Never forget those who have died because of various sex offender laws.
Showing posts with label Security Leak - Facebook. Show all posts
Showing posts with label Security Leak - Facebook. Show all posts

June 9, 2011

Facebook Turns On Facial Recognition, Prompting Concern

6-9-2011 Global:

Security firm Sophos on Tuesday expressed concern that Facebook's facial-recognition technology had been turned on by default. The social-networking site acknowledged that it should have been more communicative about the service's roll-out, but did not announce plans to make it opt-in.

"Now might be a good time to check your Facebook privacy settings as many Facebook users are reporting that the site has enabled the option in the last few days without giving users any notice," Sophos' Graham Cluley wrote in a blog post.

Back in December, Facebook announced plans for facial-recognition technology intended to make it easier for people to tag photos of friends. Facebook said it would examine newly uploaded photos and compare them to other photos in which you or your friends are tagged in order to make tagging suggestions.

When it was announced, Facebook said it would test the service and listen to feedback before a full rollout. "We should have been more clear with people during the roll-out process when this became available to them," a Facebook spokesman said in a Tuesday statement.

Facebook is "rather creepily ... pushing your friends to go ahead and tag you," Cluley wrote. "Remember, Facebook does not give you any right to pre-approve tags. Instead the onus is on you to untag yourself in any photo a friend has tagged you in. After the fact."

Facebook, however, said the tool is simply intended to help users speed up a process that is "done more than 100 million times a day." Tag suggestions are made only when people upload photos and it only suggests friends.

"Tag Suggestions are now available in most countries and we'll post further updates to our blog over time," the Facebook spokesman said.

If you don't want facial recognition turned on, go to your Facebook account's privacy settings, click on "Customize settings," go to "Things others share" and find the option for "Suggest photos of me to friends." To see if it's enabled, click "Edit Settings" and the box should either say "enabled" or "disabled."

In April, Cluley published an open letter to Facebook that outlined three fundamental steps Facebook needed to take to better protect its users. That included a request for a "privacy by default" setting.

"Unfortunately, once again, Facebook seems to be sharing personal information by default," Cluley wrote today. "The onus should not be on Facebook users having to "opt-out" of the facial recognition feature, but instead on users having to 'opt-in.'" ..Source.. by Chloe Albanesius

Read More of Article...

May 10, 2011

Facebook caught exposing millions of user credentials

5-10-2011 Global:

App bug overrides user privacy settings

Facebook has leaked access to millions of users' photographs, profiles and other personal information because of a years-old bug that overrides individual privacy settings, researchers from Symantec said.

The flaw, which the researchers estimate has affected hundreds of thousands of applications, exposed user access tokens to advertisers and others. The tokens serve as a spare set of keys that Facebook apps use to perform certain actions on behalf of the user, such as posting messages to a Facebook wall or sending RSVP replies to invitations. For years, many apps that rely on an older form of user authentication turned over these keys to third parties, giving them the ability to access information users specifically designated as off limits.

The Symantec researchers said Facebook has fixed the underlying bug, but they warned that tokens already exposed may still be widely accessible.

“There is no good way to estimate how many access tokens have already been leaked since the release [of] Facebook applications back in 2007,” Symantec's Nishant Doshi wrote in a blog post published on Tuesday. “We fear a lot of these tokens might still be available in log files of third-party servers or still being actively used by advertisers.”

While many access tokens expire shortly after they're issued, Facebook also supplies offline access tokens that remain valid indefinitely. Facebook users can close this potential security hole by changing their passwords, which immediately revokes all previously issued keys.

The flaw resides in an authentication scheme that predates the roll out of a newer standard known as OAUTH. Facebook apps that rely on the legacy system and use certain commonly used code variables will leak access tokens in URLs that are automatically opened by the application host. The credentials can then be leaked to advertisers or other third parties that embed iframe tags on the host's page.

“The Facebook application is now in a position to inadvertently leak the access tokens to third parties potentially on purpose and unfortunately very commonly by accident,” Doshi wrote. “In particular, this URL, including the access token, is passed to third-party advertisers as part of the referrer field of the HTTP requests.”

A Facebook spokeswoman said there is no evidence the weakness has been exploited in ways that would violate the social network's privacy policy, which steadfastly promises: “We never share your personal information with our advertisers.” Facebook on Tuesday also announced it was permanently retiring the old authentication routine.

Doshi, who was assisted by fellow researcher Candid Wueest, said there's no way to know precisely how many apps or Facebook users were affected by the glitch. They estimate that as of last month, almost 100,000 applications were enabling the leakage and that over the years “hundreds of thousands of applications may have inadvertently leaked millions of access tokens to third parties.”

Facebook over the years has regularly been criticized for compromising the security of its users, which now number more than 500 million. The company has rolled out improvements, such as always-on web encryption, although users still must be savvy enough to turn it on themselves, since the SSL feature isn't enabled by default.

As indicated above, all previously issued access tokens can be cleared by changing your Facebook password. Readers who aren't sure if they're affected might want to err on the side of security and update their password now. ® ..Source.. by Dan Goodin in San Francisco

Read More of Article...