12 Aug 2010
Facebook has sealed a security hole that left users' names and profile pictures available to unrelated users.
The vulnerability was first reported by Secfence Technologies researcher Atul Agarwal on the Full Disclosure security mailing list.
Agarwal found that entering an email address and incorrect password into the Facebook log-in screen returned a password incorrect message which contained first name and surname along with a profile photograph.
The researcher suggested that the vulnerability could be used by cyber criminals to match names to mass lists of email addresses. The information could then be used for customised spear phishing operations.
A Facebook spokesperson told V3.co.uk that the issue had been fixed, and that the information is no longer available.
"We have technical systems in place to prevent names and photos showing to unrelated users on log-in, but a recently introduced bug temporarily prevented these from working as intended," the company said. "We remedied the situation swiftly."
Facebook has been under intense pressure from privacy groups, and has spent much of 2010 shoring up its security and providing a clearer explanation of what data is shared and how users can lock down their information.
Latest stories from Software
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Hands on with the highly anticipated Android 4.0 Ice Cream Sandwich hybrid tablet
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
PHP Developers - Fixed Term Contracts (initially 6 months...
Junior Ruby on Rails Developer - London - Permanent...
A Project Manager is required to join a leading Insurance...
CCIE Network Engineer required with fluent Hungarian...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
Log-in Security Glitch
This 'glitch' may have been sorted in San Francisco, but over here in the United Kingdom (Scotland to be precise), the problem still exists. I have been unable to access my Facebook page since last night. The reset code, designed to presumably re-set the account doesn't work as there is no text box in which to enter it
Posted by: Alan Paterson 14 Aug 2010