Skip to main content
  1. Home
  2. Social Media
  3. News

Facebook pays $15,000 bounty to close bug that can access any user’s account

Add as a preferred source on Google

A major flaw in Facebook’s account security has been brought to light by a security researcher, who has received a cool $15,000 payout from the social network for his efforts.

Anand Prakash spotted the flaw, which allowed him access to any user’s account on the platform, last month. The bug was related to the Facebook account reset process, which results in the site sending a six-digit PIN to a user’s phone to be used as a temporary password.

Recommended Videos

Usually, the individual resetting an account is granted approximately 10-12 wrong password guesses. Prakash noticed that those security measures were missing from the Facebook beta site for developers, where every single user account is also readily available. Consequently, the bug allowed Prakash to seemingly flood the site with PIN guesses, and hack into any account he wanted.

Instead of exploiting the flaw, however, Prakash notified Facebook through its report vulnerability page. The following day, the social network confirmed that the bug occurred due to a change to the beta page a few days earlier. Although Facebook assures that the flaw was not misused in that time frame, it still felt compelled to pay the $15,000 bug bounty to Prakash.

The resulting award and Facebook’s rapid response in stamping out the bug hints at the major risk involved. It may not have been the most complicated security issue, but it could have resulted in complete chaos if utilized through the site’s main page.

“One of the most valuable benefits of bug bounty programs is the ability to find problems even before they reach production,” Facebook said in a statement to The Verge. “We’re happy to recognize and reward Anand for his excellent report.”

Since its inception, Facebook’s bug bounty program has forked out over $4 million to hackers and security researchers for responsibly disclosing issues in its system.

Saqib Shah
Saqib Shah is a Twitter addict and film fan with an obsessive interest in pop culture trends. In his spare time he can be…
Instagram lands on Samsung TVs, with episodic series and live TV coming to your screen soon
Instagram for TV adds new features for group watching.
instagram-samsung-tv

Meta just expanded Instagram for TV to Samsung Smart TVs across the US, rolling out a bunch of new features built for group viewing. With Samsung now on board, Instagram for TV has officially landed on the three biggest connected TV platforms in the country.

https://twitter.com/metanewsroom/status/2069062429821026732?s=46

Read more
TikTok’s AI slop problem is worse than you think — and kids are seeing the most of it
TikTok

TikTok has spent years perfecting the art of knowing exactly what you want to watch next. Open the app, scroll a few times, and suddenly it’s serving videos that feel uncannily tailored to your interests. But what happens before TikTok learns who you are? According to new research from video editing platform Kapwing, the answer is increasingly AI slop.

The study found that nearly 60% of the videos shown to a brand-new TikTok account were low-quality AI-generated content. That’s not a niche problem buried in obscure corners of the platform. It’s the first impression TikTok is making on new users before the algorithm even begins personalizing their feed. And if that sounds concerning, the findings around children’s content are even harder to ignore.

Read more
Your Instagram photo dumps just got a caption for every single slide
One toggle, up to 20 captions, and finally a reason to write something for every slide.
Clothing, Hardhat, Helmet

Instagram just made one of its most popular post formats significantly more useful. 

Starting today, you can add a unique caption to every single slide in a carousel post. So, instead of one caption trying to explain up to 20 different photos, each slide gets its own text underneath. It is the kind of addition that makes me wonder why it took this long.

Read more