ie8 fix

Facebook: no evidence of apps leaking user data

By | May 11, 2011, 1:33pm PDT

Summary: Facebook says it has found no evidence that the flaw affecting hundreds of thousands of its apps resulted in leaked user data.

Yesterday Symantec revealed that hundreds of thousands of Facebook apps have been accidentally leaking user data for years (if you haven’t yet, change your Facebook password, to be on the safe side). Thankfully, the two companies worked together to fix the flaw before it could be seriously exploited.

Symantec said the Facebook apps were leaking access to millions of Facebook users’ accounts, including profiles, photographs, chat, and other personal information. The only comfort the security company offered was that the third parties who were accidentally granted access to the data may not have realized their ability to see this information.

I checked with Facebook, and the company has confirmed that the bug allowed some developers to use an outdated and undocumented version of Facebook’s API. As a result, some apps may have inadvertently transmitted user IDs and access tokens to third parties. Facebook also clarified that neither an access token nor a user ID can provide access to details such as a user’s contact information, financial details, or any other sensitive information not available through its API. It also underlined that the vast majority of access tokens expire in two hours.

Most importantly, Facebook found no evidence that this information was being used in a way that violated its policies. If it did, Facebook would have to severe ties with any third parties that broke its rules. Either way, the company still took the issue seriously and fixed the flaw.

“We appreciate Symantec raising this issue and we worked with them to address it immediately,” a Facebook spokesperson said in a statement. “Unfortunately, their resulting report has a few inaccuracies. Specifically, we’ve conducted a thorough investigation which revealed no evidence of this issue resulting in a user’s private information being shared with unauthorized third parties. In addition, this report ignores the contractual obligations of advertisers and developers which prohibit them from obtaining or sharing user information in a way that violates our policies.”

Soon after Symantec’s report was published, Facebook yesterday also announced that it would be permanently retiring its old authentication routine. The company is still working to transition apps from the old Facebook authentication system and HTTP to OAuth 2.0 and HTTPS.

Facebook is requiring all sites and apps to migrate to OAuth 2.0, process the signed_request parameter, and obtain an SSL certificate in the next five months. The company says that the sheer number of Facebook apps prevents it from forcing developers to make the switch immediately. Here’s the timeline:

  • July 1: Updates to the PHP and JS SDKs available that use OAuth 2.0 and have new cookie format (without access token).
  • September 1: All apps must migrate to OAuth 2.0 and expect an encrypted access token.
  • October 1: All Canvas apps must process signed_request (fb_sig will be removed) and obtain an SSL certificate (unless you are in Sandbox mode). This will ensure that users browsing Facebook over HTTPS will have a great experience over a secure connection.

To learn more about the now-fixed flaw, please check out my previous article: Facebook apps have been accidentally leaking user data for years. The most important thing to note is that both Facebook and Symantec made sure the issue was fixed before disclosing the flaw publicly.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Emil Protalinski has covered the tech industry for five years for multiple publications.

Disclosure

Emil Protalinski

Emil has nothing to disclose.

Biography

Emil Protalinski

Emil Protalinski has covered the tech industry for five years for multiple publications, including Neowin for two years and Ars Technica for three years. He has written 1,000s of articles for both, with a particular focus on scrutinizing Microsoft products and services. Recently, Emil has expanded his coverage to non-Microsoft technologies, including the social networking giant Facebook.

12
Comments

Join the conversation!

Just In

RE: Facebook: no evidence of apps leaking user data
FAULKNE 13th Oct
Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.
I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate! nccma cooler
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post. this thread is amazing i like your work and i appreciate you that you have share a useful stuff thanks for sharing the i shop abatwa
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post.Bookmarking now thanks please consider a follow up post. power sa shop
I think the representation of this article is actually superb one. This is my first visit to your site. Thanks a lot and keep sharing the information. Keep updating the information for all of us. Thanks ZDNet Government was launched as the brand's first industry vertical, with a mission to cater to IT professionals in the public secto I agree with your post. However, do you have any sources I can cite for my paper wheel car com bury
I think the representation of this article is actually mt2 pvp superb one. This is my first visit to your site. Thanks a lot metin2 and keep sharing the information. Keep updating the information for all of us. mt2 Thanks ZDNet Government was launched as the brand's first industry vertical, mynet with a mission to cater to IT professionain the public secto I agree with your post yemek tarifleri However, do you have any sources I can cite for my paper face
pvp

metin2, mt2, games, game, oyun, metin2 pvp sserverler knight online pvp metin2, mt2, games, game, oyun, metin2 pvp sserverler metin2 hile
metin2, mt2, games, game, oyun, metin2 pvp sserverler metin2 indir metin2, mt2, games, game, oyun, metin2 pvp sserverler guzel sozler metin2, mt2, games, game, oyun, metin2 pvp sserverler guzel sozleri metin2, mt2, games, game, oyun, metin2 pvp sserverler sevgiliye sozler metin2, mt2, games, game, oyun, metin2 pvp sserverler anlamli sozler metin2, mt2, games, game, oyun, metin2 pvp sserverler sex metin2, mt2, games, game, oyun, metin2 pvp sserverler sex hikayeleri metin2, mt2, games, game, oyun, metin2 pvp sserverler metin2 pvp server metin2, mt2, games, game, oyun, metin2 pvp sserverler metin2 pvp serverler metin2, mt2, games, game, oyun, metin2 pvp sserverler metin2 pvp serverlar metin2, mt2, games, game, oyun, metin2 pvp sserverler pvp serverlar metin2, mt2, games, game, oyun, metin2 pvp sserverler pvp serverler
Well welcome, hopefully you can become a vital member of the community and really help to push far ahead of google. Which Im sure the development team would love. This will of course earn you alot points too and get you on the leaders board. z d n e t t h a n k Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas.
Thanks nice info z d n e t I really liked your current article write more..let me add you to its favorite
I really enjoyed reading this post !!!have bookmarked w e b s will come back to read more.
Fantastic news about the new release.I positively enjoying each little bit of it and I have you b o o k m a r k e d to check out new stuff you weblog post.Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas
0 Votes
+ -
RE: Facebook: no evidence of apps leaking user data
jackson1984-24316069205748857739440257893812 10th Oct
This publish was remarkably accordingly printed, and you will find it carries a superb sum of very helpful information. I appreciated your professed signifies lv ******** on sale of creating this publish.
Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix