Symantec Warns Certain Facebook Apps Are Leaking Info to Third Parties

By

It looks like some personal information has yet again been exposed, but this time it’s not all on Sony’s network.

Antivirus software company Symantec says a programming bug on Facebook may have mistakenly given advertisers, and others, a chance to scan the personal information of those using certain apps.

Nearly 100,000 Facebook applications have been inadvertently handing advertisers and online analytics companies, “access tokens,” strings of numbers and letters that can be used by a browser to access Facebook accounts online. The leaks were made via URLs that third parties received, according to a report in PCWorld.

Essentially, Facebook users have been sold out by their applications.

During the application installation process, the application requests the user to grant permissions to these actions. Upon granting these permissions, the application gets an access token.

By default, most access tokens expire after a short time, however the application can request offline access tokens which allow them to use these tokens until a user changes his or her password, even when not logged in.

“Access tokens are like ‘spare keys’ granted by you to the Facebook application. Applications can use these tokens or keys to perform certain actions on behalf of the user or to access the user’s profile. Each token or ‘spare key’ is associated with a select set of permissions, like reading your wall, accessing your friend’s profile, posting to your wall, etc.,” said Symantec in a blog post.

Information that may have been accessed includes profiles, photographs and chat. The access also had the ability to post messages and personal information.

“Fortunately, these third-parties may not have realized their ability to access this information. We have reported this issue to Facebook, who has taken corrective action to help eliminate this issue," Symantec said.

"Unfortunately, Symantec's resulting report has a few inaccuracies," Facebook spokeswoman Malorie Lucich said in a statement. "Specifically, we have conducted a thorough investigation that revealed no evidence of this issue resulting in a user's private information being shared with unauthorized third parties."

Lucich said the report also ignores the contractual obligations of advertisers and developers that prohibit them from obtaining or sharing user information in a way that "violates our policies.”

The remedy is plain and simple – just close this potential security hole for good by changing your password, as that will automatically revoke all previously issued keys.



Michelle Amodio is a TechZone360 contributor. She has helped promote companies and groups in all industries, from technology to banking to professional roller derby. She holds a bachelor's degree in Writing from Endicott College and currently works in marketing, journalism, and public relations as a freelancer.
Get stories like this delivered straight to your inbox. [Free eNews Subscription]

TechZone360 Contributor

SHARE THIS ARTICLE
Related Articles

ChatGPT Isn't Really AI: Here's Why

By: Contributing Writer    4/17/2024

ChatGPT is the biggest talking point in the world of AI, but is it actually artificial intelligence? Click here to find out the truth behind ChatGPT.

Read More

Revolutionizing Home Energy Management: The Partnership of Hub Controls and Four Square/TRE

By: Reece Loftus    4/16/2024

Through a recently announced partnership with manufacturer Four Square/TRE, Hub Controls is set to redefine the landscape of home energy management in…

Read More

4 Benefits of Time Tracking Software for Small Businesses

By: Contributing Writer    4/16/2024

Time tracking is invaluable for every business's success. It ensures teams and time are well managed. While you can do manual time tracking, it's time…

Read More

How the Terraform Registry Helps DevOps Teams Increase Efficiency

By: Contributing Writer    4/16/2024

A key component to HashiCorp's Terraform infrastructure-as-code (IaC) ecosystem, the Terraform Registry made it to the news in late 2023 when changes …

Read More

Nightmares, No More: New CanineAlert Device for Service Dogs Helps Reduce PTSD for Owners, Particularly Veterans

By: Alex Passett    4/11/2024

Canine Companions, a nonprofit organization that transforms the lives of veterans (and others) suffering PTSD with vigilant service dogs, has debuted …

Read More