Facebook leaked keys to account data: Symantec

Advertisement
By Agence France-Presse | Updated: 5 June 2012 02:08 IST
Highlights
  • US computer security firm Symantec on Tuesday said that Facebook accidentally left a door open for advertisers to access profiles, pictures, chat and other private data at the social network.
US computer security firm Symantec on Tuesday said that Facebook accidentally left a door open for advertisers to access profiles, pictures, chat and other private data at the social network.

Symantec discovered that certain Facebook applications leaked tokens that act essentially as "spare keys" for accessing profiles, reading messages, posting to walls or other actions.

Facebook applications are Web software programs that are integrated onto the leading online social network's platform. Symantec said that 20 million Facebook applications such as games are installed every day.

The tokens were being leaked to third-party applications including advertisers and analytic platforms allowing them to post messages or mine personal information from profiles, according to Nishant Doshi of Symantec.

"Fortunately, these third-parties may not have realized their ability to access this information," Doshi said in a blog post.

"We have reported this issue to Facebook, who has taken corrective action to help eliminate this issue."

Symantec estimated that as of April, nearly 100,000 applications were giving away keys to Facebook profiles.

"We estimate that over the years, hundreds of thousands of applications may have inadvertently leaked millions of access tokens to third parties," Doshi said.

Facebook confirmed the problem, which was discovered by Doshi and Symantec colleague Candid Wueest, according to the computer security firm.

There was no reliable estimate of how many tokens have been leaked since the release of Facebook applications in 2007.

Despite whatever fix Facebook has put in place, token data may still be stored in files on third-party computers, Symantec warned.

"Concerned Facebook users can change their Facebook passwords to invalidate leaked access tokens," Doshi said.

"Changing the password invalidates these tokens and is equivalent to 'changing the lock' on your Facebook profile."

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Redmi Pad 2 Pro 5G Will Launch in India Soon: See Expected Features
  2. Xiaomi 17 Ultra With Leica-Tuned Cameras Confirmed to Launch Soon
  3. Nvidia's GeForce RTX 50 Series GPUs Are About to Be Scarce
  4. GTA 6 Map Guide: Here's All You Need to Know About Different Areas
  5. OnePlus 15s Visits BIS Certification Website; Could Launch in India Soon
  6. Eko OTT Release Reportedly Revealed: When and Where to Watch it Online?
  7. You Can Now Vibe Code AI Mini Apps Within Gemini With This Tool
  8. Samsung Will Unveil These New Bespoke AI Devices at CES 2026
  9. Best ANC TWS Earbuds Under Rs 8,000: Sony WF-C710N, OnePlus Buds 4, More
  10. OnePlus Watch Lite With Up to 10 Days Battery Life Launched: See Price
  1. Adobe Firefly Platform Updated With New AI Models and Tools, Offers Limited-Time Unlimited Generations
  2. Boat Valour Ring 1 Launched in India With Heart Rate Variability Tracking, Up to 15-Day Battery Life: Price, Features
  3. Call of Duty: Black Ops 7 Was the Best-Selling Game in the US in November, but Trails Battlefield 6 in 2025
  4. Truecaller Voicemail Feature Launched for Android Users in India With Transcription in 12 Regional Languages
  5. OpenAI Starts Reviewing Third-Party App Submissions for ChatGPT Integration
  6. Google Brings Opal, an AI-Powered Mini App Builder Tool to Gemini
  7. Redmi Pad 2 Pro 5G India Launch Teased Soon After Global Debut: Expected Specifications, Features
  8. CES 2026: Samsung to Unveil Bespoke AI Laundry Combo, Jet Bot Steam Ultra Robot Vacuum, and More
  9. Samsung Exynos 2600 Details Leak Ahead of Galaxy S26 Launch; Could Be Equipped With 10-Core CPU, AMD GPU
  10. Vivo Y50e 5G, Vivo Y50s 5G Appear on Google Play Console; Mysterious Vivo Phone Listed on Certification Site
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.