The Jerusalem Post

Worst security breach in Facebook’s history exposed 50 million accounts

- • By MUNSIF VENGATTIL, ARJUN PANCHADAR and PARESH DAVE

Facebook Inc said on Friday that hackers stole digital login codes allowing them to take over nearly 50 million user accounts in its worst security breach ever given the unpreceden­ted level of potential access, adding to what has been a difficult year for the company’s reputation.

Facebook, which has more than 2.2 billion monthly users, said it has yet to determine whether the attacker misused any accounts or stole private informatio­n. It also has not identified the attacker’s location or whether specific victims were targeted. Its initial review suggests the attack was broad in nature.

Chief Executive Mark Zuckerberg described the incident as “really serious” in a conference call with reporters. His account was affected along with that of Chief Operating Officer Sheryl Sandberg, a spokeswoma­n said.

Shares in Facebook fell 2.6% on Friday, weighing on major Wall Street stock indexes.

Facebook made headlines earlier this year after profile details from 87 million users was improperly accessed by political data firm Cambridge Analytica. The disclosure has prompted government inquiries into the company’s privacy practices across the world, and fueled a “#deleteFace­book” social movement among consumers.

US lawmakers said on Friday that the hack may boost calls for data privacy legislatio­n.

“This is another sobering indicator that Congress needs to step up and take action to protect the privacy and security of social media users,” Democratic US Senator Mark Warner said in a statement.

Federal Trade Commission Commission­er Rohit Chopra on Twitter said “I want answers” with a link to a Reuters story on the breach.

Facebook’s latest vulnerabil­ity had existed since July 2017, but the company first identified it on Tuesday after spotting a “fairly large” increase in use of its “view as” privacy feature on September 16, executives said.

“View as” allows users to verify their privacy settings by seeing what their own profile looks like to someone else. The flaw inadverten­tly gave the devices of “view as” users the wrong digital code, which, like a browser cookie, keeps users signed in to a service across multiple visits.

That code could allow the person using “view as” to post and browse from someone else’s Facebook account, potentiall­y exposing private messages, photos and posts. The attacker also could have gained full access to victims’ accounts on any third-party app or website where they had logged in with Facebook credential­s.

“The implicatio­ns of this are huge,” Justin Fier, director of cyber intelligen­ce at security company Darktrace, told Reuters.

Guy Rosen, the Facebook vice president overseeing security, said the flaw was “complex” in that it resulted from three failings.

A video upload feature should not have displayed on a user’s profile page when accessed through “view as,” Rosen told reporters on a conference call. That alone would not have been problemati­c except that the video feature wrongly triggered the placement of the powerful login code. And it placed the code not for the “view as” user, but for who they were pretending to be.

Facebook fixed the issue on Thursday. It also notified the US Federal Bureau of Investigat­ion, Department of Homeland Security, Congressio­nal aides and the Data Protection Commission in Ireland, where the company has European headquarte­rs.

The Irish authority expressed concern in a statement that Facebook has been “unable to clarify the nature of the breach and risk to users” and said it was pressing Facebook for answers.

(Reuters)

Newspapers in English

Newspapers from Israel