Facebook Hack: No Third-Party Access Claimed
- Facebook reports that its inquiry has not yet revealed any indication that attackers exploited Facebook Login to gain access to third-party websites during the recent Facebook data breach.
- Guy Rosen of Facebook stated that an analysis of logs for all third-party apps installed or logged in during the attack showed no evidence of unauthorized app access...
- The social media giant, ticker FB, saeid that attackers exploited a vulnerability, allowing them to view Facebook profiles as if they were the actual account holders.
Facebook’s recent hack, impacting up to 50 million users, shows no immediate evidence of attackers accessing third-party sites via Facebook Login, according to teh company. The primary_keyword, the data breach, exploited a vulnerability allowing unauthorized profile views as if the attackers were the account owners. While the attack’s scope is vast, and the implications for secondary_keyword are significant, the social media giant has stated that logs from third-party apps revealed no such access. News directory 3 is closely watching Facebook’s inquiry into the security incident, along with its commitment to user privacy. With Facebook resetting millions of access tokens and enforcing logouts to secure user accounts, what further revelations will emerge as the investigation continues? Discover what’s next.
Facebook Hack: No Evidence of Third-Party Site Access
Updated October 2, 2018
Facebook reports that its inquiry has not yet revealed any indication that attackers exploited Facebook Login to gain access to third-party websites during the recent Facebook data breach. The company initially disclosed the breach last week, revealing that as many as 50 million accounts were compromised.
Guy Rosen of Facebook stated that an analysis of logs for all third-party apps installed or logged in during the attack showed no evidence of unauthorized app access via Facebook Login.
The social media giant, ticker FB, saeid that attackers exploited a vulnerability, allowing them to view Facebook profiles as if they were the actual account holders. This included access to friends’ profiles and updates.
Facebook said it addressed the vulnerability,forcing approximately 90 million users to log out as a security measure.
The attackers reportedly stole Facebook “access tokens,” which maintain user login status.Facebook reset 50 million tokens and an additional 40 million as a precaution for those who used the “view as” feature in the past year.
During a call last week,rosen noted the potential for attackers to access third-party sites using Facebook Login but reiterated that no evidence of such activity had been found.
Many sites and apps,including Tinder,Spotify,and Airbnb,use Facebook Login,enabling users to access services with their Facebook credentials. The Facebook hack left developers uncertain about potential exposure to their services.
Facebook stated that partners adhering to its “best practices” received automatic protection.However, developers who did not follow these guidelines might have exposed their users to risk. The company continues to investigate the Facebook security issue.
“We’re sorry that this attack happened — and we’ll continue to update people as we find out more,” Rosen said.
What’s next
Facebook is expected to release further updates as its investigation into the data breach progresses, focusing on user Facebook privacy and security enhancements.
