Live data from Hacker News

More than 1MM Facebook accounts exposed

google.com

111–120 of 181 posts

Re: More than 1MM Facebook accounts exposed

#111
post #79

Earlier quoted context omitted.

The URLs don't need to be posted online. Some browsers (Chrome, possibly Firefox with Safe Browsing mode, very likely any browser with a Google Toolbar installed) send visited URLs to Google and they will be indexed. I don't know if this is officially documented by Google, but several people have reported seeing this while testing new/beta websites that weren't published or linked anywhere.

I'm not sure either, but I doubt that Chrome or any of the badware-stopping features that are built in to it cause the URLs they're checking to be indexed. I'd be even more surprised if Firefox did this. If you've got the toolbar installed though, I'd be less surprised if they tried crawling or indexing URLs you go to. EDIT: It looks like they've explicitly said the toolbar does not cause things to appear in search r…

> EDIT: It looks like they've explicitly said the toolbar does not cause things to appear in search results

I read this too after posting, but I'm skeptical. It wouldn't be the first time they claimed to not do things they later admitted doing ... The rationale being that search engines need a way to discover new URLs quickly and keep ahead of the competition (indexing speed and breadth).

I'd also like to know what exactly Google Desktop Search does with URLs it finds.

Re: More than 1MM Facebook accounts exposed

#113
post #73

My name is Matt Jones, and I work on the Facbook security team that looked into this tonight. We only send these URLs to the email address of the account owner for their ease of use and never make them publicly available. Even then we put protection in place to reduce the likelihood that anyone else could click through to the account. For a search engine to come across these links, the content of the emails would nee…

Would Facebook ever consider having the option of two factor authentication (something similar, if not compatible with Google Authentication/TOTP/MOTP apps)?

It does, and I'm using it.

Re: More than 1MM Facebook accounts exposed

#114
post #73

My name is Matt Jones, and I work on the Facbook security team that looked into this tonight. We only send these URLs to the email address of the account owner for their ease of use and never make them publicly available. Even then we put protection in place to reduce the likelihood that anyone else could click through to the account. For a search engine to come across these links, the content of the emails would nee…

Thanks Matt, My only concern is my account security (not money). I found this issue with almost no technical knowledge, so the crazy thing is: How many back doors should be over there ready to be exploited by spammers? BTW, a big "report security issue" button on https://www.facebook.com/help/ would certainly help next time. Thanks again, Nico

It shouldn't take you more than one Google query to find the place to report Facebook security problems.

I don't think it's a good idea to link it from the general support section -- you don't want the security team that is hopefully carefully monitoring this stuff to have to wade through thousands of regular customer service complaints.

Re: More than 1MM Facebook accounts exposed

#115
post #24

Here's one theory and analysis of what might have happened. Some people's emails got out into the public internet, and were indexed. Some of these emails were from Facebook, and included links to resources that require login. These links pre-populated the username field for convenience, or in some cases auto-login the user. Facebook's engineers probably did not anticipate email notifications to users being crawled by…

This is how everything started: A friend forward me an email from a FB group notification Something like: http://www.facebook.com/n/?groups%[id here]%2Fpermalink%[id here]%2F&mid=[id here]&bcode=[id here]-mjoi&n_m=[email adress here] When I clicked the url I got automatically logged into my friend's account. So is definitely a Facebook security issue. Then I tried some google searches to see if I could find some urls…

Thanks for catching this nico-- looks like it's been removed from Google.

Re: More than 1MM Facebook accounts exposed

#116
post #61

Earlier quoted context omitted.

This arrogance is baffling. What makes you think you know enough about Facebook's infrastructure to make such a claim?

huh? Infrastructure is totally and utterly irrelevant to the problem. I know enough about common sense to make such a claim. Just send a new message, exactly as you would post an original item/comment/etc, but have some special text/field in there that says "please ignore the previous message". The UI would then hide the previous message. eg COMMENT: {id:9374758, from:"mibbitier", data:"I hate you all!"} COMMENT: {id…

I'm sure it's already rendered to a static presentation-level (HTML/template language du jour) form at that point. That wouldn't work.

Re: More than 1MM Facebook accounts exposed

#118
post #73

My name is Matt Jones, and I work on the Facbook security team that looked into this tonight. We only send these URLs to the email address of the account owner for their ease of use and never make them publicly available. Even then we put protection in place to reduce the likelihood that anyone else could click through to the account. For a search engine to come across these links, the content of the emails would nee…

Since this is already out there as a known issue, and concerns Google too, check out:

https://www.google.com/search?q=%22wants+to+be+friends+on+Fa...

And you'll find at the time of writing 250.000 more results where the "wants to be friends" email with the auto-login link is posted on blogs. Many of these blogs are also hacked, in that they redirect you to Russian dating sites if you visit the homepage.

An example of such a blog with password reset email is: http://papajimummyji.blogspot.com/

An example of a spam-redirecting blog is: http://demiansyahhh.blogspot.com/ (possibly unsafe)

For some more Facebook reset emails see:

https://www.google.com/search?q=%22You+recently+asked+to+res...

EDIT: Twitter emails are also exposed: https://www.google.com/search?q=%22Forgot+your+Twitter+passw...

Youtube emails: https://www.google.com/search?q=%22YouTube+sends+email+summa...

Twoo emails: https://www.google.nl/search?q=%22Massive+Media+NV%2C+Emile+...

And likely more web services.

Re: More than 1MM Facebook accounts exposed

#119
post #73

My name is Matt Jones, and I work on the Facbook security team that looked into this tonight. We only send these URLs to the email address of the account owner for their ease of use and never make them publicly available. Even then we put protection in place to reduce the likelihood that anyone else could click through to the account. For a search engine to come across these links, the content of the emails would nee…

Would Facebook ever consider having the option of two factor authentication (something similar, if not compatible with Google Authentication/TOTP/MOTP apps)?

Actually it already has, see http://www.facebook.com/note.php?note_id=10150172618258920.

Re: More than 1MM Facebook accounts exposed

#120
post #86

Earlier quoted context omitted.

The URLs don't need to be posted online. Some browsers (Chrome, possibly Firefox with Safe Browsing mode, very likely any browser with a Google Toolbar installed) send visited URLs to Google and they will be indexed. I don't know if this is officially documented by Google, but several people have reported seeing this while testing new/beta websites that weren't published or linked anywhere.

(Regardless of whether one has a Facebook account or not) If your theory is correct, this seems like a good reason to not use Chrome or any browser with a Google Toolbar :)

Another good reason.
Post reply on HN