Live data from Hacker News

More than 1MM Facebook accounts exposed

google.com

91–100 of 181 posts

Re: More than 1MM Facebook accounts exposed

#91
post #61

Earlier quoted context omitted.

All they need to do is add a new "message" to say "y'know that message number 4029375 in the cache, yeah that ones deleted, ignore it". This is not hard.

This arrogance is baffling. What makes you think you know enough about Facebook's infrastructure to make such a claim?

huh? Infrastructure is totally and utterly irrelevant to the problem. I know enough about common sense to make such a claim.

Just send a new message, exactly as you would post an original item/comment/etc, but have some special text/field in there that says "please ignore the previous message". The UI would then hide the previous message.

eg

  COMMENT: {id:9374758, from:"mibbitier", data:"I hate you all!"}
  COMMENT: {id:9374759, from:"mibbitier", data:"*IGNORE_MESSAGE_IN_UI* 9374758"}
Nothing whatsoever to do with infrastructure. Nothing to do with caches. Purely to do with the UI. Not rocket science.

Granted, it's a poor way to do it, but it's better than nothing, and easier than trying to invalidate caches etc

Re: More than 1MM Facebook accounts exposed

#94
post #73

My name is Matt Jones, and I work on the Facbook security team that looked into this tonight. We only send these URLs to the email address of the account owner for their ease of use and never make them publicly available. Even then we put protection in place to reduce the likelihood that anyone else could click through to the account. For a search engine to come across these links, the content of the emails would nee…

The URLs don't need to be posted online. Some browsers (Chrome, possibly Firefox with Safe Browsing mode, very likely any browser with a Google Toolbar installed) send visited URLs to Google and they will be indexed. I don't know if this is officially documented by Google, but several people have reported seeing this while testing new/beta websites that weren't published or linked anywhere.

When you like or share a post in your newsfeed, you're sending a linkback to the original post.

So, if your newsfeed is public "to everyone" Google is able to crawl and index the content on it (discard the original post privacy settings)

Re: More than 1MM Facebook accounts exposed

#95
post #60

More than 1 millimeter Facebook accounts exposed?

Millimetre is mm, not MM which would be "meter meter" which is nonsense. MM is actually the roman numeral for 1 million.

Capital M would be 'mega' as a prefix, but I think it does not exist as a unit. If you're willing to read MM as Mm, then it would be Megameter.

Your really should revisit roman numerals. MM = 2000, you have to add them, not multiply.

Re: More than 1MM Facebook accounts exposed

#96

I'm somewhat curious, why MM for million/mega and not M? Or does the second M stand for some unit?

The Roman numeral M (mille) means 1000. M^2 therefore equals one million.

If that's truly how people use it, it is very strange. In actual roman numerals MM = 2000. Using 'M' as a roman numeral but then multiplying digits makes no sense at all (you'd need numerals for all the prime numbers to represent arbitrary numbers...).

And in SI, the prefix 'M' (mega) already means 1 million, so to me it seems MM is the notation that maximizes confusion.

Re: More than 1MM Facebook accounts exposed

#97
post #85
post #73

My name is Matt Jones, and I work on the Facbook security team that looked into this tonight. We only send these URLs to the email address of the account owner for their ease of use and never make them publicly available. Even then we put protection in place to reduce the likelihood that anyone else could click through to the account. For a search engine to come across these links, the content of the emails would nee…

You mention that the nonces expire after a period of time. If you don't plan on cutting the feature for ever, perhaps you could consider an alternative approach of limiting the validity of the URLs to the first visit and also removing the email-id (and other PII data) of the user from the URL.

The feature is absolutely too dangerous to ever have existed!

It turns out that Facebook implemented the plain links that are more powerful than the password reset procedures, considering the easiness in taking over the account of another user.

Having the actual user id in the link is just a small topping on that cake, not even worth to discuss as long as the "no login just click the link" possibility remains to exist.

Post reply on HN