Hackers accessed data of 30 million Facebook users

Agencies
October 13, 2018

Washington, Oct 13: Social media giant Facebook, which has its largest user base in India, said that a recent hacking into its system has affected about 30 million users.

Facebook product management vice president Guy Rosen on Friday said the cyber attackers exploited a vulnerability in Facebook's code that existed between July 2017 and September 2018.

The vulnerability has now been fixed, but not before the attackers used an automated technique to move from account to account so they could steal the access tokens of users, their friends, friends of their friends, and so on, totalling about 400,000 people.

"The attackers used a portion of these 400,000 people's lists of friends to steal access tokens for about 30 million people. For 15 million people, attackers accessed two sets of information, name and contact details -- phone number, email, or both, depending on what people had on their profiles," Rosen said.

For another 14 million people, the attack was potentially more damaging as the hackers accessed both their name and contact details as well as other details like username, gender, location, language, relationship status, religion, hometown, date of birth, device types used to access Facebook, education, work details, places they have recently "checked in" to as visiting, people or pages they follow and the 15 most recent searches.

For the remaining one million people whose access token were stolen, the attackers did not access any information, Rosen said. He said users' accounts have already been secured by the Facebook two weeks ago and they do not need to log out again or change their passwords. The attack did not affect Facebook-owned Messenger, Messenger Kids, Instagram, WhatsApp, Oculus, Workplace, third-party apps, payments, Pages, and advertising or developer accounts, the company said.

Asserting that Facebook is still looking at other ways the hackers may have used the platform, Rosen said, "People's credit card information would not have been visible to the attackers, as we do not display full credit card numbers -- not even to the account holder."

"We haven't ruled out the possibility of smaller-scale, low-level access attempts during the time the vulnerability was exposed. Our investigation into that continues," he said.

Facebook has been cooperating with the FBI, the US Federal Trade Commission, the Irish Data Protection Commission and other authorities.

"We don't have a specific indication of the intention of the attackers. And as we have said, we are cooperating with the FBI in an active investigation. As part of the information that we will be sharing with users over the coming days, we will be including information as to how they can watch out for any suspicious e-mails or text messages or things of that sort," Rosen said.

Responding to a question, he said, the company will be notifying people through Facebook so that they can understand what information was accessed from their account and which group they were part of.

"We will also work to contact people who may not be on Facebook any longer," he said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
June 22,2020

New Delhi, Jun 22: Defence Minister Rajnath Singh on Monday left for a three-day visit to Russia. Singh is likely to discuss the India-Russia defence and strategic partnership during the visit and also attend a military parade in Moscow to mark the 75th anniversary of the Soviet victory over Nazi Germany in the Second World War.

The visit comes days after the violent face-off with China in which 20 Indian Armymen were killed in Galwan valley in Ladakh.

"Leaving for Moscow on a three day visit. The visit to Russia will give me an opportunity to hold talks on ways to further deepen the India-Russia defence and strategic partnership. I shall also be attending the 75th Victory Day Parade in Moscow," the Defence Minister tweeted.

Defence Secretary Ajay Kumar is also accompanying the minister.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
January 3,2020

Giving each and every app access to personal information stored on Android smartphones such as your contacts, call history, SMS and photos may put you in trouble as bad actors can easily use these access to spy on you, send spam messages and make calls anywhere at your expense or even sign you up for a premium "service", researchers from cybersecurity firm Kaspersky have warned.

But one can restrict access to such information as Android lets you configure app permissions. 

Giving an app any of these permissions generally means that from now on it can obtain information of this type and upload it to the Cloud without asking your explicit consent for whatever it intends to do with your data.

Therefore, security researchers recommend one should think twice before granting permissions to apps, especially if they are not needed for the app to work. 

For example, most games have no need to access your contacts or camera, messengers do not really need to know your location, and some trendy filter for the camera can probably survive without your call history, Kaspersky said. 

While decision to give permission is yours, the fewer access you hand out, the more intact your data will be.

Here's what you should know to protect your data.

SMS: An app with permission to send and receive SMS, MMS, and WAP (Wireless Application Protocol) push messages, as well as view messages in the smartphone memory will be able to read all of your SMS correspondence, including messages with one-time codes for online banking and confirming transactions.

Using this permission, the app can also send spam messages in your name (and at your expense) to all your friends. Or sign you up for a premium "service." You can see and conrol which apps have these rights by going to the settings of your phone.

Calendar: With permission to view, delete, modify, and add events in the calendar, prying eyes can find out what you have done and what you are doing today and in the future. Spyware loves this permission.

Camera: Permission to access the camera is necessary for the app to take photos and record video. But apps with this permission can take a photo or record a video at any moment and without warning. Attackers armed with embarrassing images and other dirt on you can make life a misery, according to Kaspersky.

Contacts: With permission to read, change, and add contacts in your address book, and access the list of accounts registered in the smartphone, an app can send your entire address book to its server. Even legitimate services have been found to abuse this permission, never mind scammers and spammers, for whom it is a windfall.

This permission also grants access to the list of app accounts on the device, including Google, Facebook, and many other services.

Phone: Giving access to your phone means permission to view and modify call history, obtain your phone number, cellular network data, and the status of outgoing calls, add voicemail, access IP telephony services, view numbers being called with the ability to end the call or redirect it to another number and call any number.

This permission basically lets the app do anything it likes with voice communication. It can find out who you called and when or prevent you from making calls (to a particular number or in general) by constantly terminating calls. 

It can eavesdrop on your conversations or, of course, make calls anywhere at your expense, including to pay-through-the-nose numbers, Kaspersky warned.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
May 28,2020

Pulwama, May 28: A major incident of a vehicle-borne IED blast was averted by the timely input and action by Pulwama Police, Central Reserve Police Force (CRPF) and Army, the Jammu and Kashmir Police said.

According to sources, Pulwama Police got credible information last night about a terrorist moving with an explosive-laden car ready to blast at some location. They took out various parties of police and security forces and covered all possible routes keeping themselves and the police and security forces away from the road at safer locations.

The suspected vehicle came and a few rounds were fired towards it. A little ahead this vehicle was abandoned and the driver escaped in the darkness. On close look, the vehicle was seen to be carrying heavy explosives in a drum on the rear seat. Possibly more explosive would be fitted elsewhere in the vehicle, sources added.

The vehicle was kept under watch for the night. People in nearby houses were evacuated and the vehicle exploded in situ by the Bomb Disposal Squad as moving the vehicle would have involved serious threat, sources said.

The vehicle reportedly sports a number plate of a scooter registered somewhere in Kathua district of Jammu zone, sources added.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.