Facebook name extraction based on email/wrong password + POC
seclists.org
seclists.org
But this isn't any web app; it's the most popular complex web app in the world. It seems like there's zero likelihood Facebook doesn't (a) know about this and (b) want Facebook to work this way. Presumably, it helps people like my mom.
It was always a bad idea to associate your secret anonymous email address that you use to send ransom letters with your Facebook account.
https://graph.facebook.com/search?q=josh@eventvue.com&ty....
Heck, this is perfectly possible with LinkedIn and twitter as well. I don't understand what the fuss is.
However, since this solution isn't spectacularly scalable, I'm not too worried.
Now, I'm not saying they are using this vector, but then they must be using something like this because how else could they offer the service. (This also means there might be other vectors to achieve this end result).
To me, this also makes me pleased that I use a unique email address against my email domain for each site I use.
See the following including a link to see what is available via email address lookup.
http://jeffreykishner.com/2010/03/what-anyone-can-know-just-... http://petewarden.typepad.com/searchbrowser/2009/12/what-can... http://web.mailana.com/labs/findbyemail/
It could be put to malicious use by phishers. If I know your full name I can make more realistic phishing emails.
This seems like quite an asset to me, because spam mails with the real name will have a much higher engagement.
Maybe Google should worry about this too...I usually type unfamiliar email addresses into Google and end up with far more than just a name and a picture.
This coupled with the fbnames release earlier makes me think it's only a matter of time before someone crawls and "open sources" all accessible personal data from facebook.
This 'vulnerability' doesn't contact the victim, so it can be done in combination with, like the report said, a phishing scheme to gain the real names of the users of an email list.
I'm not saying that this is some massive privacy issue. It opens up a vector to make other attacks, specifically email based attacks, seem more legitimate, which is a bad thing.
Either way, my main point stands. This isn't a major privacy issue. Though, I've always been taught that when developing an authentication mechanism, one should not distinguish between a bad password or bad email address/user name in the error message provided to the user. Specifically the latter, since a "Invalid password supplied for John Doe" gives confirmation that the username provided is valid, and a bruteforce or dictionary attack on the name will probably successful.
The only thing you can discover is whether the email address you entered is a valid Facebook login or not - you get a different error response for an email address that's not a valid Facebook login.