Facebook security hole allows viewing of private photos
forum.bodybuilding.com
forum.bodybuilding.com
In the future, if you find a security / privacy bug on Facebook, feel free to report it via our whitehat program, which will get things looked at more quickly than random blog posts. You can get credit for the find and even make money with bug-bounty payouts: http://www.facebook.com/whitehat/.
For what it's worth, a few people were alluding to this meaning that we don't check privacy by default. In fact we do have a pretty robust default-deny system for running privacy checks. This was an edge case where it was forced to work in a way that was incorrect.
(I work at Facebook, but not on this system.)
http://www.facebook.com/ajax/report/social.php?__a=1&__d=1&attach_additional_photos=1&cid=XX&content_type=0&h=YY&phase=6&report_id=1&rid=XX
Where XX and YY can be found by watching the net request made when clicking the initial Report/Block button.That said, I'm not sure if it is returning private photos, or just photos that are public - possibly you guys have fixed it on this side, not just the front end having links to it, but figured I'd mention it in case not.
One thing though: Your bounty of $500 is quite low. I bet this whole incident did/does a lot more damage than that. And to be honest, if I had the choice between $500 and trolling Mark Zuckerberg by posting his private photos album online, I would probably chose the latter option (sans the posting a howto on a forum part).
Disclaimer: I am not a security researcher, I don't even look for vulnerabilities. I just sometimes stumble upon bugs and get curious what other side-effects this bug might cause.
At least for me personally, it's not the posting of one person's private photos that is most frustrating - it's public posting of repro instructions so that script kiddies can exploit a bug. That just seems irresponsible.
Eg - up until today, and for who knows how long, photos you thought were private may have been accessed by undesireables.
I'm curious - do you think responsible disclosure is a bad idea? Or is the "badness" of this bug small enough (compared to malware) that you think it's better for the common good to publicly post the repro instructions and enable many users to exploit it?
I think having a bug bounty program is actually a lot better than the vast majority of sites / vendors that don't even have a whitehat disclosure program, let alone a bug bounty program. It's worth noting that this is just the base bounty - I've seen us pay out a lot more for good discoveries. $500 is also the base that Google and Mozilla offer for their programs (http://googleonlinesecurity.blogspot.com/2010/11/rewarding-w..., http://www.mozilla.org/security/bug-bounty.html). What would be a good price, do you think? I'm not hooked in enough to know what black market prices are like for bugs like this.
> I think having a bug bounty program is actually a lot better than the vast majority of sites / vendors that don't even have a whitehat [aka responsible] disclosure program, let alone a bug bounty program. It's worth noting that this is just the base bounty - I've seen us pay out a lot more for good discoveries. $500 is also the base that Google and Mozilla offer for their programs (http://googleonlinesecurity.blogspot.com/2010/11/rewarding-w..., http://www.mozilla.org/security/bug-bounty.html). What would be a good price, do you think? I'm not hooked in enough to know what black market prices are like for bugs like this.
We've improved a lot in the last couple years though - we launched the explicit whitehat program in 2010: http://www.insidefacebook.com/2010/12/22/facebook-security-t... and the bug bounty in July of this year: https://www.facebook.com/security/posts/238039389561434.
Feel free to respond here or let me know if you ever run into similar issues with the whitehat program (hopefully you'll change your mind about no longer reporting security problems!).
http://www.facebook.com/ajax/report/social.php?
__a=1&
__d=1&
attach_additional_photos=1&
cid=((FBID))&
content_type=0&
h=((HASH BASED ON YOUR ACCOUNT))&
phase=6&
report_id=1&
rid=((FBID))
After you get that initial hash then you can swap out the CID and the RID and get everyone else (I tried it for 3)... it's pretty easy.This issue is probably going to make mainstream news by noon.
I get this however,
for (;;);{"__ar":1,"error":1357006,"errorSummary":"Don't have Permission","errorDescription":"You don't have sufficient permissions to do that.","payload":null}
Anyone know if it's already patched?
http://imgur.com/a/PrLrB (ps: what a nice photo of them on halloween. very generous too I can see!)
Edit: it appears this same char is available in both URI formats I was referring to, so yes, full-size images are exposed.
[quote] right click inspect the image copy url in another window change the 'a' to 'n' (the last one right before jpg) =fullsize original image [/quote]
Secondly, Facebook is a site with hundreds of millions of users managing billions of private photos. With the amount of revenue & number of developers they have, it's inexcusable that they can't think through a simple process like this without considering what happens if two users aren't friends.
Granted, they're probably not "trying" to undermine privacy. But they're doing a very poor job at maintaining it.
If it wasn't on purpose, it was a mistake. Period.
It might be inexcusable, as you later pointed out, but it was still unintentional. Everyone likes to hate on Facebook. If this was a YC startup, I suspect people would be more forgiving.
I think the problem is that calling it a mistake downplays the issue. I'd say this is grave negligence, because besides the feature itself, it shows a lack of access control systems.
It was a mistake, but another word for a mistake is 'negligence'. The fact that something like this can happen illustrates systemic shortcomings at the company. Millions of people are depending on them to enforce the privacy restrictions Facebook claims to enforce. Facebook encourages you to store highly personal data, and as such, they have a responsibility to be more careful. Facebook prides themselves on constantly pushing changes to their software. More safeguards, testing, and perhaps slowing down the software development cycle a little would not be a bad idea.
No it isn't.
'a mistake' puts this at the same level of seriousness as other problems. This is at least a big mistake.
Evidence to the contrary: the Dropbox security fiasco (which sounded worse but was resolved in hours with claims of no malicious activity) prompted several HN entries. HNers aren't so biased as to be blind to inexcusable negligence (esp. because a large majority of us are users of those services and have personal stake.)
Facebook has a history of such "mistakes", a founder who thinks FB users are "dumb fucks" (and has reportedly maliciously used FB's password log), and all the motive in the world to be "negligent" as it's a way they can make money (as long as we don't find out).
The foolish thing to do is to assume this is still a mistake after repeated history of such "mistakes".
What one does this fall into?
At some point a developer coded in a resource that bypasses any privacy data, had it approved by management/coworkers (not sure what model they use) and published it live. I'm certain many people have been exploiting this longer than that forum post existed.
This comment seems to argue that this was intentional.
For a company of FBs size and personal data contents, I agree, they have a rather scary track record. But saying <symptom of X> implies <X> is fallacious, especially when it's also a symptom of <AAA> through <ZZZ>.
edit: imgur album was also created 4 hrs ago
I'm a little skeezed out at having looked at these photos at all, but "name that liquor" will apparently (in borderline cases like this) trump my principles.
Don't get me wrong, it's much nicer than a £20 bottle of blended stuff, but nowhere near good enough to justify the price tag, and is the huge majority of scotch drinkers (at least a huge majority of those who buy by taste not price) would rate a much cheaper single malt over it, yet alone an equal-costing bottle.
Don't get me wrong, when I get given a bottle I enjoy drinking it, but not as much as the bottles I spend £30-£80 on, yet alone the bottles I spend more on. So that's personal opinion, but it's shared by most people who have drunk and enjoyed a decent range.
Granted it's pompous but if you're going to spend the money a single malt is probably a good investment. Stop by a quality store and they'll be able to pick one out to fit your tastes.
I have never been able to appreciate blended as much as I appreciate pure malt, but my sample is really limited. My favorite so far is Glenlivet 18 years.
edit: pure->pure/single
So, good blended is more expensive than as-good single malt - indeed, it is also more expensive than great single malts. The only bottles I'll buy more than once are ones I personally consider great, and for me that's rarely less than £50 and never more than £500.
But, really, price isn't equatable to quality even within a category. You can't say that a £100 bottle will be twice as good as a £50 bottle, nor even that it will be better. The reason for spending more on a bottle is not that more expensive is better, just that, the wider your price range, the more options you have - and naturally, some of the more expensive bottles are better than some of the cheaper ones, and visa versa. If I couldn't afford it I could be perfectly happy with a lower top-end, and actually my second favourite bottle right now does cost around £50.
Two things to note: as with anything subjective, anyone can have a completely different opinion. Some people may genuinely love the JW Blue, enough to justify its cost. Most people who drink it don't, and they either haven't tried nicer whisky, or they are fooled by the price into deciding how good it is without paying attention to the drink itself, or (often) they don't really want to be whisky drinkers, and are doing it for the image not for the taste. But just because the majority are like that, doesn't mean there aren't people who, for their own tastes, are correct in loving it.
Also worth keeping in mind than JW Blue is notorious for being overpriced, don't think of it as representative of blended whisky. There are even nicer drinks in the JW range itself, and Blue is, at least by price, the top of their standard range. Green, for example, is considered by many to be nicer than Blue - not just better value, but nicer ignoring price. (I disagree on that, but at £30 it certainly is much, much better value.)
JW Blue is not whisky makers thinking "how can we make the best scotch", it is businessmen thinking "how can we market this", the drink itself is an afterthought.
edit: Personally I will always think single malts are much, much more attractive. But, blends can be good. JW, instead of trying to play with the blend to create an interesting and unique drink, tries hard to create a bland drink, with no interesting notes, a drink that will be acceptable rather than amazing to as many people as possible. It's not that they tried and failed, being smooth and boring is the purpose of the drink.
edit2: Am I just going on way too much about this?
Just a quick note though that if you're opening up the field to whiskey in general, the people who find Johnnie Walker especially drinkable are probably better served by moving to a more drinkable whiskey category in general. Bourbon is as forward as I get these days, and I strongly strongly prefer rye. Either option is bound to be much cheaper than Blue Label, and if you read up on (say) Bourbon and get a little spendy (but not Blue Label spendy), some of the bottles out there are revelatory.
(I say as I tuck into some Black Maple for an evening of Rails dev).
I used to have the scotch-snob assumption that it must, but I've had enough people whose opinions I value call me an idiot. I will at some point give a few a go, but just haven't got round to it yet.
I would agree with that. I prefer JW Gold to either, however.
(I'm pretty much done with scotch these days, though --- tastes like burnt trees --- so I'd defer to strong disagreement).
Does that mean it's the favorite whipping boy of people who like to think of themselves as connoisseurs?
449,543 like this
16,516 talking about this
That's a popular dog.Behold, "misc," the /b/ of bodybuilding.com: http://forum.bodybuilding.com/forumdisplay.php?f=19
As pud mentioned, they're basically /b/tards.
However, someone had to implement the backend for listing out those photos, and they clearly didn't think of access control, so there's at least something fishy here…
If there's a goof here, it's that the framework they've built apparently doesn't make the privacy controls mandatory. Developers have to remember to "turn them on" by calling an access control predicate or whatnot. That's bad. That's dumb. But it's not malicious.
Nice find.
I doubt law enforcement would see it that way. Downloading photos with this method is not much different than guessing somebody's email or voicemail password; you're accessing something you're not supposed to.
See 18 U.S.C. § 1030(a)(2)(C) and § 2701.
It is not enough for purposes of these laws to accidently or
unintentionally wander into areas on the internet where valuable
or secure information may reside. If one enters such an area
using computers or computer technology, his/her intent must be
to steal, destroy or defraud to be found guilty of a crime.
For example, David Kernell was convicted of "misdemeanor computer intrusion"[1] for accessing Sarah Palin's Yahoo! email.[1] http://www.esecurityplanet.com/headlines/article.php/3879756...
Or possibly didn't say:
http://en.wikipedia.org/wiki/Theres_a_sucker_born_every_minu...
I wonder whether this is limited to photos in the profile album, or whatever it is called, these days.
EDIT: I'll add this suggestion that I've made before, since you're going to have a LOT of people wanting to delete photos, if this problem proves to be significant. Delegate someone to spend a few hours writing a routine that will replace a cached photo with an identically sized, all white (or black, blue, whatever), no metadata generated image. So, you don't have to rebuild your image caches in order to ensure that a photo is really gone (well, except for the fact that it once existed, as demonstrated by the working URL and white image).
I've read the excuse made in the past that aggressive, large, integrated image caches made actual photo deletion "not an option". As long as you can overwrite existing bits in place, this should solve that. (Although I don't know about all the tagging you've now since overlaid onto the images.)
A few years ago, I believe, they explained that they generate these ginormous image caches where, IIRC, individual images are not distinct files.
My point is, regardless, if you can find the image (and its extent), and if the cache data are still write-able, then overlay a generated "blank" image onto the cached image, in place. You still have some data leakage, in that the working URL confirms that there was an image having that URL. But for most cases, I believe this would suffice.
I guess they'd also have to track down and overwrite the various thumbnail versions, but if their systems can already find these in the course of their normal work, this shouldn't be a problem.
As for overlaid tag data and whatnot, I'm not sure what to suggest. At a first pass, I'd suggest just deleting (or "offlining" or whatever, given that FB apparently never really deletes anything) that data. But I don't know what continuing dependencies that might break.)
EDIT: I should add that I don't know whether/how such image caches are replicated. And perpetuating such an overwrite against multiple replications might not be easy / something the existing design supports.
Nonetheless, I think it's something they should support. At a minimum, when a user really wants to delete an image, then overwrite its segment of whatever image cache file with a "blank" equivalent.
Although... then you get into what may be legally required and/or prudent, from FB's perspective, to retain.
I'll stick to the simplistic user perspective: When I say delete, I mean delete.
I deleted a couple of pictures this morning (nothing 'nekkid' ;-) and will have a look to confirm that they are indeed "gone" (inaccessible via direct URL -- albeit the URL of a CDN).
Would you happen to have the identity or URL of a specific guideline that you could point to?
EDIT: I just checked the URL of an image I deleted about an hour and a half ago, and that image is still accessible. It is under akamaihd.net; nonetheless, it is still accessible.
Thanks again for taking the time to reply.
Maybe they are rolling it out (lets say blocking it out) slowly now.
I think the reason it only works on some profiles it that perhaps the profile pictures are the only ones that it will show you. And some people only have one profile photo. (This is an untested theory / guess.)