By Guy Rosen, VP of Product Management
We wanted to provide an update on the security attack that we announced last week. This was a serious issue and we worked fast to protect the security of people’s accounts and investigate what happened. We fixed the vulnerability and we reset the access tokens for a total of 90 million accounts — 50 million that had access tokens stolen and 40 million that were subject to a “View As” look-up in the last year. Resetting the access tokens protected the security of people’s accounts and meant they had to log back in to Facebook or any of their apps that use Facebook Login.
We’ve had questions about what exactly this attack means for the apps using Facebook Login. We have now analyzed our logs for all third-party apps installed or logged in during the attack we discovered last week. That investigation has so far found no evidence that the attackers accessed any apps using Facebook Login.
Any developer using our official Facebook SDKs — and all those that have regularly checked the validity of their users’ access tokens – were automatically protected when we reset people’s access tokens. However, out of an abundance of caution, as some developers may not use our SDKs — or regularly check whether Facebook access tokens are valid — we’re building a tool to enable developers to manually identify the users of their apps who may have been affected, so that they can log them out.
Security is incredibly important to Facebook. It’s why we recommend developers stick to our Facebook Login security best practices:
- Use the Graph API to keep information updated regularly and always log users out of apps where error codes show that any Facebook session is invalid.
We’re sorry that this attack happened — and we’ll continue to update people as we find out more.
October 22, 2018
October 19, 2018
October 19, 2018
October 18, 2018
You must log in to post a comment.
This site uses Akismet to reduce spam. Learn how your comment data is processed.
Receive the latest tech news straight to your email inbox.
As a sponsor of Glamour’s 2017 Women of the Year Summit, we launched a new mentor program in partnership with The Girl Project—Glamour Magazine’s philanthropic initiative. The Girl Project aims to unleash the vast economic and social power of girls through education to ensure that girls everywhere have access to quality secondary education. This mentorship…
In any sport, athletes and amateurs alike are concerned about how their equipment might impact their performance. For gamers, the capabilities of their hardware are fundamental to their experiences. It can be particularly frustrating when the viewing field of the game is interrupted by the bezels of three monitors, or by the slow response of…