Skip to main content
  1. Home
  2. Computing
  3. Legacy Archives

Facebook applications security flaw fixed

Add as a preferred source on Google

A security flaw concerning Facebook applications that allowed advertisers to access user profiles has now, according to the social networking site, been dealt with.

Internet security firm Symantec said in a blog post that third parties “have accidentally had access to Facebook users’ accounts including profiles, photographs, chat, and also had the ability to post messages and mine personal information.”

Recommended Videos

Symantec’s Nishant Doshi, who discovered the issue along with co-worker Candid Wueest, pointed out that most of these third parties will not have known about the flaw. “Fortunately, these third-parties may not have realized their ability to access this information. We have reported this issue to Facebook, who has taken corrective action to help eliminate this issue,” Doshi said in the post.

Doshi explained that some Facebook applications inadvertently leaked what are called “access tokens” to third parties. Facebook applications are programs integrated into the Facebook website that enable users to shop and play games, among other things.

“We estimate that as of April 2011, close to 100,000 applications were enabling this leakage [and that] over the years, hundreds of thousands of applications may have inadvertently leaked millions of access tokens to third parties,” Doshi said.

The access tokens are described as being like spare keys that can be used to carry out certain actions on behalf of a user or to access the profile of a user. Doshi explained that “each token or ‘spare key’ is associated with a select set of permissions, like reading your wall, accessing your friend’s profile, posting to your wall, etc.”

In an email to the Wall Street Journal, a spokeswoman for Facebook said, “We’ve conducted a thorough investigation which revealed no evidence of this issue resulting in a user’s private information being shared with unauthorized third parties.”

According to Doshi, Facebook has been taken steps to fix the flaw to prevent further token leaks. He added, however, that “we fear a lot of these tokens might still be available in log files of third-party servers or still being actively used by advertisers.”

If any Facebook users are still worried about security with regards to this issue, Doshi has some useful advice: “Concerned Facebook users can change their Facebook passwords to invalidate leaked access tokens. Changing the password invalidates these tokens and is equivalent to “changing the lock” on your Facebook profile.”

With a site as massive as Facebook, security issues are bound to hit the headlines from time to time. In January the social networking site beefed up security by incorporating HTTPS capability. This came in the wake of a study conducted by Digital Society that looked at the basic security functions of some popular websites – Facebook didn’t come out of that too well. In January, the fan page of Facebook CEO Mark Zuckerberg was hacked (though his personal page remained intact) and was taken down. Worshippers of the man will be happy to know that the page is back up.

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Topics
Google’s AI is digging up Chrome bugs that humans missed for years
Here's how Google is using Gemini AI to find, triage, and patch Chrome security bugs faster than ever.
Google Chrome safety feature.

I've always assumed Chrome's endless update notifications were just routine housekeeping with a batch of actually useful features every now and then. Turns out some of them are patching bugs that have been quietly sitting in the browser's code for over a decade.

So how exactly is AI catching these bugs?

Read more
The Best Password Managers for 2026
As online security evolves, so should the way you protect your accounts
password manager on a mac.

Think about how many online accounts you use in a typical week. Between work, banking, shopping, streaming, social media, and everything in between, it's easy to end up managing dozens of passwords. Remembering a different, secure password for every account simply isn't realistic, which is why so many people fall back on reusing the same login across multiple websites. That's a recipe for disaster, if you ask any cybersecurity expert.

If you're in a conundrum on how to safely handle digital privacy, password managers are a reliable solution. Rather than trying to remember every single password yourself, a credentials manager tool securely stores your login details, creates stronger passwords for new accounts, and automatically fills them in whenever you need them.

Read more
Amazon and Walmart’s AI can spot fake ‘Made in USA’ labels but won’t tell you, says study
The same chatbot that happily discusses "Made in China" claims stays silent on "Made in USA" ones.
amazon-join-the-chat-ai

When you ask an AI shopping assistant to help you find products, you probably expect it to point out misleading listings too. According to a new study, both Amazon and Walmart's AI tools can detect fake "Made in USA" claims. However, the study claims that retailers are not using those capabilities to flag or remove the misleading listings, even when the AI recognizes conflicting information on the same product page.

How did the researchers catch this fraud?

Read more