Excerpts from the press call transcript [1] by Guy Rosen explaining what lead to this breach being possible: > The first bug was that, when using the View As function to look at your profile as another person would, the video uploader shouldn’t have actually shown up at all. But in a very specific case, on certain types of posts that are encouraging people to post happy birthday greetings, it did show up. > The secon…
How likely is it that the three bug combination could be discoverd without access to source code ?
Facebook Network Breach Impacts Up to 50M Users
601–610 of 635 posts
Re: Facebook Network Breach Impacts Up to 50M Users
#602Earlier quoted context omitted.
How likely is it that the three bug combination could be discoverd without access to source code ?
Very likely. It happens all of the time. If you read through some cve’s or other bug reports or post mortem’s, you’ll be surprised just how complex attacks can be.
Re: Facebook Network Breach Impacts Up to 50M Users
#603Earlier quoted context omitted.
I work for a major (by Norwegian standards) bank. This level of authentication integration trickery wouldn't be attempted by us. Mainly because we try hard to avoid serious technical debt (due to timeline/delivery pressure) in our security infrastructure. We occasionally take such shortcuts in places that are not mission-critical, but they are always considered carefully as the tradeoff that they are. I believe that…
Meanwhile I work for a major US IB. While I don't work on anything customer facing our internal SSO infrastructure basically consists of a single cookie that gets access to almost everything.. And its really not difficult to sniff one from another user (like say getting them to visit a link like http://mydesktop.companyname.com/.. ). Its so bad that for certain systems we check the origin of your connection and will…
Re: Facebook Network Breach Impacts Up to 50M Users
#604My girlfriend and I experienced a really weird bug in the past. We would see that Facebook said we were active in the middle of the night when we were definitely asleep. It didn't make too much sense then, but now its possible that those instances might have occurred due to someone else accessing our accounts? Both of our accounts were logged out. Did anyone else experience anything like that?
Re: Facebook Network Breach Impacts Up to 50M Users
#605Earlier quoted context omitted.
Probably because it's entirely anecdotal and attempts to extrapolate from such a small sample size.
It's more a problem of a biased sample than a small sample - this attack spread through the friend network, and so if one of your Facebook friends is in the attacked/vulnerable group then other ones are also likely to be.
Re: Facebook Network Breach Impacts Up to 50M Users
#606Earlier quoted context omitted.
> the long-term societal tradeoff of not developing addictive mental candy Along with React, GraphQL and a bunch of other technologies with various degrees of popularity https://opensource.fb.com Along with various startups building around the projects incubated at Facebook - Asana, Interana, Phacility, Qubole, etc.
Ok so React, GraphQL, and good pay. Definitely not short-sighted. You don't think those technologies could have been developed by people at ethical companies, or even by the same people at ethical companies?
Re: Facebook Network Breach Impacts Up to 50M Users
#607Re: Facebook Network Breach Impacts Up to 50M Users
#608Earlier quoted context omitted.
This is a very short-sighted view. Yes it has some immediate benefit in terms of pay, but you have to consider the long-term societal tradeoff of not developing addictive mental candy for people or developing societally useful technologies (or vice-versa, as it now stands). We can focussed on getting paid a lot now, or improving the wealth of everyone and generative the value we can all enjoy later.
> the long-term societal tradeoff of not developing addictive mental candy Along with React, GraphQL and a bunch of other technologies with various degrees of popularity https://opensource.fb.com Along with various startups building around the projects incubated at Facebook - Asana, Interana, Phacility, Qubole, etc.
Re: Facebook Network Breach Impacts Up to 50M Users
#609Earlier quoted context omitted.
Technical debt, multiple systems using multiple old authentication routines getting slowly upgraded to new auth methods. And no one taking the time to fully understand the ramifications. And honestly it seems like that was the right choice for the teams responsible. They all made tons of money delivered features and now years later a bug is found.
Would you feel the same way if this vulnerability was for, say, a major banking website?
With that said, this is a bigger vulnerability precisely because Facebook is a free service - at banks, you need to be a customer with real-world identity to even begin to attempt to exploit this.
Re: Facebook Network Breach Impacts Up to 50M Users
#610Earlier quoted context omitted.
Just as Microsoft developed Patch Tuesday, Facebook should have Forced Logoff Friday
Every day on Facebook should be forced logoff day. Or, at least, incognito mode day.
No effort needed, if you click your Facebook bookmark, or follow a link or whatever, the browser goes "Oh, this is Facebook" and traps it inside the box with the rest of Facebook without any extra steps from the user. There's a cute blue "Facebook" icon added to the URL bar so you can see it's working.
(I mean, or, stop using Facebook, but for many that isn't a reasonable option)