Facebook cancels shortcut over concern for security

Advertisement
By Somini Sengupta, The New York Times | Updated: 5 November 2012 11:50 IST
What was supposed to be a shortcut for Facebook users to log into their pages ended up exposing their e-mail addresses and, in some cases, potentially allowing access to their accounts as well.

A Facebook spokesman said on Friday that the company had created the shortcut, called auto login, to let some users go directly to their pages by clicking on a Web link sent to their e-mail addresses. Once they clicked on the link, they could get into their accounts, rather than having to go to Facebook.com and log in.

Some of the links required users to type their passwords, while others did not, the company said.

Advertisement

On the Web site Hacker News, a technology discussion board, Matt Jones, an engineer at Facebook, said the company had offered the service for "ease of use" and never made the Web addresses "publicly available."

But they did become publicly available, as the discussion on Hacker News revealed on Friday.

Advertisement

The Facebook spokesman, Frederic Wolens, said some users may have posted the links on the Web, allowing anyone to search for them. Those links could give a stranger access to the Facebook pages connected to them, as well as the e-mail addresses of those users. Mr. Wolens said he had no explanation why someone would post the links.

When Facebook found the problem, it discontinued the shortcut.

Advertisement

The Hacker News thread said over one million Facebook accounts had been affected. Facebook could not confirm that figure on Friday afternoon.

TrendMicro, a private security company that offers safety tools for Facebook users, said Web address shortcuts were inherently dangerous because they could ultimately end up on the Web.

Advertisement

"Many, many hackers are targeting these portals because of the ubiquitous trust and use of them," said Tom Kellermann, vice president for cybersecurity at TrendMicro. He added, "You don't take shortcuts through the woods in cyberspace."

The news of the security hole comes a week after a Bulgarian blogger, Bogomil Shopov, said he had bought 1.1 million Facebook users' names and e-mail addresses on the Web for $5. He found the information for sale on a marketplace site, gigbucks.com. The items are no longer available.

Mr. Wolens of Facebook said the data had been acquired and compiled by someone who took whatever information Facebook users made public on their pages and from other publicly available data about those users.

Mr. Kellermann of TrendMicro said the problem with the shortcut could explain how the names and e-mail addresses that Mr. Shopov had found became public. Facebook said the security flaw and the user data for sale had nothing to do with each another.

"We have no reason whatsoever to believe that these two incidents are related," Mr. Wolens said.

© 2012, The New York Times News Service

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo X300 FE Arrives in India With a 50-Megapixel Zeiss Camera at This Price
  2. Vivo X300 Ultra Debuts in India With 200-Megapixel Zeiss Cameras: See Price
  3. Infinix Note 60 Pro Review: Just Another Mid-Ranger?
  4. Adobe Acrobat gets a Productivity Agent, New PDF Spaces Features
  5. Vivo X300 FE Review: A Strong Contender With a Catch
  6. Vivo X300 Ultra vs Samsung Galaxy S25 Ultra vs iPhone 17 Pro Max
  7. Apple Agrees to Pay $250 Million Settlement for Misleading Claims on AI
  8. Cognizant Could Cut Up to 15,000 Jobs Globally Amid AI-Led Restructuring
  1. Astronomers Discover Trans-Neptunian Object With Atmosphere in Outer Solar System
  2. Samsung's One UI 8.5 Update Finally Rolls Out to Galaxy S25 Series, S24 Series, S25 FE, Z Fold 7 and Z Flip 7
  3. Samsung Galaxy A27 5G Shows Up on Geekbench Again With Slightly Improved Performance Scores
  4. Adobe Unveils New Productivity Agent for Acrobat, Adds New Features to PDF Spaces
  5. Google's May 2026 Update for Pixel Devices Rolls Out With Fixes for Slow Wireless Charging, Screen Freezing Issues
  6. Colombia Seeks to Mine Bitcoin Using Surplus Renewable Energy From Country's Coastline
  7. CloudZ RAT Malware Could Exploit Microsoft Phone Link App to Access Messages and OTPs, Researchers Warn
  8. Vaazha II: Biopic of a Billion Bros OTT Release Date: When and Where to Watch This Malayalam Drama Film Online
  9. Dacoit: A Love Story OTT Release Date: When and Where to Watch Adivi Sesh and Mrunal Thakur Starrer Online?
  10. Sony Xperia 1 VIII Price, Sale Date Reportedly Surface Online via Amazon Listing
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.