Live data from Hacker News

Facebook Network Breach Impacts Up to 50M Users

nytimes.com

601–610 of 635 posts

Re: Facebook Network Breach Impacts Up to 50M Users

#601

Excerpts from the press call transcript [1] by Guy Rosen explaining what lead to this breach being possible: > The first bug was that, when using the View As function to look at your profile as another person would, the video uploader shouldn’t have actually shown up at all. But in a very specific case, on certain types of posts that are encouraging people to post happy birthday greetings, it did show up. > The secon…

How likely is it that the three bug combination could be discoverd without access to source code ?

Very likely. It happens all of the time. If you read through some cve’s or other bug reports or post mortem’s, you’ll be surprised just how complex attacks can be.

Re: Facebook Network Breach Impacts Up to 50M Users

#602

Earlier quoted context omitted.

How likely is it that the three bug combination could be discoverd without access to source code ?

Very likely. It happens all of the time. If you read through some cve’s or other bug reports or post mortem’s, you’ll be surprised just how complex attacks can be.

I suppose that the likelihood estimate would need to take into account the number of people who have (or had) access to the sources. Obviously the alternatives are not mutually exclusive.

Re: Facebook Network Breach Impacts Up to 50M Users

#603
post #586

Earlier quoted context omitted.

I work for a major (by Norwegian standards) bank. This level of authentication integration trickery wouldn't be attempted by us. Mainly because we try hard to avoid serious technical debt (due to timeline/delivery pressure) in our security infrastructure. We occasionally take such shortcuts in places that are not mission-critical, but they are always considered carefully as the tradeoff that they are. I believe that…

Meanwhile I work for a major US IB. While I don't work on anything customer facing our internal SSO infrastructure basically consists of a single cookie that gets access to almost everything.. And its really not difficult to sniff one from another user (like say getting them to visit a link like http://mydesktop.companyname.com/.. ). Its so bad that for certain systems we check the origin of your connection and will…

Is the cookie not associated to a specific IP? SSO systems would normally flag the mismatch if you try to connect to a website and pass an SSO cookie issued for a different IP, so sniffing cookies wouldn’t help all that much.

Re: Facebook Network Breach Impacts Up to 50M Users

#604
post #547

My girlfriend and I experienced a really weird bug in the past. We would see that Facebook said we were active in the middle of the night when we were definitely asleep. It didn't make too much sense then, but now its possible that those instances might have occurred due to someone else accessing our accounts? Both of our accounts were logged out. Did anyone else experience anything like that?

AFAIK if you have messenger installed and you have internet connection, Facebook displays your status as active.

Re: Facebook Network Breach Impacts Up to 50M Users

#605

Earlier quoted context omitted.

Probably because it's entirely anecdotal and attempts to extrapolate from such a small sample size.

It's more a problem of a biased sample than a small sample - this attack spread through the friend network, and so if one of your Facebook friends is in the attacked/vulnerable group then other ones are also likely to be.

Sure, but that's very different than the logical problem I'm talking about.

Re: Facebook Network Breach Impacts Up to 50M Users

#606
post #214

Earlier quoted context omitted.

> the long-term societal tradeoff of not developing addictive mental candy Along with React, GraphQL and a bunch of other technologies with various degrees of popularity https://opensource.fb.com Along with various startups building around the projects incubated at Facebook - Asana, Interana, Phacility, Qubole, etc.

Ok so React, GraphQL, and good pay. Definitely not short-sighted. You don't think those technologies could have been developed by people at ethical companies, or even by the same people at ethical companies?

[deleted]

Re: Facebook Network Breach Impacts Up to 50M Users

#608

Earlier quoted context omitted.

This is a very short-sighted view. Yes it has some immediate benefit in terms of pay, but you have to consider the long-term societal tradeoff of not developing addictive mental candy for people or developing societally useful technologies (or vice-versa, as it now stands). We can focussed on getting paid a lot now, or improving the wealth of everyone and generative the value we can all enjoy later.

> the long-term societal tradeoff of not developing addictive mental candy Along with React, GraphQL and a bunch of other technologies with various degrees of popularity https://opensource.fb.com Along with various startups building around the projects incubated at Facebook - Asana, Interana, Phacility, Qubole, etc.

OData was developed before Graphql - pretty much does the same thing

Re: Facebook Network Breach Impacts Up to 50M Users

#609
post #560
post #550

Earlier quoted context omitted.

Technical debt, multiple systems using multiple old authentication routines getting slowly upgraded to new auth methods. And no one taking the time to fully understand the ramifications. And honestly it seems like that was the right choice for the teams responsible. They all made tons of money delivered features and now years later a bug is found.

Would you feel the same way if this vulnerability was for, say, a major banking website?

You're vastly overrating the size of the vulnerability and the security of banks. This would not have been caught by internal security teams at most banks and even if it was caught, it wouldn't be considered a major vulnerability on a major banking website.

With that said, this is a bigger vulnerability precisely because Facebook is a free service - at banks, you need to be a customer with real-world identity to even begin to attempt to exploit this.

Re: Facebook Network Breach Impacts Up to 50M Users

#610

Earlier quoted context omitted.

Just as Microsoft developed Patch Tuesday, Facebook should have Forced Logoff Friday

Every day on Facebook should be forced logoff day. Or, at least, incognito mode day.

There's a Firefox Add-on named "Facebook Container". Once you install that Facebook lives in a little box, Facebook cookies, Facebook whatever else, all trapped in the little box.

No effort needed, if you click your Facebook bookmark, or follow a link or whatever, the browser goes "Oh, this is Facebook" and traps it inside the box with the rest of Facebook without any extra steps from the user. There's a cute blue "Facebook" icon added to the URL bar so you can see it's working.

(I mean, or, stop using Facebook, but for many that isn't a reasonable option)

Post reply on HN