Facebook Security Team Clamps Down On Links Scare

Facebook has rushed to counter a security threat which saw public links providing direct access into users’ accounts.

A message on the Hacker News website exposed the bug, providing a search string that brought up a list of links to over 1.3 million Facebook accounts. They appeared to have been links that Facebook sends to users via email, indicating such emails had been leaked online.

In some cases, clicking on those links gave access to accounts without any need for a password. Facebook has now disabled the feature which allowed users to click on a link and go directly into their account.

Facebook security responds

“These are not URLs that we make publicly available,” said Matt Jones, from the Facebook security team. “We send them in notification emails to users – they’re designed to make it easier to log in if you click a link we sent to your email in a notification.

“It’s likely that Google came across these URLs by crawling pages where people publicly post the contents of their email (e.g. throwaway email sites, as someone pointed out – or people whose email addresses go to email lists with online archives).”

Jones said the “nonces” – the links – expired after a period of time and only work for certain users. “Even then we run additional security checks to make sure it looks like the account owner who’s logging in,” he added.

“Regardless, due to some of these links being disclosed, we’ve turned the feature off until we can better ensure its security for users whose email contents are publicly visible. We are also securing the accounts of anyone who recently logged in through this flow.”

Are you a security pro? Try our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Hate Speech Watchdog CCDH To Quit Musk’s X

Target for Elon Musk's lawsuit, hate speech watchdog CCDH, announces its decision to quit X…

12 hours ago

Meta Fined €798m Over Alleged Facebook Marketplace Violations

Antitrust penalty. European Commission fines Meta a hefty €798m ($843m) for tying Facebook Marketplace to…

13 hours ago

Elon Musk Rebuked By Italian President Over Migration Tweets

Elon Musk continues to provoke the ire of various leaders around the world with his…

15 hours ago

VW, Rivian Launch Joint Venture, As Investment Rises To $5.8 Billion

Volkswagen and Rivian officially launch their joint venture, as German car giant ups investment to…

16 hours ago

AMD Axes 4 Percent Of Staff, Amid AI Chip Focus

Merry Christmas staff. AMD hands marching orders to 1,000 employees in the led up to…

19 hours ago

Tesla Recalls 2,431 Cybertrucks Over Propulsion Issue

Recall number six in 2024 for Tesla Cybertruck, and this time the fault cannot be…

20 hours ago