Newsletters
News & Information for Technology Purchasers NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
Home Enterprise I.T. Cloud Computing Applications Hardware More Topics...
Network Security
24/7/365 Network Uptime!
Average Rating:
Rate this article:  
Facebook Security Glitch Exposed Millions of Users
Facebook Security Glitch Exposed Millions of Users' Data

By Jennifer LeClaire
June 24, 2013 11:18AM

    Bookmark and Share
Mike Gross, director of professional services and risk management at 41st Parameter, told us Facebook is facing the same potential risks LivingSocial experienced when hackers breached its database earlier in May that put its 50 million users at risk. In this case, Facebook fixed the user-data bug within 24 hours of its discovery.
 



Facebook has disclosed a data breach has revealed six million user phone numbers and e-mail addresses over the past year. The company pointed to a technical glitch in its 1.1 billion user database as the root of the issue. Facebook fixed the bug within 24 hours of its discovery, but it may not have been soon enough to stop a ripple effect.

"We currently have no evidence that this bug has been exploited maliciously and we have not received complaints from users or seen anomalous behavior on the tool or site to suggest wrongdoing," Facebook said in a blog post.

"Although the practical impact of this bug is likely to be minimal since any email address or phone number that was shared was shared with people who already had some of that contact information anyway, or who had some connection to one another, it's still something we're upset and embarrassed by, and we'll work doubly hard to make sure nothing like this happens again."

Is Facebook Security Lagging?

We turned to Sean Bodmer, chief researcher at CounterTack, to get his thoughts on the latest social media security mishap. He told us the discovery of shadow profile leaks on Facebook was one story. Finding secret shadow files amongst the data -- that seem to be analyzed and correlated data points of every user ranging from their real-life details and private information input by members -- is another.

It's shocking, he said, but not surprising.

"If you look back over the past few years, Facebook publications and reports included a handful of articles about Facebook selling information to customers. Who is to say this isn't one of the data sources that has been sold to the target-marketing firms placing specific ads in view of members based on likes, interests and habits?" he asked.

"The monetization of this information isn't a shock and anyone, in my humble opinion, who thought this free service was completely free doesn't fully understand the basic back-door practices of big data firms finding clever ways of increasing their bottom-line by finding novel ways to massage their big data sets to turn a profit."

Not the First Time

Mike Gross, director of professional services and risk management at 41st Parameter, told us Facebook is facing the same potential risks LivingSocial experienced when hackers breached its database earlier in May that put its 50 million users at risk. It was a seemingly innocuous breach of low-risk data -- no card or payment information -- but it makes phishers' jobs much easier because they now potentially have access to an e-mail address, as well as the individual's closest connections.

"Rather than getting a phishing e-mail with a link from Facebook or another site, a fraudster could make the phishing e-mail look as though it is originating from your close friend with a link to looks legitimate but sends the user to a site that downloads malware on their device," Gross said. "This is actually a much more dangerous data breach than others where no contextual data is provided since having data on close connections allows the fraudster to easily target victims with e-mails that are more likely to get opened and links to be clicked."

His conclusion: Any breach is a big deal, but when relationships are disclosed it raises the stakes. Once malware is on millions of devices, the fraudster essentially has access to every potential online account, from banks to and beyond.
 

Tell Us What You Think
Comment:

Name:



Salesforce.com is the market and technology leader in Software-as-a-Service. Its award-winning CRM solution helps 82,400 customers worldwide manage and share business information over the Internet. Experience CRM success. Click here for a FREE 30-day trial.


 Network Security
1.   Banks Hit by Android-Skirting Malware
2.   New Technology Defeats Privacy Efforts
3.   Juniper DDoS for High-IQ Networks
4.   Big DDoS Attacks Hit Record in 2014
5.   Can Google Stop Zero Day Flaws?


advertisement
Android SMS Worm on the Loose
Malware lets bad actors cash in.
Average Rating:
Banks Hit by Android-Skirting Malware
34 institutions, four European countries
Average Rating:
New Technology Defeats Privacy Efforts
Study identifies 3 browser techniques.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
34 European Banks Hit by Android-Skirting Malware
Criminals have been finding gaping holes in Android-based two-factor authentication systems that banks around the world are using. The result: 34 banks in four European countries have been hit.
 
New Web Tracking Technologies Defeat Privacy Protections
Recently developed Web tracking tools are able to circumvent even the best privacy defenses, according to a new study by researchers at Princeton and the University of Leuven in Belgium.
 
Juniper DDoS Solution Aims at High-IQ Networks
In the face of more complex attacks, Juniper Networks is boosting its DDoS Secure solution to help companies mitigate the threats with more effective security intelligence throughout the network fabric.
 

Enterprise Hardware Spotlight
Contrary to Report, Lenovo's Staying in Small Windows Tablets
Device maker Lenovo has clarified a report that indicated it is getting out of the small Windows tablet business -- as in the ThinkPad 8 and the 8-inch Miix 2. But the firm said it is not exiting that market.
 
Seagate Unveils Networked Drives for Small Businesses
Seagate is out with five new networked attached storage products aimed at small businesses. The drives are for companies with up to 50 workers, and range in capacity from two to 20 terabytes.
 
Another Day, Another Internet of Things Consortium Is Born
In the emerging Internet of Things, zillions of devices will be talking to each other. Samsung, Intel and Dell just formed a consortium to ensure each thing can understand what others are saying.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Cloud Computing | Applications | Hardware | Mobile Tech | Big Data | Communications
World Wide Web | Network Security | Data Storage | Small Business | Microsoft/Windows | Apple/Mac | Linux/Open Source | Personal Tech
Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.