Select your language

Errors on Facebook that endanger users' privacy

This series of vulnerabilities or errors have a particularity: the company founded and led by Mark Zuckerberg considers and affirms that they are important functionalities within its environment and, therefore, cannot be eliminated.

This series of vulnerabilities or errors in the popular social network have a particularity: Facebook considers that they are important functionalities within its environment and, therefore, cannot be eliminated.

Initially, on July 18, a Spanish researcher discovered a vulnerability that allows an open redirection from the mobile platform of the social network (m.facebook.com).

This is that, by carrying out a simple procedure, it is possible to trick the user into thinking that he is entering Facebook when, in reality, he may be entering another site. Criminals could use this method to commit fraud and scams on the Internet.

Facebook admitted to this anomalous behavior but said "it lies in a functionality they need and therefore prefer to take the risk."

- Publicidad -

As a result of this discovery, another Chilean researcher published the way in which it is possible to obtain in an automated way (making thousands of queries simultaneously and without control) if a user is registered in the social network, simply knowing their email or telephone number.

Again, the company expressed that "this ability to locate friends through mail is part of the core of Facebook and while it may be a vulnerability in a financial site, here it corresponds to a functionality of the network."

Paradoxically, coinciding with these findings, Facebook launched the "Bug Bounty" program whose objective is to pay $ 500 to those who discover critical vulnerabilities in the platform, similar to what Google has done since 2010.

Cristian Borghello, stressed to iProfesional.com: "Needless to say, neither of the two previous discoveries was rewarded, because they have not even been recognized as failures."

Also at the end of July, in Spanish-speaking countries began to circulate a message informing that the Facebook application for all smartphones shares (still does) the personal agenda of the user, by default and without informing him: "Attention, for reasons that are unknown, all smartphones share the information of the personal agenda of one with the company Facebook, see for yourselves."

Indeed, when you install the app, Facebook automatically stores (does not share, as incorrectly reported) contact information, profile pictures and calendar in order to connect its users at some point. In this regard, Facebook on its website informs:

Errores en Facebook que ponen en peligro la privacidad de los usuarios"Activating this feature will periodically send copies of your BlackBerry device contacts to Facebook Inc. to link and connect with your Facebook friends. Profile pictures and information about you and your friends on the social network will also be periodically sent from your Facebook to your BlackBerry contact list and calendar. You agree that access to this data (e.g. via apps) will no longer be subject to your privacy settings and that of your Facebook friends once it is stored on your BlackBerry device."

Facebook, through its fan page, has denied the "rumors" that this information is shared publicly and has said that "the possibility of seeing the agenda has been around for a long time and has been designed to show a single list of contacts instead of having to visit each profile".

- Publicidad -

For Borghello, "this statement is true, since the information is not shared openly for everyone, but it has long been taken from the phone and stored on the Facebook platform, without properly communicating it to the user."

The computer specialist pointed out that the contents already shared "can be deleted and this 'functionality' can be disabled, but whoever does not pay attention to this fact, when installing the application will be openly sharing all the information and, what is even worse, will also be providing it to the social network, without the corresponding permission of its owners".

To correct this you must enter the social network through the smartphoneand there is an option that must be disabled. The access address is: https://www.facebook.com/friends/edit/?sk=phonebook

For Borghello, "the reason for considering as vulnerability to a supposed functionality lies in the point from where such anomalous behavior is observed":

Facebook sees it from the additional advantages that the user acquires when using this functionality or from the benefits obtained by the social network, without forgetting its economic reasons and that its creator has declared that "he does not believe in privacy or intimacy".

"The people who develop our activity in security see it from the point of view of user privacy and how it is overwhelmed, simply to obtain a questionable advantage and that, anyway, could be generated in another more reliable way," said the specialist.

- Publicidad -

"Regardless of whether the aforementioned findings should be considered functionalities or vulnerabilities, the most important thing to note is that, according to the company, these behaviors, and surely many others, obey the growth of the social network, which is obviously above the privacy of the user, who is the one who ultimately ends up paying for their access, believing that it is free." Borghello concluded.

Source: iProfesional and ZMA

See original.

No comments

• If you're already registered, please log in first. Your email will not be published.

Comments are closed

The comments for this content are closed.

Security becomes a technological platform

Security becomes a technological platform

Mexico. Security is moving from a set of standalone systems to an integrated technology platform that combines artificial intelligence, video analytics, sensors, access control, and data platforms....

Security industry in Mexico and Latin America continues its expansion and professionalization

Security industry in Mexico and Latin America continues its expansion and professionalization

International. The security industry in Mexico and Latin America maintains a growth trend driven by digital transformation, the increase in physical and cyber risks, as well as the need to protect...

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

United States. Veeam Software today announced the launch of Agent Commander, a solution aimed at helping organizations detect risks associated with artificial intelligence, protect AI-based systems...

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

In industries where every minute counts, efficient asset and resource management has become a strategic factor to ensure operational continuity, safety, and productivity. By: Héctor Meléndez,...

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Puerto Rico. A centralized monitoring operation developed by Genesis Security was able to significantly reduce the volume of false alarms in its security systems, thanks to the integration of...

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Türkiye. An open-ocean fish farming farm in Turkey implemented a smart surveillance system based on Dahua solar cameras, thermal monitoring, and wireless data transmission to improve safety and...

 The Hidden Security Gap in Data Centers

The Hidden Security Gap in Data Centers

Imagine the journey of an authorized technician inside a data center. When he arrives, he presents his credential and enters the premises, and before entering the server corridor he needs a key to...

Digital fraud increased at Christmas

Digital fraud increased at Christmas

Colombia. During the holiday season, as e-commerce and digital transactions intensified, online fraud attempts also increased. Fake promotions, impersonation of businesses and messages that...

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Mexico. Milestone Systems, a leading provider of open platform video management software (VMS), hosted the Milestone XPerience Days Mexico 2025 event, a gathering that brought together industry...

Hikvision Mexico launches the third edition of

Hikvision Mexico launches the third edition of "Hikvision Women"

Mexico. Hikvision Mexico announced the launch of the third edition of its "Hikvision Women" program, an initiative aimed at strengthening the participation and professional development of women in...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter