Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - Gettin' Geeky with it.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews



IObit Black Friday Sale

spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. MusicBee
5. Sergei Strelec's WinPE
6. Microsoft Visual C++ 2015-2022 Redistributable Package
7. Visual C++ Redistributable Runtimes AIO Repack
8. McAfee Removal Tool (MCPR)
9. K-Lite Mega Codec Pack
10. Visual C++ Runtime Installer (All-In-One)
More >>

top reads

Star AI Answers: Authority Without Accountability

Star All the New Features Landing in Windows 11 This December

Star Lossless vs Lossy: When FLAC, APE, and ALAC Beat MP3 and When They Don't

Star Google Search Tricks You'll Actually Use in 2025 and Beyond

Star Fresh PC Checklist: First 12 Things to Do On a New Windows 11 Machine

Star Running AI Models Locally: What They Are, Where to Find Them, and How to Get Started

Star Deciding Between Idle State, Sleep Mode, and Shutdown: What's Best for Your PC?

Star How to Fix VMware Workstation "The Update Server Could Not Be Resolved" Error Installing VMware Tools

Star How to Remove Google Gemini from Your Phone (and Your Life)

Star Windows Bloat Removal Guide: Debloat Safely and Keep What You Need


MajorGeeks.Com » News » November 2012 » Speculation over Facebook access via Google index

Speculation over Facebook access via Google index


Contributed by: Email on 11/02/2012 02:59 PM [ comments Comments ]


According to a report on HackerNews, until recently a special Google search query returned numerous Facebook links permitting access to other users' accounts. The links contain a token which automatically logs into someone else's Facebook account. The search results are also reported to have contained links providing access to other users' email addresses.

The links appear to have come from notification emails sent out by Facebook in response to events such as being tagged by another user in a photo. The emails contain a direct link to the relevant event on Facebook. To make it easier for users to log in, Facebook includes the user's email address in the link URL.

This is then entered into the relevant field on the login page automatically and users need only enter their password – and even this can be omitted if they are already logged in. In some cases Facebook also uses links containing tokens which log users in without requiring a password. This is not a security problem in itself, since Facebook sends these emails directly to the account owner.

The problem arises when these links, as here, fall into the wrong hands. At the moment, it remains unclear how they came to be indexed by Google. Facebook employee Matt Jones hypothesizes on HackerNews that the notification emails may have been made publicly available for reasons such as the use of a throwaway email site, access to which does not require a password.

According to one comment on HackerNews, many of the email addresses are in fact from the domain asdasd.ru, a Russian provider of throwaway email addresses. Indeed the site's main page consists of a global inbox, listing all emails received for all users. Users who have registered their Facebook account using a service of this type should not be surprised if others access their accounts.

According to Jones, Facebook has now deactivated token-based logins. Google also appears to have taken action, with the links in question having largely vanished from its search results.






« Surprise Amazon Announcement: “Early Black Friday” · Speculation over Facebook access via Google index · Vupen brags about Windows 8 hack »




Comments
comments powered by Disqus

MajorGeeks.Com » News » November 2012 » Speculation over Facebook access via Google index

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition