50 million Facebook accounts breached by access-token-harvesting attack

50 million Facebook accounts breached by access-token-harvesting attack

6 years ago
Anonymous $oIHRkISgaL

https://arstechnica.com/information-technology/2018/09/50-million-facebook-accounts-breached-by-an-access-token-harvesting-attack/

Facebook reset logins for millions of customers last night as it dealt with a data breach that may have exposed nearly 50 million accounts. The breach was caused by an exploit of three bugs in Facebook's code that were introduced with the addition of a new video uploader in July of 2017. Facebook patched the vulnerabilities on Thursday, and it revoked access tokens for a total of 90 million users

In a call with press today, Facebook CEO Mark Zuckerberg said that the attack targeted the "view as" feature, "code that allowed people to see what other people were seeing when they viewed their profile," Zuckerberg said. The attackers were able to use this feature, combined with the video uploader feature, to harvest access tokens.