Dons Deals

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 27 June 2013

Facebook Bug worse than reported - Non-users also affected - ZDNet

Posted on 12:10 by Unknown
This is just one ore reason, why. I don't put anything Personal or Important to me, on Face Book!:O

Don

Firm: Facebook 'bug' worse than reported; non-users also affected

Summary: According to the firm who found the bug, Facebook's email to six million users affected by its shadow profiles leak left out some numbers. Plus, non-user contacts were also leaked. UPDATED with Facebook responses (inline).

By Violet Blue for Zero Day | June 26, 2013 -- 13:05 GMT (06:05 PDT)

The security researchers who found Facebook's shadow profiles vulnerability have compared their numbers to what Facebook told its users in emails, and the numbers don't match.

They say Facebook told users the data exposure is much less than what the researchers found, and the researchers also say Facebook is hoarding non-user contact information — seen when it was also shared and exposed in the leak.

Friday Facebook announced the fix of a bug it said inadvertently exposed the private information of over six million users when Facebook's previously unknown shadow profiles accidentally merged with user accounts in data history record requests. 

Since at least 2012, Facebook users who used the Download Your Information (DYI) tool to get their data history record also got an address book with contacts users had never provided to Facebook.

Facebook explained the issue to ZDNet Sunday after user anger exploded — saying that when a Facebook user uploads an address book, the social network obtains all contacts in the user's database and saves all of them.

Users are still furious and were unaware that their not-for-sharing, offsite phone numbers and email addresses are being collected, stored, secretly matched to them (and now accidentally shared) by Facebook.

In its Friday email, Facebook disclosed the security and privacy flaw to users, but no one knew that Facebook's email wasn't telling the whole story — except security researcher Michael Fury (who originally found the vulnerability) and colleagues at Packet Storm Security (and anyone quietly exploiting the data breach).

Because Packet Storm had prior test data verifying the leak, they were able to compare what they knew was actually being revealed in the DYI reports against what Facebook reported to its users via email — as well as what Facebook told the press.

Packet Storm wrote in Facebook: Math of the Aftermath,

We compared Facebook email notification data to our test case data. In one case, they stated 1 [one] additional email address was disclosed, though 4 pieces of data were actually disclosed.

For another individual, they only told him about 3 out of 7 pieces of data were disclosed.

Read More...
http://www.zdnet.com/firm-facebook-bug-worse-than-reported-non-users-also-affected-7000017318/?s_cid=e036&ttag=e036

News 06-27-13
Linux Today - Fedora 19 RC2 "Schrödinger's Cat" Is Now Available for Testing
Fedora 19 RC2 "Schrödinger's Cat" Is Now Available for Testing
Linux Today - Raspberry Pi bot tracks hacker posts to vacuum up passwords and more
Raspberry Pi bot tracks hacker posts to vacuum up passwords and more | Ars Technica
Linux Today - Find an open source RSS reader today
Open source alternatives to Google Reader | opensource.com
Astrosmash style video game as Sony SmartWatch firmware
Atari 2600 has a Raspberry Pi hiding under the hood
Building an IR mouse interface for the disabled
Going, Going, Still Going? Voyager 1 at Solar System’s Edge - NYTimes.com
PayPal Galactic to Make Space Money Transfers : Discovery News
Ugly Animals That Need Saving Too: Photos : Discovery News
Is Your Fido Really a Furry Baby? – WebMD
Firm: Facebook 'bug' worse than reported; non-users also affected | ZDNet
Five Apps: Free disaster recovery | TechRepublic
Packet Storm
Search files: Facebook 'bug' ≈ Packet Storm
fin1te - Hijacking a Facebook Account with SMS
Facebook Information Disclosure ≈ Packet Storm
DNews: Can Air Pollution Be Good for the Earth? : Discovery News

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • ZigBee - a specification for a suite of high level communication protocols used to create personal area networks built from small low-power digital radios
    ZigBee From Wikipedia, the free encyclopedia Jump to: navigation , search ZigBee ...
  • Open Sorce Hardware - The Wandboard is a low cost board based on the i.MX6 multicore ARM Cortex-A9 family of processors. In consists of a core module based on the EDM standard and a simple to extend baseboard
    Here's an Open Source Wandboard - Freescale i.MX6 ARM Cortex-A9 Opensource Community Development Board. The Wandboard is a low ...
  • 1967 Chevy Camaro Complete Rebuild - Videos, HowStuffWorks Videos "NAPA Videos"
    Video Playlist - West Coast Customs Shop, Completely Tears Down a 1967 Chevy Camaro and then does a Complete Rebuild...
  • Installing and Updating GRUB 2 in Fedora Linux
    This Page has allot of info on Installing, Updating and Trouble Shooting Grub 2 in Fedora Linux. There are some good How To's for...
  • Dynaco Stereo 400 Power Amplifier - Dead Channel Fix - Dynaco Repairs For PC-28 Amplifier Boards
    My Dynaco Stereo 400 Amp... The Page Below these e-mails with Kevin Boales. Looks like the one that I found. Back in ...
  • Open source PLC's - PLC (programmable logic controller)
    Here's some Great Looking Open source PLC Projects. The OSPLC Small & Large Bricks are open-source PLC (programmable logic ...
  • NetProMax PC with Motherboard P5PE-VM ASUSTeK
    Here are some links to info on the NetProMax PC with Motherboard P5PE-VM ASUSTeK ... Don ASUSTe...
  • Running a PXE Boot Server in Parted Magic
    Here's some good info on Running PXE Boot Server in Parted Magic... Don PXE – Parted Magic PXE PXE: the "classic" way ...
  • Americas Health Care - Obama Care - Key Features of the Affordable Care Act - Health Care and Education Reconciliation Act
    Finally! Some real info, as in... This is the date that the Affordable Care Act, goes into effect. Open enrollment in the Heal...
  • Building a Brushless Motor Controller using an ATmega Chip - by Davide Gironi
    Here's a very in depth Article on Building a Brushless Motor Controller using an ATmega Chip - by Davide Gironi... Do...

Blog Archive

  • ▼  2013 (354)
    • ►  December (12)
    • ►  November (33)
    • ►  October (23)
    • ►  September (46)
    • ►  August (52)
    • ►  July (36)
    • ▼  June (45)
      • Murph - a Man Exploring the World on a BMW R 1150
      • Crazy Robotic Drummer - YouTube Video and Many Mor...
      • How to Make Pull-Out Shelves for Kitchen Cabinets ...
      • iGoogle Alternatives - The deadline for the demise...
      • Dynasphere a monowheel vehicle design patented in ...
      • Would you trust a Company in India with your Medic...
      • Hitch Hikers Ride to the Moon - Moon Mission for $300
      • MacBook Conversions and Repairs adding Internal US...
      • A New Linux Distro - SolydX and SolydK are Debian ...
      • Fedora 19 Final RC2 Desktop Download - FedoraProject
      • Can Air Pollution Be Good for the Earth? - Discove...
      • Facebook Bug worse than reported - Non-users also ...
      • Electronic Cello - Theremin Cello and the New Ther...
      • A New Old Electronic Musical Instrument - The Onde...
      • MonotrOndes - Korg Monotron hacked into Ondes Mart...
      • George of the Jungle - YouTube
      • The Jungle - Book
      • Rethinking Bottled Water - by Gina Shaw WebMD.com
      • Adjustable Power Supplies DC Voltage Regulators DC...
      • How to use a Multimeter for beginners - Part 1 - V...
      • Making Graphene with a DVD burner and Synthesizing...
      • Fly Geyser is located on the private Fly Ranch and...
      • Icons - Collections of Free Icons and Software to ...
      • WiSee - Wi-Fi signals enable gesture recognition t...
      • Cybersecurity for Medical Devices and Hospital Net...
      • 3 Ways to Control Black Spot on Roses - wikiHow
      • Ophcrack - My Review for ophcrack at SourceForge.n...
      • Google begins launching Internet-beaming balloons ...
      • CentOS - TUI's text-based user interfaces, availab...
      • ServiWin: Windows Services/Drivers Tool (start/sto...
      • DIY Cyclone Dust Collectors and Wet Spill Vacuum C...
      • Here's your Kitten Video, for Today
      • Fedora Linux Project - Download Links and info
      • Recalls, Market Withdrawals, & Safety Alerts > Ald...
      • Open source PLC's - PLC (programmable logic contro...
      • How are these Car Thieves exploiting Automotive Ke...
      • XnView - Great Free Software for reading, organizi...
      • Glary Utilities by Glarysoft - One Click Windows P...
      • UDOO - Android Linux Arduino in a tiny single-boar...
      • Ninite.com Easy Multiple Open Source App Installer...
      • Screenshot Captor - Free Software at DonationCoder...
      • Billionaires Dumping Stocks, Economist Knows Why -...
      • Autoranging Multimeter Review - YouTube
      • Linux Terminal Basics and some Commands - Codecademy
      • Pidora The Raspberry Pi Fedora Remix - opensource.com
    • ►  May (17)
    • ►  April (38)
    • ►  March (19)
    • ►  February (22)
    • ►  January (11)
  • ►  2012 (145)
    • ►  December (27)
    • ►  November (31)
    • ►  October (14)
    • ►  September (15)
    • ►  August (48)
    • ►  July (10)
Powered by Blogger.

About Me

Unknown
View my complete profile