Email addresses. Facebook faces a new crisis
Facebook is still struggling with the effects of revealing the phone numbers of hundreds of millions of users over the past month, but it is now facing a new privacy crisis over email addresses that the social media giant has to deal with.
An anonymous security researcher has highlighted a new vulnerability that reveals millions of users' email addresses.
He designed a tool called Facebook Email Search v1.0 that links Facebook accounts to the email addresses associated with them.
An anonymous security researcher has posted a video showing the tool that can link Facebook accounts to email addresses, even when the user chooses not to display the email address to the public.
He explained that the tool was able to process up to 5 million addresses per day, but he provided it with a list of 65,000 addresses just to prove the concept.
He said: I reported the vulnerability to Facebook before posting it, but I made the Facebook Email Search tool v1.0 and posted the video after the social media giant told me it didn't think the exploit was important enough to be fixed.
In response to the report on Facebook Email Search tool v1.0, a Facebook spokesperson said: We value the researcher's sharing of information and are taking initial measures to mitigate this issue as we continue to better understand his findings.
"Facebook engineers believe they have mitigated the leak by disabling the technology shown in the video," he added.
It is currently unknown if the bug was used to create a database of email addresses of Facebook users.
The researcher said: Facebook had a similar vulnerability earlier this year that was fixed, and this is exactly the same one, and for some reason they told me directly that they would not take any action on it, even though I made it clear to Facebook.
Facebook has been criticized for collecting this massive amount of data and the way it is actively trying to promote the idea that such vulnerabilities cause minimal harm to its users.
And in an email about a leak of phone numbers of hundreds of millions of users that Facebook mistakenly sent to the Dutch publication DataNews, the company instructed public relations workers to frame this as a large-scale industry problem and normalize the fact that this activity occurs regularly.
Comments
Post a Comment