Live data from Hacker News

More than 1MM Facebook accounts exposed

google.com

41–50 of 181 posts

Re: More than 1MM Facebook accounts exposed

#41
post #24

Here's one theory and analysis of what might have happened. Some people's emails got out into the public internet, and were indexed. Some of these emails were from Facebook, and included links to resources that require login. These links pre-populated the username field for convenience, or in some cases auto-login the user. Facebook's engineers probably did not anticipate email notifications to users being crawled by…

I clicked on some profiles, and I noticed that many of the e-mail addresses populated were @asdasd.ru — the domain of a Russian mailinator-type service. Something like that might be indexed.

Re: More than 1MM Facebook accounts exposed

#42
post #18

What is the meaning of the square brackets in the Google query syntax? I could not find any official documentation.

They don't seem to do anything. Searching without the brackets seems to give the same results for me.

https://www.google.com/search?q=inurl%3Abcode%3D*%2Bn_m%3D*+...

Re: More than 1MM Facebook accounts exposed

#43
post #24

Here's one theory and analysis of what might have happened. Some people's emails got out into the public internet, and were indexed. Some of these emails were from Facebook, and included links to resources that require login. These links pre-populated the username field for convenience, or in some cases auto-login the user. Facebook's engineers probably did not anticipate email notifications to users being crawled by…

"Some people's emails got out into the public internet, and were indexed. Some of these emails were from Facebook, and included links..."

Doesn't Google's toolbar phone home with the URLs you click on? That could be a way to get supposedly-private URLs into Google's list of URLs to be visited.

Re: More than 1MM Facebook accounts exposed

#44
post #24

Here's one theory and analysis of what might have happened. Some people's emails got out into the public internet, and were indexed. Some of these emails were from Facebook, and included links to resources that require login. These links pre-populated the username field for convenience, or in some cases auto-login the user. Facebook's engineers probably did not anticipate email notifications to users being crawled by…

This theory seems partially supported by the fact that a lot of email addresses here are on the same domains:

  yahoogrupos.com.br
  yahoogroupes.fr
  asdasd.ru
  blogger.com
Seems like emails on these domains are much more easily viewable/leakable/indexable than normal personal email addresses?

EDIT: Googling one of the discovered gmail address revealed a Facebook email (with 'bcode') being auto-blogged at weight-loss-information-123.blogspot.com https://encrypted.google.com/search?hl=en&q=danielsams20... - some kind of malware maybe?

Re: More than 1MM Facebook accounts exposed

#46
post #43
post #24

Here's one theory and analysis of what might have happened. Some people's emails got out into the public internet, and were indexed. Some of these emails were from Facebook, and included links to resources that require login. These links pre-populated the username field for convenience, or in some cases auto-login the user. Facebook's engineers probably did not anticipate email notifications to users being crawled by…

"Some people's emails got out into the public internet, and were indexed. Some of these emails were from Facebook, and included links..." Doesn't Google's toolbar phone home with the URLs you click on? That could be a way to get supposedly-private URLs into Google's list of URLs to be visited.

That's an interesting idea, but as someone noted, most of the emails involved here come from a small set of domains, such as blogger or anonymous mailinator type emails (emails which are possibly crawled by google often!)

I think if it were google's toolbars picking up urls in emails, that there would be many more email domains here.

Re: More than 1MM Facebook accounts exposed

#48

Facebook's privacy settings have a ton of bugs. Here's another one: 1. Make a stupid status update post. 2. It appears in all your friends newsfeed. 3. You realize you said something stupid and private. 4. Panic. Delete post 5. Breathe sigh of relief that it is no longer showing up in your profile. 6. But wait a minute! It still keeps showing up in all your friends newsfeed. 7. Now that you deleted the post, you can'…

Mumble mumble mumble eventual consistency mumble mumble sharded MySQL mumble mumble

Re: More than 1MM Facebook accounts exposed

#49

What exactly was exposed here. It looks like it's been blocked now... Just stealing from other bit in this thread: somehow these urls got on the Internet even though they shouldn't have. They are pre-authed urls that auto-login and then expire.

Seconding this... I see just ordinary account numbers from here.
Post reply on HN