Facebook Pays Out For SSL Weakness In Android App

Facebook has added extra protection to its Android app, after a researcher discovered images were still being sent over HTTP, even if HTTPS had been turned on.

SSL protection should provide adequate encryption, stopping snoops, or man-in-the-middle hackers, intercepting data. But Facebook was seen doing SSL in some places, but not in the sending and receiving of photos in the Android application.

Facebook fixes bad SSL

Facebook broken

Researcher Mohamed Ramadan discovered the problem by using the Wireshark traffic monitoring tool.

He reported the bug on 22 February and Facebook eventually responded by admitting it “wasn’t using HTTPS as it was supposed to”, according to a blog post from Ramadan.

Facebook ended up giving him $2000 in bug bounty funds. Ramadan has now promised to deliver more information on Facebook bugs he has discovered.

“It is time to update your Facebook apps right now, if you are a bit lazy like me and forget to update Android apps then update now,” he added.

It’s not uncommon for Android apps to have SSL flaws. Last year, over 1,000 vulnerable applications were uncovered.

Facebook confirmed the flaw was real and fixed, in an email statement sent to TechWeekEurope. It did not offer any more detail.

The social network has been gaining a lot of attention in the security community of late. It was criticised for not handing a bug bounty to one researcher, who discovered a flaw that let him post to anyone’s wall, including Facebook CEO Mark Zuckerberg’s timeline, without being a contact. They were rewarded by a community crowd fund instead, earning them over $10,000.

What do you know about Internet security? Find out with our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

TSMC Denies Talks With Intel Over Chipmaking Joint Venture

Denial from TSMC, after multiple reports it was in talks with Intel over a joint…

2 days ago

Apple iPhone Shipments In China Slide, As Cook Talks With Trump Official

CEO Tim Cook talks to Trump official, as IDC notes China's smartphone market growth, and…

2 days ago

AMD Warns Of $800m Charge From US Chip Restrictions On China

Another big name chip maker expects a hefty financial charge, after the US tightened rules…

2 days ago

Google Digital Ad Network Ruled Illegal Monopoly By Judge

More bad news for Google. Second time in less than a year that some part…

2 days ago

US State Dept Closes Office Flagging Russia, China Disinformation

Federal office that tackled misinformation and disinformation from hostile nations is closed down, after criticism…

2 days ago

Nvidia CEO Jensen Huang Makes Surprise Visit To China

After Nvidia admits it will take $5.5 billion charge as Trump export limits of slower…

2 days ago