Facebook Security Breach

Isabeau

Merdeuse
Joined
Sep 20, 2018
Messages
9,372
Location
Montréal
SL Rez
2007
Security Update | Facebook Newsroom
On the afternoon of Tuesday, September 25, our engineering team discovered a security issue affecting almost 50 million accounts. We’re taking this incredibly seriously and wanted to let everyone know what’s happened and the immediate action we’ve taken to protect people’s security.
Our investigation is still in its early stages. But it’s clear that attackers exploited a vulnerability in Facebook’s code that impacted “View As”, a feature that lets people see what their own profile looks like to someone else. This allowed them to steal Facebook access tokens which they could then use to take over people’s accounts. Access tokens are the equivalent of digital keys that keep people logged in to Facebook so they don’t need to re-enter their password every time they use the app.


...
 

Isabeau

Merdeuse
Joined
Sep 20, 2018
Messages
9,372
Location
Montréal
SL Rez
2007
Mark Zuckerberg

''I want to update you on an important security issue we've identified. We patched the issue last night and are taking precautionary measures for those who might have been affected. We're still investigating, but I want to share what we've already found:

On Tuesday, we discovered that an attacker exploited a technical vulnerability to steal access tokens that would allow them to log into about 50 million people's accounts on Facebook.

We do not yet know whether these accounts were misused but we are continuing to look into this and will update when we learn more.
We've already taken a number of steps to address this issue:

1. We patched the security vulnerability to prevent this attacker or any other from being able to steal additional access tokens. And we invalidated the access tokens for the accounts of the 50 million people who were affected – causing them to be logged out. These people will have to log back in to access their accounts again. We will also notify these people in a message on top of their News Feed about what happened when they log back in.

2. As a precautionary measure, even though we believe we've fixed the issue, we're temporarily taking down the feature that had the security vulnerability until we can fully investigate it and make sure there are no other security issues with it. The feature is called "View As" and it's a privacy tool to let you see how your own profile would look to other people.

3. As an additional precautionary measure, we're also logging out everyone who used the View As feature since the vulnerability was introduced. This will require another 40 million people or more to log back into their accounts. We do not currently have any evidence that suggests these accounts have been compromised, but we're taking this step as a precautionary measure.

We face constant attacks from people who want to take over accounts or steal information around the world. While I'm glad we found this, fixed the vulnerability, and secured the accounts that may be at risk, the reality is we need to continue developing new tools to prevent this from happening in the first place. If you've forgotten your password or are having trouble logging in, you can access your account through the @Help Center.
 

Dakota Tebaldi

Well-known member
VVO Supporter 🍦🎈👾❤
Joined
Sep 19, 2018
Messages
9,767
Location
Ohio
Joined SLU
02-22-2008
SLU Posts
16791
Yeah be aware guys - if these attackers managed to gain access tokens, 2-factor authentication wouldn't have protected your account.

My pseudonym Facebook account was still logged in when I went to the page just now, so I guess I'm one of the lucky ones. If you weren't, I would strongly suggest changing your password. Heck, I guess it would be a good idea to change your password either way.
 

Isabeau

Merdeuse
Joined
Sep 20, 2018
Messages
9,372
Location
Montréal
SL Rez
2007
I just deactivated mine. I wish I could simply delete it, but I still use Messenger for friends and family.
 

WolfEyes

Well known member no one knows
Joined
Sep 20, 2018
Messages
4,502
SL Rez
2004
Joined SLU
2009
Apparently I wasn't affected since I'm still logged in and the only site I use FB to log into is The Sims Resource. I recently removed my payment info so there's that. There's like 5 bucks in my checking just to keep it open.

I hope everyone else is safe, too. Even those who obviously don't like me.