RSS
热门关键字:  www xnxx com A  tinyurl com  bjq  www  food safety
当前位置 :| 主页>新闻>

Facebook flaw leaked millions of user account access tokens

来源:msnbc.msn.com 作者:Bob Sullivan 时间:2011-05-11 Tag:Facebook   leak   security   点击:

 

Advertisers and other third parties had the potential to gain unauthorized access to many Facebook user accounts(账户) and profile(简介) information because of a software flaw, Symantec Corp. said Tuesday night.

Hundreds of thousands of third party applications leaked user account access tokens(访问令牌) to advertisers and others during the past several years, Symantec said. In April alone, when the flaw was found, about 100,000 applications were enabling the leakage(泄漏), according to the company.

Facebook was advised of the flaw and fixed it, according to Symantec, but some of the leaked access codes(访问代码) -- called tokens -- might still be stored on log files(记录文件) or in applications, and could be exploited.

"Concerned Facebook users can change their Facebook passwords(密码) to invalidate(使无效) leaked access tokens," Symantec wrote in a blog post describing the situation. "We estimate that over the years, hundreds of thousands of applications may have inadvertently leaked millions of access tokens to third parties."

The tokens act like "spare keys(备用钥匙)," allowing third-party applications to perform certain functions on behalf of users without requiring them to log in each time. When third-party apps(应用软件) are installed, users selectively grant them permission to access profile data. In certain situations, a token can be passed by Facebook to these third-party applications "potentially on purpose and unfortunately very commonly by accident" in the referrer field of Web-based data requests. That data, in turn, can be shared with other third parties.

In other words, the spare key gets around.

That would enable third parties to gain unauthorized access to profiles, photographs, and chats, and also enable a malicious attacker to post messages and mine personal information, Symantec said.

Facebook acknowledged the flaw, but told the Wall Street Journal that it had not been exploited by anyone.

"We've conducted a thorough investigation which revealed no evidence of this issue resulting in a user's private information being shared with unauthorized third parties," the firm said, according to the Journal. No explanation of the investigation was shared.

The incident is not the first time Facebook has been accused of leaking critical data to third parties. Last fall, the Wall Street Journal found that many popular apps were transmitting Facebook user ID information to third parties, regardless of user privacy settings.

The token leakage incident is just the latest reminder(提醒物) that Facebook holds a treasure trove(无主珍宝) of information about half a billion people, leaving the firm atop a mountain of private data. The safety and security of so much information stored in one place is inherently suspect.

"The repercussions(反响) of this access token leakage are seen far and wide," wrote Nishant Doshi, who discovered the flaw with Candid Wueest, in his blog post about the incident.


最新评论共有 6 位网友发表了评论
发表评论
评论内容:不能超过250字,需审核,请自觉遵守互联网相关政策法规。
用户名: 密码:
匿名?
注册