Live data from Hacker News

More than 1MM Facebook accounts exposed

google.com

171–180 of 181 posts

Re: More than 1MM Facebook accounts exposed

#171
post #73

My name is Matt Jones, and I work on the Facbook security team that looked into this tonight. We only send these URLs to the email address of the account owner for their ease of use and never make them publicly available. Even then we put protection in place to reduce the likelihood that anyone else could click through to the account. For a search engine to come across these links, the content of the emails would nee…

I discovered this a long time ago, and I denounced this In this post you can see http://gonzac-studios.blogspot.com.ar/2012/02/hack-la-vulner...

Re: More than 1MM Facebook accounts exposed

#176
post #73

My name is Matt Jones, and I work on the Facbook security team that looked into this tonight. We only send these URLs to the email address of the account owner for their ease of use and never make them publicly available. Even then we put protection in place to reduce the likelihood that anyone else could click through to the account. For a search engine to come across these links, the content of the emails would nee…

Hi, My account was hacked at the weekend and although it is locked the person still keeps changing my password and I am not able to get into it. it wont let me reset my password as keeps coming up with an error message. I need this sorted and have had no help from fb even after reporting it numerous times

Re: More than 1MM Facebook accounts exposed

#177
post #73

My name is Matt Jones, and I work on the Facbook security team that looked into this tonight. We only send these URLs to the email address of the account owner for their ease of use and never make them publicly available. Even then we put protection in place to reduce the likelihood that anyone else could click through to the account. For a search engine to come across these links, the content of the emails would nee…

My name is Jared Null, and I first reported this as a vulnerability back in March to the bug bounty program. I've posted one conversation here: http://news.cnet.com/8301-1023_3-57544933-93/facebook-passwo.... I'm confused, you say that its not a vulnerability, yet Facebook had to take action. I guess seeing is believing and it only took a public disclosure to see the light. The sad thing is I reported both the recover password link and the checkpoint link "https://www.facebook.com/checkpoint/checkpointme?u= (which by the way is still vulnerable), the checkpoint links are reusable but the recover password links were one time use.

Jared Null WhiteHat Security

Re: More than 1MM Facebook accounts exposed

#178

Earlier quoted context omitted.

Millimetre is mm, not MM which would be "meter meter" which is nonsense. MM is actually the roman numeral for 1 million.

Capital M would be 'mega' as a prefix, but I think it does not exist as a unit. If you're willing to read MM as Mm, then it would be Megameter. Your really should revisit roman numerals. MM = 2000, you have to add them, not multiply.

Good point. So it turns out that MM is supposed to mean "thousand thousand" in the world of finance, but it is indeed not a correct roman numeral. Old school.

Re: More than 1MM Facebook accounts exposed

#179
hallo,..sorry for this message,but i need your help...one of my exfriend have my email and password (for account on facebook),... for this i have change my pasword and becouse he tries again and again to enter your security team locked my account and i can't have again back it....please , i need my profile,....help me how soon you can....thank you very much..i want back my account

Re: More than 1MM Facebook accounts exposed

#180

Earlier quoted context omitted.

Multiple people have run controlled experiments like I described in http://www.mattcutts.com/blog/debunking-toolbar-doesnt-lead-... The most common way such "secret" pages get crawled is that someone visited that secret page with their referrers on and then goes to another page. For example, are you 100% positive that every person who ever visited that page had referrers turned off on every single browser (including…

Are you sure that it is the referrer headers? PP clearly stated there were no outgoing links on the secret page. I think there's a much more mundane explanation: javascript stuff downloaded from Googles CDN. People nowadays are so used to just plopping jQuery etc. into their web pages that they forget that this stuff has to come from somewhere. If it's from Google, I'm quite certain that their CDN loader phones home…

[deleted]
Post reply on HN