Facebook Says Hackers Stole Detailed Personal Data from 14M People
bloomberg.com
bloomberg.com
Check if you are affected here: https://www.facebook.com/help/securitynotice
(posting because it took 10+ mins to find it - many media outlets are not linking directly to it)
Does deleting Facebook mean I no longer have a right to know if my data was breached while I was a member?
If you're in Europe you might have some some recourse (GDPR and such), but if you're from the US you are most likely out of luck.
Regardless, Facebook might have a detailed profile on you but not know your name. I doubt there is much you can do.
[1]: https://theconversation.com/shadow-profiles-facebook-knows-a...
People don't want to because they want their content to be "evergreen" and they think that if there's a date that's more than a year or so old, people will disregard / discount the content. So by default many blog CMSs default to not showing the date of any articles.
/grump
You can thank SEO for that. Something about older content being less "relevant"
They might intend to repeatedly update the second one, which might be a reason not to put a published date on it.
""" Is my Facebook account impacted by this security issue? Based on what we've learned so far, your Facebook account has not been impacted by this security incident. If we find more Facebook accounts were impacted, we will reset their access tokens and notify those accounts. """
I get the same message that I'm not likely impacted
IIRC that was on Facebook Lite on Android. I don't know my password so didn't log in at the time, but it just worked the next time I tried.
Might be unrelated.
Is my Facebook account impacted by this security issue?
Yes. Based on what we've learned so far in our investigation, attackers accessed the following Facebook account information:
Name.
Email addresses.
Phone number.
Based on what we've learned so far in our investigation, the attackers did not gain access to certain information, such as: Account passwords.
Payment card or credit card information.Additionally, the attackers also accessed other account information, including:
- The following information associated with your Facebook account:
- Username.
- Date of birth.
- Gender.
- Types of the devices you've used to access Facebook.
- The language you choose to use Facebook in.
- If you previously added this specific information to your Facebook account, it was also accessed:
- Relationship status.
- Religion.
- Hometown.
- Current city.
- Work.
- Education.
- Website.
- The 10 most recent locations you've checked in to or been tagged in. These locations are determined by the places named in the posts, such as a landmark or restaurant, not location data from a device.
- The 15 most recent searches you've entered into the Facebook search bar.
- People or Pages you follow on Facebook.The data you listed is semi-public in my case.
Like if I say "I'm calling from Samsung about your SMA500FU, phone number #####, ..." that gives me a lot of trust for a phish.
I wonder, say, how many phones I could get by mailing people an envelope saying their phone was at risk of exploding, sending corresponding texts, etc..
Is my Facebook account impacted by this security issue?
Yes. Based on what we've learned so far in our investigation, attackers accessed the following Facebook account information:
Name.
Email addresses.
Phone number.
Based on what we've learned so far in our investigation, the attackers did not gain access to certain information, such as: Account passwords.
Payment card or credit card information.Yet another reason they should email affected users, guess they care more about not publicizing bad information than taking responsibility.
As one of those people, this summer I encountered a spotify issue where my spotify would randomly start playing Cannabis Club ATL. Others had the same issue. Perhaps unrelated, too difficult to tell, especially if FB doesn't consider me an active user.
If they still store some user details (which it seems they do) and then this leaks - absolutely.
What about those who have never been users yet Facebook stores plenty of information about?
I understand in general that only "pure" facebook users were impacted and that "WhatsApp" users aren't?
(not sure how integrated WhatsApp is with the Facebook infrastructure - I do use WhatsApp but I don't have a Facebook account)
Is my Facebook account impacted by this security issue?
Yes. Based on what we've learned so far in our investigation, attackers accessed the following Facebook account information:
* Name.
* Primary email address.
* Most recently added phone number.
Additionally, the attackers also accessed other account information, including:
* The following information associated with your Facebook account:
* Username.
* Date of birth.
* Gender.
* Types of the devices you've used to access Facebook.
* The language you choose to use Facebook in.
* If you previously added this specific information to your Facebook account, it was also accessed:
* Relationship status.
* Religion.
* Hometown.
* Current city.
* Work.
* Education.
* Website.
* The 10 most recent locations you've checked in to or been tagged in. These locations are determined by the places named in the posts, such as a landmark or restaurant, not location data from a device.
* The 15 most recent searches you've entered into the Facebook search bar.
* People or Pages you follow on Facebook.
A small subset of Facebook accounts, including yours, had additional Facebook information made available to the attackers. Learn more about how this information was made available. This is specifically information that appears when viewing your own profile and includes additional information, such as:
* Posts from your timeline.
* Your Friends list.
* Messenger conversation names, but not their contents.
* If you are a Page admin, you may have also had messages to your Page made available to the attackers.
* Groups you're a member of.
Based on what we've learned so far in our investigation, the attackers did not gain access to certain information, such as:
* Account passwords.
* Payment card or credit card information.That seems to stand out to me as a bit of an outlier. Depending on the kind of page that an affected individual operates, that could be pretty big.
I can see how the attacker can use this to blackmail somebody.
The warning should be displayed during registration and then repeated monthly as a reminder.
I could start using fake answers but trying to remember the fake answers vs real answers is tough. Whereas when I get a custom question I have a custom answer that I will always remember. Such as made up on the spot Name of the babysitter with curly finger nails. I remember that and no one can figure it out based on the internet.
I use “batteryhorsestaple” type of passwords stored in a password manager for the security questions. Those are easy to say over the phone and more resistant to social engineering.
https://www.logmeininc.com/legal/privacy
it basically says they collect everything possible to collect and will use it for anything they want including sharing with 3rd parties
The vast majority of users aren't using random characters, so how would they know to say that to begin with? Are you implying they try that line, idk, 10,000 times until it (maybe) works?
Support: what is your fathers middle name?
Hacker: Michael
Support: sorry that is wrong
Hacker: oh shoot, I forget I always put the incorrect information in this one... i can't remember, did I put a fake name or random characters? Or was this the one I put a bunch of words into?
Support: yeah, it looks like random characters... let's move on
"Computers are hard, and I'm just not very good with them!"
attacker accesses recovery answers for site A. Sees that it is random characters. Attacker has access to site A.
Attacker phones sites B,C,D and E, trys social engineering. Attacker now has access to site B,C,D,E also.
"identity theft high risk 2fZMbjL1lLZgnS8La"
As an earlier comment pointed out [1], random responses to security questions are a bad idea. I've personally tested this by entering a random security answer, calling the service, saying I forgot my password and entered gibberish as my security answer, and being let through. I presume technically-savvy people think this is more secure; if I can guess that, an attacker can too.
In social engineering, it is common to call back multiple times looking for a gullible customer service rep. Even using a recording of a crying baby in the background to Garner sympathy is something I've seen done.
Big pain the few times I've had to read over the phone a giant randomized string, but the phone reps always seem to think it's funny.
You can read 'mettlograter' or 'donetrapalyn' over the phone as easily as you can type them, and they're much better than '/1a!P:l3', which has approximately the same complexity.
If there are no custom security question, I use my password manager to store them and put random answers not tied to myself personally.
If you create a different password for them. Because you rarely use those answer, you won't be able to remember them when they are actually needed. If you generate them with your password manager, then when you loss your password you loss them too. If you actually answer the questions with real information, you basically created a weak password.
All in all, security questions is a terrible idea.
“Am I blonde?”
“What’s my shoe size?”
“How old am I?”
“Do I have a dog?”
And of course, the answers to those are incredibly easy to guess / enumerate.
I read a comment on HN that they decided to use a random word like "banana" as the answer to a security question like "What's your mother's maiden name?" Within a couple of days, the bank called his house and spoke with a different relative to get the real answer.
Q: What's the name of your first pet?
A: pVp5TxN7htNC3B3Tae3RaPLndpLj5LeV
"[name], we have more information about the security incident we discovered on September 25, 2018. An unauthorized third party accessed your name, email address and phone number. We acted quickly to secure the site and took action to protect your account, and we're working closely with law enforcement to address the incident."
Ridiculous.
Here are the facts:
1. A software company had a security incident.
2. They urgently resolved the issue.
3. They looked into who was impacted, and sent customized notifications letting people know how they were impacted.
None of this behavior is ridiculous. It's quite responsible. What would you expect to happen differently?
This means the credentials from the original implementation of said feature weren't locked down to only data available from your viewable profile.
While my phone number may be available elsewhere outside of FB, I only have it tied to my account as a password reset contact.
Yeah, that's the entire security incident. So are you saying you expect software companies to never have security incidents? Now that's ridiculous.
Most companies, most developers, and most consumers would not be happy with the cost and speed this would result in.
In short: it's not that it's impossible. We know how to do it. It just comes with a cost attached that nobody wants to pay.
Perfect safety is a pipe dream.
Facebook has some of the best information security researchers, takes bug bounty seriously, and they have got very low hacks compared to the effort hackers put to hack it.
I'm not sure if the web interface uses those same access tokens, but the mobile app probably does. So they were probably able to access everything using unpublished API endpoints that the mobile app would normally use.
If that means different API tokens for different services, then maybe that's a better way to do it. I'm not Facebook, though.
I kind of work on the assumption that those things are largely public. I mean, phone books were a thing for a very long time. Don't get me wrong, leak bad, very bad, but they didn't leak my bank accounts or a list of my worst fears.
"For 14 million people, the attackers accessed the same two sets of information, as well as other details people had on their profiles. This included username, gender, locale/language, relationship status, religion, hometown, self-reported current city, birthdate, device types used to access Facebook, education, work, the last 10 places they checked into or were tagged in, website, people or Pages they follow, and the 15 most recent searches. "
The attackers accessed different info for different groups of people.
HN guidelines:
https://news.ycombinator.com/newsguidelines.html
>Please don't insinuate that someone hasn't read an article.
It’s a rule because of the effect it has on the conversation that follows, not because it is Just or Unjust. In that sense, HN is not like a court. As much as people, at times, seem to think it is :p
Too often an email address plus correct answers to questions like “what’s your mother’s birthplace?”, “what’s your fathers middle name?”, “what’s your favourite hockey team” are used to prove identity online, and these types of questions could be very answerable from this breach.
Even when being selective, there is no identity verification, so it is common for spammers or data collectors to simply make an account using the name and profile pic of any of your friends and requesting to be your friend.
There are many preferences in facebook that are like that - unavoidable/impassible fields that ask for info, and then you set it to "private/only yourself" to prevent information leakage, but are set default to world or friend visible.
It's a dark pattern that's all over facebook - you will see it if you install the facebook mobile apps - you can't proceed to surf your timeline without clicking through and answering questions sometimes - best thing is to fill in blank/gibberish info, but sometimes phone numbers, etc can't be avoided.
Otherwise it seems that big tech has limited risk and huge upside.
edit: 40acres put it more eloquently - Regulation is coming. If data is the new oil these are the oil spills that lead to the EPA.
In all earnestness, Facebook would have required password reset if it were needed.
More important is perhaps to warn less savvy people to be vigilant about phishing attempts.
This sort of victim blaming is all too common in the mainstream press:
IRS Says More Taxpayers May Have Been Hacked http://time.com/4000659/irs-taxpayer-hacked-cybercrime/
It wasn't the taxpayers that were hacked - it was the IRS.
Hackers stole personal information from 104,000 taxpayers, IRS says https://www.washingtonpost.com/news/federal-eye/wp/2015/05/2...
Hackers did not steal personal information from 104,000 taxpayers - they stole it from the IRS.
Smaller media outlets often get it right:
Over 700,000 People Got Screwed in Last Year's IRS Data Breach http://gizmodo.com/over-700-000-people-got-screwed-in-last-y...
And it’s a pain to ask them to delete the info. It’s obscure and time consuming and no guarantees. That in my mind is worse than anything here. I didn’t allow that info to be public, we need more privacy laws.
2. Your personal data is already collected meticulously by companies like Acxiom and Equifax for anyone who is ready to pay. You would be amazed how much information they have on you already. What are you going to do about it?
Both Cambridge Analytica and these hackers were able to launch a successful attack on a relatively small number of accounts and through Facebook's graph like network were able to leverage the initial attack to affect more people.
Social networks mirror real life networks; they can be attacked with virus like tendencies.
Regardless, I completely agree - that's almost surely where this is headed.
There's no real appetite for regulation of commercial data use in the US on either end of the political spectrum. And this is a good thing, because GDPR-style regulation would do nothing but further entrench the big players and crowd out innovation.
a) Paying out a $1m USD bug bounty, or
b) Accepting the reputational hit from a successful exploit
I wonder which they would choose with perfect hindsight?
Facebook runs a great bug bounty program, but given Facebook's size, data footprint, and profitability, perhaps it's worth increasing the rewards.
I would guess facebook gets a fair number of bug bounty reports of equal or greater severity than this one. Also in the past on HN when people argue that the payout of a bug bounty is too low, there have been comments saying web vulnerabilities are pretty much worthless on the black market.
https://news.ycombinator.com/item?id=9041017
>We have now determined that attackers used access tokens to gain unauthorized access to account information from approximately 30 million Facebook accounts.
Did I miss anything?
I know you're the Area Man Constantly Mentioning He Doesn't Own a TV[1], but...
Facebook probably has a profile on you containing personally identifiable information. If literally anyone who has ever had your phone number or email address also had a Facebook account, and gave Facebook access to their contacts, that's the ballgame. So maybe be a little less sanctimonious about telling others not to give away their data, because I'd bet all the money in my wallet Facebook has data on you.
[1] https://www.theonion.com/area-man-constantly-mentioning-he-d...
The same is true for many other social networks.
So while you're posting about being all smug and happy that you never signed up for one of these services, your personal data is still in their servers, ready to be exploited by both the company and hackers.
So what? That doesn't change a single thing. All you are doing with this line of thinking is blaming the victim. The fault here is Facebook's and the attacker's. No one else's.
1) https://news.ycombinator.com/item?id=18203002
This comment suggests that they discovered the vulnerability and spent two days working out how to fix it, whilst leaving the site live for exploitation.
2) Did they report the breach in a timely manner. That is not clear to me yet
3) Until a detailed analysis is done we don't know if there was anything negligent about this.
4) If in other investigations into Facebook it is found that Facebook were storing data they had no right to, and it transpired that they had lost some in this attack, they would be culpable because they shouldn't have had the data to lose.
So nothing specific, but lots of maybees
Even under the most harsh interpretations 3 days is the standard & that comes with all kinds of outs.
To the rest of your other points they largely are not at all covered by GDPR.
For instance I’ve never seen an interpretation of the GDPR that required a timeframe for remediation.
Further there is no requirement to allow a supervisory authority investigatory power after a breach.
In any case this appears to be a Facebook acting with extreme transparency. Exactly what the regulators want. It would be weird if this lead to negative ramifications.
Yesterday after news of stolen data emerges, I received a "Facebook password reset" email sent to my gmail address. I ignore all and filter as spam, but sometimes I see them. The email headers do show the source is facebook.
Seems like Facebook allows new account sign up from unverified email addresses. That's a flaw in their policy against spam and abuse, making these hacking events worse when they happen. They need to use activation codes in the email used to sign up with.
I am not willing to roll the dice on that assumption.
If you think about it, a breach of 30 million accounts out of 2 billion ain’t that bad.
That we know of. These sorts of leaks always seem to end up having a much wider impact than initially reported.
Well, they could just not collect as much data?
Both systems experience what on the Web we'd consider a staggering level of problems. Fraud losses just in the UK for the card payment system exceed £500M per year. They're proud of themselves for catching about 60% by value of potential fraud. That is, people _tried_ to steal over a billion pounds each year, but only get away with £500M...
They use out-dated cryptography, they straight up lie to their partners, to customers and even to the courts. I trust them about as much as some random Etsy maker.
Now, my country's laws mean when Visa screws up, my bank, regulated by those laws, has to make me whole. And I'm a middle-aged white guy, so good old-fashioned unconscious bias means when I'm screaming at a regulator about my rights they listen.
But if I didn't have those laws, if I was an elderly black lady, I can expect that I'd be told it's not the payment card company, I must have secretly travelled to Hong Kong last weekend and bought $5000 of men's watches and so I have to pay for that transaction even if I have witnesses who say I never left... after all the computer says it was my card and how could that be wrong?
Hackers stole personal information stored by FACEBOOK not 'people'.
It sounds like they are creating a new way for their company to avoid responsibility, just like banks created 'identity theft'.
I imagine such information will be very useful for fine-tuning phishing scams. E.g. something like “we saw you the other day at the Baton Rouge State Fair, and it’d be a shame if anyone saw what you did there. Send 0.5 BTC here so no one finds out.”
I consider that pretty scary, at least.
Yeah. It's all their fault.
Dumb fucks.
/s