IDG News Service - A bug allowed Facebook users to view their friends' chat sessions on the site, prompting the social-networking company to disable its internal instant-messaging service. The bug also let people see their friends' pending friend requests.
To exploit the now-patched hole, people had to manipulate "in a specific way" the site's feature that lets members preview how their profile looks to each of their friends, Facebook said Wednesday on its official corporate page on the site.
The vulnerability existed "for a limited amount of time," the company said. The chat function is now working again.
Technology news site TechCrunch first reported the bug and posted a video that demonstrates how the bug could be exploited.
"When we received reports of the problem, our engineers promptly diagnosed it and temporarily disabled the chat function," a Facebook spokeswoman said via e-mail.
"We worked quickly to resolve this matter, ensuring that once the bug was reported to us, a solution was quickly found and implemented," she added.
When asked how long the vulnerability existed, she replied: "We don't have specifics on how long the vulnerability existed, but it was for a short period of time."
John Simpson, an official with Consumer Watchdog, was displeased with the incident. "Once again we see what happens when companies push the technological envelope with little concern for consumers' privacy rights," he said via e-mail.
The bug reinforces the Electronic Frontier Foundation's blanket recommendation for users on Facebook, said Peter Eckersley, an EFF senior staff technologist.
"What you don't want the world to know about, don't put it on Facebook," he said in a phone interview.
"Facebook's security engineering is improving, but it's still not good enough that we'd ever advise people to put private, sensitive information there," Eckersley said.
The bug comes at a time when privacy concerns regarding Facebook have heated up, after the company recently introduced features that allow third-party Web sites to tap into users' profile data to personalize their experience for them.
Two weeks ago, Facebook announced it had revamped its application development platform so that its site and external sites can mesh their users' "social graphs" to individually customize their interaction with them.
"People can have instantly social and personalized experiences everywhere they go," said Mark Zuckerberg, Facebook's CEO.
Key to this vision is Facebook's Open Graph API (application programming interface) and Open Graph Protocol, a system to mark up objects in a uniform way so that Facebook and participating sites can understand them the same way.
Facebook also released plug-ins for developers to easily incorporate on their Web pages Facebook functionality, such as the already widespread "Like" button, which lets end-users express interest in content and inform participating Web sites.
- Best iPhone, iPad Business Apps for 2014
- 14 Tech Conventions You Should Attend in 2014
- 10 Desktop Apps to Power Your Windows PC
- How to Add New Job Skills Without Going Back to School
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- The 12 PCI DSS 3.0 requirements addressed by Peer 1 Hosting This handy quick reference outlines the 12 PCI DSS 3.0 requirements, who needs to be compliant and how Alert Logic solutions address the...
- Defense Throughout the Vulnerability Life Cycle This whitepaper provides insight into how to leverage threat and log management technologies to protect your IT assets throughout their vulnerability life cycle.
- Mobile Policy Checklist Here's what to consider when putting together a mobile policy designed to support a highly productive workforce.
- Securing BYOD Mobile computing is becoming so ubiquitous that people no longer bat an eye seeing someone working two devices simultaneously. Individuals and organizations are...
- Live Webcast On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy...
- Live Webcast Endpoint Backup & Restore: Protect Everyone, Everywhere Arek Sokol from the bleeding-edge IT team at Genentech/Roche explains how he leverages cross-platform enterprise endpoint backup in the public cloud as part...
- Streamline Software Asset Management, Compose a software Management Symphony Keeping track of your organization's software is easy with effective software management solutions from CDW. View the videos in our software solutions channel
- Druva inSync: Endpoint Data Protection & Governance CLICK HERE to watch this video about protecting corporate data on laptops and mobile devices, sponsored by Druva. All Security White Papers | Webcasts