Facebook Was Breached
Were You Or A Facebook Friend Affected?
Facebook has confirmed that more than 50 million user accounts have been breached. TheyĀ made the announcement today, Friday, September 28th.Ā However, their engineering team discovered the security breach back on Tuesday, September 25th, 2018. They tell us that the vulnerability has been fixed and the breach was reported to the appropriate authorities.
How Did This Happen?
Hackers stole usersā access tokens through Facebookās āview as.ā This is a feature that lets you view what your profile looks like to other Facebook users. The flaw in this feature allowed hackers to take over 50 million user accounts.
If youāre like me, you may have received notices from some of your Facebook friends this week that someone took control of their accounts.Ā Perhaps they were affected by this breach.
What Are Access Tokens?
These are the digital keys that keep us logged in so we donāt need to re-enter our password every time we use Facebook. With this information, hackers can take over our account.
Hereās how Facebook explains what happened:
āAttackers exploited a vulnerability in Facebookās code that impacted āView As,ā a feature that lets people see what their own profile looks like to someone else. This allowed them to steal Facebook access tokens which they could then use to take over peopleās accounts.ā
What Now?
Facebook reset the tokens of all those affected. They also logged off 40 million additional users as a precaution. If you are one of these people, youāll need to log back in the next time you use Facebook.
According to Facebook, their investigators are in the early stages of their investigation. They are temporarily turning off the āView Asā feature while they conduct a thorough security review
What Should You Do?
If you have trouble logging back into Facebook, or you forgot your password, visit FacebookāsĀ Help Center.
If youāre like me, you take extra precautions when you hear about breaches like this.Ā If you want, you can visit the āSecurity and Loginā section in Facebook settings. It lists the places where youāre logged into Facebook with a one-click option. If you choose, you can log out of them all.