Ads by TechWords

See your link here
Receive the latest technology news and information.
Networking
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Update: Facebook fixes security lapse that exposed photos

Researcher and reporter accessed restricted photos of Paris Hilton, Facebook CEO

March 26, 2008 12:00 PM ET

Active Comments
Anonymous says: Why has no one on FB detected that if you send or tag a picture to your profile or send...
Health says: I think the next security lapse will come from the way they opened up data to 3rd party developers for...


Computerworld - Even after last week's unveiling of privacy upgrades, a security lapse on the Facebook Inc. social network early this week still exposed restricted photos to anyone using the site, according to an Associated Press report later confirmed by the company to Computerworld.

A spokeswoman said that after learning of the problem, Facebook engineers on Monday "tested the scenario, found that it was a bug and fixed it immediately." In a statement, the company added that "We take security very seriously."  

The AP verified the security lapse earlier Monday after receiving a tip from Byron Ng, a Canadian computer technician who claimed to discover the lapse. Ng said he began looking for security weaknesses at the popular social network after last week's announcement that Facebook had developed new ways for members to limit access to content in their personal profiles.

Ng was able to find private pictures of Paris Hilton, and he sent the AP a template that allowed the company to access private photos of Facebook co-founder and CEO Mark Zuckerburg.

Marshall Kirkpatrick, a blogger at ReadWriteWeb, wrote that his readers had found evidence that the photos were exposed to unauthorized users for months via a simple URL edit.

"[The lapse] appears to have been simply a technical inadequacy," Kirkpatrick wrote. "It's tempting to say that breaches like this are an obstacle to ongoing user adoption of online services. At the same time, how often are credit card numbers exposed? The convenience of online shopping mitigates the impact of those stories. The same may or may not be true with online social networking."

Nick O'Neill, a blogger at AllFacebook, said that as Facebook grows, the company will be forced to upgrade privacy protections during each level of development.

"Then again, should Facebook hold the same standards for their photos team as they do for their credit card processing?" O'Neill added. "I would imagine that it ends up being a cost-benefit analysis which determines how much protection goes into each product."



Jump to comments

facebook

Additional Resources

WHITE PAPER
Approximately 60 percent of data migration projects overrun time or budget, while some fail completely. Download this white paper, "Enhancing Your Chance for Successful Data Migration," to learn the critical steps you need to take to execute a data migration project with minimum cost and risk to your business.
WHITE PAPER
Read the Gartner research note to learn why the TCO of a server-based computing deployment used to deliver all applications to users is around 50% lower than that of an unmanaged desktop deployment.
WHITE PAPER
Economic downturns have a tendency to accelerate emerging technologies, boost the adoption of effective solutions, and punish solutions that are not cost competitive or that are out of synch with industry trends. This IDC White Paper presents the results of an IDC survey of 330 companies in Western Europe, Asia/Pacific and the Americas that measures the receptiveness to Linux and takes into consideration changing views driven by the disruptive economic environment that businesses face today.

What People Are Saying

White Papers & Webcasts

Virtualization and Web 2.0
In this era of Web 2.0, Web applications are absolutely mission critical to almost any organization. But these applications are giving IT managers...  

Southern Company
Download Now  

Share our Strength
Download Now  

The Commercialization of ITIL: Lessons Learned
Register for this event today!

Disaster Recovery & Cost Savings Zone
Thousands of customers world-wide have turned to virtualization solutions from Riverbed as a way to reduce costs.