook states that the hacker took advantage of three bugs in Facebook’s systems:

  1. The ‘View As’ feature isn’t supposed to let anyone post anything, it’s only meant as a preview. A bug in the interface allowed users to post a video while using ‘View As’.
  2. Facebook updated the video uploader interface in July 2017, which “incorrectly” generated an access token (more on that later).
  3. The catch here is that you would gain an access token of the account you “viewed as”. If you were my friend and viewed my page as your profile using ‘View As’, I could potentially gain access to your Facebook account.

The access token can be thought of as a key to an account. It’s because of things like access tokens that we don’t need to sign in with our usernames and passwords every time we access our account from a mobile phone or personal computer. Someone with access to the access token to our account could, well, access our account. Any website or app that used Facebook’s single sign-on feature was vulnerable once the token was leaked. This also includes apps like Instagram and Zomato, which carry yet more personal information.

Accounts so hacked could then be used to look up other accounts and gain access to those as well, leading to a data breach that can grow exponentially. Facebook claims to have spotted the vulnerability when it saw an unusual spike in the use of the “View As” feature. To deal with the issue, Facebook has disabled ‘View As’ and deauthorised access tokens for 50 million affected accounts. Access Tokens for another 40 million accounts that may have been compromised by someone using the ‘View As’ feature were also disabled. While Facebook seems to have responded promptly to the issue, the fact remains that one careless mistake, (or maybe 3, in this case), could have compromised the accounts of each and every one of Facebook’s 2 billion+ users.

Tags
facebook Mark Zuckerberg Facebook Hack CEO Mark Zuckerberg Facebook Data Breach
  • Home
  • Tech
  • News & Analysis
  • How three bugs allowed hackers to compromise over 90 million Facebook accounts
End of Article
Latest News
Find us on YouTube
Subscribe
  • Home
  • Tech
  • News & Analysis
  • How three bugs allowed hackers to compromise over 90 million Facebook accounts
End of Article

Top Stories

US ready to ‘impose costs’ on Russia if war in Ukraine drags on, says Hegseth

US ready to ‘impose costs’ on Russia if war in Ukraine drags on, says Hegseth

US tells Hamas to stop violence against Gaza civilians and disarm 'without delay'

US tells Hamas to stop violence against Gaza civilians and disarm 'without delay'

China seizes 60,000 maps mislabelling Taiwan, omitting South China Sea islands

China seizes 60,000 maps mislabelling Taiwan, omitting South China Sea islands

Syria’s Sharaa pledges to honor Russia ties, seeks economic and military support in Kremlin visit

Syria’s Sharaa pledges to honor Russia ties, seeks economic and military support in Kremlin visit

US ready to ‘impose costs’ on Russia if war in Ukraine drags on, says Hegseth

US ready to ‘impose costs’ on Russia if war in Ukraine drags on, says Hegseth

US tells Hamas to stop violence against Gaza civilians and disarm 'without delay'

US tells Hamas to stop violence against Gaza civilians and disarm 'without delay'

China seizes 60,000 maps mislabelling Taiwan, omitting South China Sea islands

China seizes 60,000 maps mislabelling Taiwan, omitting South China Sea islands

Syria’s Sharaa pledges to honor Russia ties, seeks economic and military support in Kremlin visit

Syria’s Sharaa pledges to honor Russia ties, seeks economic and military support in Kremlin visit

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Enjoying the news?

Get the latest stories delivered straight to your inbox.

Subscribe
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV