Khaleej Times

Facebook users must log-out and log-in

-

NEW DELHI — After Facebook admitted that hackers broke into nearly 50 million users’ accounts by stealing their “access tokens” or digital keys, cyber experts on Saturday warned over 2.3 billion users to log out and log back into Facebook, or any of third-party apps that use Facebook login.

Facebook has reset the access tokens of almost 50 million accounts it knew were affected. It has also taken the precaution­ary step of resetting access tokens for another 40 million accounts that have been subject to “View As” look-up in the last year.

“For now, logging out and back in is all that is necessary. The truly concerned should use this as a reminder and an opportunit­y to review all of their security and privacy settings on Facebook and all other social media platforms,” Chester Wisniewski, principal research scientist with global cyber security major Sophos, told IANS.

According to Dr Gary McGraw, vice-president of Security Technology, Synopsys (Software Integrity Group), this breach emphasises just how important software security is, and how subtle solid security engineerin­g can be.

“When a feature like ‘View As’ can be turned on its head into an exploit, it indicates a design problem that led to unanticipa­ted security vulnerabil­ity,” noted Dr McGraw.

“Design flaws like this lurk in the mind boggling complexity of today’s commercial systems, and must be systematic­ally uncovered and corrected when software is being designed and built,” he added.

If you’ve ever wondered what keeps you logged into your account even after you restart your laptop/browser — those are access tokens (cookies).

They maintain a constant session even when your IP changes.

“In this case, hackers were able to steal these tokens, which basically means the hacker could fool Facebook servers to believe they are the authorised users of the target’s account that would give the attacker, complete access of the target’s account,” said Saket Modi, CEO and co-founder of Lucideus, an IT risk assessment and digital security services provider. —

 ??  ??
 ??  ?? Facebook has reset the access tokens of 50 million accounts.
Facebook has reset the access tokens of 50 million accounts.

Newspapers in English

Newspapers from United Arab Emirates