Live data from Hacker News

More than 1MM Facebook accounts exposed

google.com

151–160 of 181 posts

Re: More than 1MM Facebook accounts exposed

#151
Okay, I've been through all the comments and I'm going to try to summarize:

- It looks like in some situations, Facebook will send an email that has a link. That link expires after a certain amount of time, but in the mean time, clicking that link lets people access that Facebook account.

- A large number of services can be set up to automatically post any email received onto the web. One major category is disposable email services such as asdasd.ru. Any email to a throwaway account on asdasd.ru gets put up on the web. Here's an example Facebook recovery email that got turned into a web page: http://asdasd.ru/read/414831

- Once these emails are just webpages, it's no surprise that search engines discover those URLs. Note that this is not a Google-specific issue. When I search on Bing for the query [site:facebook.com bcode n_m mid], the first result is also one of these urls that has an email address embedded in it. For a debunk of the misconception that this is related to the Google Toolbar or Chrome, see my post elsewhere in this discussion at http://news.ycombinator.com/item?id=4733276

So: an email gets sent to someone. That email gets put up on the web as a webpage. Search engines (including both Google and Bing) find that webpage as they follow links on the web.

Re: More than 1MM Facebook accounts exposed

#152

Okay, I've been through all the comments and I'm going to try to summarize: - It looks like in some situations, Facebook will send an email that has a link. That link expires after a certain amount of time, but in the mean time, clicking that link lets people access that Facebook account. - A large number of services can be set up to automatically post any email received onto the web. One major category is disposable…

I tried Bing and Yandex to find the email bodies. They didn't return many results (but they do return results).

http://www.bing.com/search?q=%22wants+to+be+friends+on+Faceb...

When I try on Google to find the email bodies, I get 250k results, of which the large majority are on blogspot.com sites.

While mail bodies can be found on a few other sites, like the asdasd.ru example, and other search engines have found these links too, the main issue still seems to be with blogspot.com -- These aren't throwaway accounts with public inboxes, but likely some virus that is intercepting certain mails (Facebook, Twitter, Youtube, Twoo) and reposting them as a blogpost for everyone to see.

As Blogspot is Google-owned, this does seem to me a predominantly Google-specific issue.

Re: More than 1MM Facebook accounts exposed

#153

Earlier quoted context omitted.

The URLs don't need to be posted online. Some browsers (Chrome, possibly Firefox with Safe Browsing mode, very likely any browser with a Google Toolbar installed) send visited URLs to Google and they will be indexed. I don't know if this is officially documented by Google, but several people have reported seeing this while testing new/beta websites that weren't published or linked anywhere.

Hi there, allow me to correct this misconception. I've debunked that idea often enough that I wrote a blog post about this four years ago: http://www.mattcutts.com/blog/toolbar-indexing-debunk-post/ I wrote an earlier debunk post in 2006 too: http://www.mattcutts.com/blog/debunking-toolbar-doesnt-lead-... I noticed a new twist in your post though: you're saying that because of Safe Browsing (which checks for e.g. mal…

Sorry but don't believe you about google toolbar. I had a private page with no links in or out and yet it appeared in google search. It was not guessable and there was no chance for a referrer link. The page was never shared with friends nor accessed outside my own computers.

I only found out when a friend searched for his name and the page appeared as it was my phone list

Re: More than 1MM Facebook accounts exposed

#154

Okay, I've been through all the comments and I'm going to try to summarize: - It looks like in some situations, Facebook will send an email that has a link. That link expires after a certain amount of time, but in the mean time, clicking that link lets people access that Facebook account. - A large number of services can be set up to automatically post any email received onto the web. One major category is disposable…

I tried Bing and Yandex to find the email bodies. They didn't return many results (but they do return results). http://www.bing.com/search?q=%22wants+to+be+friends+on+Faceb... When I try on Google to find the email bodies, I get 250k results, of which the large majority are on blogspot.com sites. While mail bodies can be found on a few other sites, like the asdasd.ru example, and other search engines have found these…

No, Blogger also has a feature that will automatically post messages sent to an email address. Here's an example email from Facebook that was posted to a blogspot.com url: http://weight-loss-information-123.blogspot.com/2012/08/misb...

If you look at the bottom of that Blogger post, it says "This message was sent to ." So an email from Facebook got posted as a web page to this blog.

There's no need to suspect some virus that's intercepting emails. Plenty of people have set up their systems such that email messages get turned into web pages.

Re: More than 1MM Facebook accounts exposed

#155

Earlier quoted context omitted.

Hi there, allow me to correct this misconception. I've debunked that idea often enough that I wrote a blog post about this four years ago: http://www.mattcutts.com/blog/toolbar-indexing-debunk-post/ I wrote an earlier debunk post in 2006 too: http://www.mattcutts.com/blog/debunking-toolbar-doesnt-lead-... I noticed a new twist in your post though: you're saying that because of Safe Browsing (which checks for e.g. mal…

Sorry but don't believe you about google toolbar. I had a private page with no links in or out and yet it appeared in google search. It was not guessable and there was no chance for a referrer link. The page was never shared with friends nor accessed outside my own computers. I only found out when a friend searched for his name and the page appeared as it was my phone list

Multiple people have run controlled experiments like I described in http://www.mattcutts.com/blog/debunking-toolbar-doesnt-lead-...

The most common way such "secret" pages get crawled is that someone visited that secret page with their referrers on and then goes to another page. For example, are you 100% positive that every person who ever visited that page had referrers turned off on every single browser (including mobile phones) they used to access that page?

Re: More than 1MM Facebook accounts exposed

#156

Earlier quoted context omitted.

I tried Bing and Yandex to find the email bodies. They didn't return many results (but they do return results). http://www.bing.com/search?q=%22wants+to+be+friends+on+Faceb... When I try on Google to find the email bodies, I get 250k results, of which the large majority are on blogspot.com sites. While mail bodies can be found on a few other sites, like the asdasd.ru example, and other search engines have found these…

No, Blogger also has a feature that will automatically post messages sent to an email address. Here's an example email from Facebook that was posted to a blogspot.com url: http://weight-loss-information-123.blogspot.com/2012/08/misb... If you look at the bottom of that Blogger post, it says "This message was sent to ." So an email from Facebook got posted as a web page to this blog. There's no need to suspect some vi…

You are probably right and I apologize for any misinformation. To me it seemed strange that the blogs first started spamming, followed by publishing only certain emails. Wouldn't it make more sense if all emails were published, not only from certain webservices? Why would a user want to publish their private Facebook emails in the first place? None of these accounts posts normal updates, they act compromised.

Re: More than 1MM Facebook accounts exposed

#158
post #61

Earlier quoted context omitted.

This arrogance is baffling. What makes you think you know enough about Facebook's infrastructure to make such a claim?

huh? Infrastructure is totally and utterly irrelevant to the problem. I know enough about common sense to make such a claim. Just send a new message, exactly as you would post an original item/comment/etc, but have some special text/field in there that says "please ignore the previous message". The UI would then hide the previous message. eg COMMENT: {id:9374758, from:"mibbitier", data:"I hate you all!"} COMMENT: {id…

Here's the thing that customers, managers, and less experienced developers all have in common: they understand that no one thing is difficult. But they don't take into account that managing the complexity between a thousand, or a hundred thousand, or a million rules is very, very difficult.

That's why you hire more experienced developers: they're more experienced, not at things like cache invalidation (sure, just nuke your entire cache anytime anything changes! easy!), but at managing complexity.

Which is difficult.

That's why I try to keep my mouth shut about how somebody should "just do this, it'd be so easy, why are they dumb?"

Re: More than 1MM Facebook accounts exposed

#159
post #144

Earlier quoted context omitted.

It shouldn't... but it could be easier. I've been in the situation before where I wanted to report malware on facebook and I couldn't figure out where to report it. I agree that you don't want reporting a security issue to supersede the general case of problems, but as things stand it is hard to figure out how to report a real security issue if you don't know about that magic whitehat url. Googling "facebook security…

shrug Perhaps you're right. But "Facebook report a vulnerability" works just fine and that's what I would have tried if I were trying to report a vulnerability.

That's still a few down in the search results.

It looks like the magic search term that brings you right to the report page is: "Facebook vulnerability"

http://google.com/?q=Facebook+vulnerability

Re: More than 1MM Facebook accounts exposed

#160
post #116

Earlier quoted context omitted.

I'm sure it's already rendered to a static presentation-level (HTML/template language du jour) form at that point. That wouldn't work.

Just put some more javascript in there to deal with it. I'm sure it's not the hardest problem in the world.

Great, you've hidden the message with javascript, but now it's still in view-source and in search results for bots.

It's also still visible if someone is using noscript (actually, I have no idea if Facebook works with noscript, probably not).

The solution you are suggestion doesn't solve the problem and injects more corner cases.

Post reply on HN