Facebook: 50M user accounts affected by security breach

News

September 28, 2018 - 11:00 PM

NEW YORK (AP) — Face-book reported a major security breach in which 50 million user accounts were accessed by unknown attackers.

In a blog post , the company says hackers exploited a bug that affected its “View As” feature, which lets people see what their profiles look like to someone else. That would let attackers steal “access tokens,” which are digital keys that Facebook uses to keep people logged in. Possession of those tokens would allow attackers to “seize control” of user accounts, Facebook said.

Specifically, from the “View As” feature, a bug somehow allowed a video uploader to appear for sending “happy birthday” messages, Guy Rosen, Facebook’s vice president of product management said. Another bug then created an access token that made Face-book think the hacker had legitimately signed in with the account being viewed.

“We haven’t yet been able to determine if there was specific targeting,” Rosen said in a call with reporters. “It does seem broad. And we don’t yet know who was behind these attacks and where they might be based.”

Facebook says it has taken steps to fix the security problem and alerted law enforcement.

To deal with the issue, Face-book reset some logins, so 90 million people have been logged out and will have to log in again. That includes anyone who has been subject to a “View As” lookup in the past year.

Facebook says it doesn’t know who is behind the attacks or where they’re based. In a call with reporters on Friday, CEO Mark Zuckerberg said that the company doesn’t know yet if any of the accounts that were hacked were misused.

Jake Williams, a security expert at Rendition Infosec, said the stolen access tokens would have likely allowed attackers to view private posts and probably to post status updates or shared posts as the compromised user, but wouldn’t affect passwords.

Related