23 Jun 2009
News that hackers have once again found their way into Facebook should serve as reminder to firms using external social networks as part of a business strategy that data is not necessarily secure behind a web site's login details.
Perhaps social suites available from enterprise vendors might be a safer bet.
FBHive, a recently launched site following Facebook, said yesterday it was able to hack into any person's "Basic Information" section, no matter what their privacy settings.
"We have already reported this bug to Facebook on June 7th 2009, through multiple avenues, but it has received little attention. Hopefully this incites a little more action from them," said the post.
The exploit involved fooling the "Edit Information" section of a user's profile to display another user's Basic Information by using the Tamper Data add-on for Firefox.
FBHive launched a video to show Facebook users how easy the hack was.
Although soon after FBHive published its report, the Facebook security team fixed the exploit, the news follows a revelation from a Burton Group analyst back in 2008 that an email add-on called Xobni, which plugs in to Microsoft Office and correlates Outlook contact data with external sources such as Facebook, also managed to override privacy protections.
Analyst Mike Gotta said that when an individual's social data is pulled from an external network site into another person's email account, they should be properly notified.
"I do believe that context of a relationship agreement made within one environment does not necessarily transfer to other environments without the parties being aware and in some cases, consenting to that information being revealed in those other contexts," Gotta had said in his blog.
"What really surprised me though was that I now had access to people's information via Xonbi's Facebook Connect application that I could not access normally on Facebook," he added.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
EU data protection overhaul contains "bureaucratic tick box-proposals", says information commissioner Christopher Graham in exclusive interview with V3
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Technical support Specialist (2/3 rd Line) CCNA...
Aufgabe: - Das Design, die Implementation und Durchführung...
Aufgaben: - Provide basic IT support for the end users...
VPN - WAN - LAN - ASA - FSWM - Cisco - Routers - Swicthes...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?