Skip to main content
  1. Home
  2. Social Media
  3. Web
  4. News

Facebook investigating more security vulnerabilities with third-party logins

Add as a preferred source on Google

After a whistleblower suggested that many personality quiz apps are designed to track user data, Facebook users have yet another reason to avoid logging in with Facebook credentials. Researchers at Princeton University say lax security could allow third-party platforms to use JavaScript trackers to abuse data on some websites using the “login with Facebook” tool. In a report published on the Freedom to Tinker website hosted by the Center for Information Technology Policy at Princeton Unversity, researchers suggest social login APIs can be abused by third-party scripts through two different vulnerabilities.

The researchers found seven third-party companies accessing Facebook user data through a tool allowing users to log into websites using their Facebook ID. The report suggests that signing in with a social account unknowingly allows the user to trust not just that website, but third-party tools on that same website. 

Recommended Videos

The group found scripts embedded in websites that, when a user logs in with a Facebook account, will access the user ID and, depending on the script, other data like email addresses and even gender. The team wasn’t able to determine just how the information is used, but four of those third-party platforms run what they called a “consumer data platform.” A fifth runs cross-device tracking.

The team managed to find the scripts that caused the vulnerability installed on 434 websites out of the top 1 million sites on the web. One of those sites, MongoDB, a cloud database, has already corrected the script.

The group found fewer instances of the second type of vulnerability, but said that third-party trackers could “deanonymize users.” This type of script was found on Bandsintown, where an iFrame could be used for other websites to embed data from the music platform. The iFrame could pass user data, including identifying data, onto malicious websites accessing that iFrame. Bandsintown says the vulnerability has now been corrected.

The researchers call the vulnerability unintended, but also say that it’s “the lack of boundaries between the first-party and third-party scripts in today’s web,” not because of a bug. Facebook says that they are investigating the report.

The report is just one of the third-party vulnerabilities Facebook is currently investigating. After Cambridge Analytica, the platform is conducting audits on third-party apps using the Facebook API. Both the website scripts and the third-party apps required users to log in with their Facebook credentials.

Hillary K. Grigonis
Hillary never planned on becoming a photographer—and then she was handed a camera at her first writing job and she's been…
Instagram is testing a more convenient way to tune recommendations
A Reels shortcut is being tested to make Instagram’s Your Algorithm tool easier to access
Instagram

We have all had an Instagram feed go off track. A random Reel catches your attention for a moment, and before long, the app starts serving up the same kind of content again and again.

Instagram already has a way to fix some of that through Your Algorithm, a feature that lets users adjust the topics shaping their recommendations. Now, the company wants to make that tool easier to reach while people are actually using the app.

Read more
Snapchat Planets Meaning: Order, Rankings, and How Friend Solar System Works
Snapchat Planets turns your best friends list into a solar system, and yes, your orbit says a lot
Snapchat Planets being shown on the Snapchat app on iPhone.

Snapchat+ includes several exclusive features, but few have generated as much curiosity as Snapchat Planets. Part of the app's Friend Solar System, it transforms your Best Friends list into a planetary ranking, assigning each of your top eight friends a planet based on how often you interact.

From Mercury, which represents your closest friend, to Neptune, which represents your eighth closest, the system offers a quick visual snapshot of your interactions. But what do the different planets actually mean, and how does Snapchat decide who gets which one?

Read more
Instagram lands on Samsung TVs, with episodic series and live TV coming to your screen soon
Instagram for TV adds new features for group watching.
instagram-samsung-tv

Meta just expanded Instagram for TV to Samsung Smart TVs across the US, rolling out a bunch of new features built for group viewing. With Samsung now on board, Instagram for TV has officially landed on the three biggest connected TV platforms in the country.

https://twitter.com/metanewsroom/status/2069062429821026732?s=46

Read more