Snappy newsletters. Simple Facebook sharing. Spirited comments. Sweet features are waiting… GET THEM NOW!

Facebook's New Buy Had Huge Security Hole

Face.com app's flaw allowed Facebook, Twitter hijacking

By Rob Quinn,  Newser Staff

Posted Jun 20, 2012 10:14 AM CDT

(Newser) – Facebook has made a new acquisition, snapping up Israeli facial recognition firm Face.com in a deal believed to be worth up to $100 million. But while Face.com's technology—which is already used to auto-tag photos on Facebook—has plenty of fans, its KLIK mobile app had a major security flaw that has only just been fixed. The app stored Facebook and Twitter tokens insecurely, making it possible for anybody to hijack a user's accounts and gain access to their private photos and post updates as the user.

The security flaw was spotted by an independent security researcher, who made sure it had been fixed before making his findings public. The problems shows that "users should be aware," writes David Kravets at Wired. "Anytime you grant access to your Facebook, Google or Twitter accounts to an outside app, there’s always a hazard that your accounts could be at risk. Today might be a good day to go review which apps you have given permissions to, and which you no longer use."

A researcher found a major problem with Face.com, Facebook's latest acquisition.
A researcher found a major problem with Face.com, Facebook's latest acquisition.   (slatester)
« Prev« Prev | Next »Next » Slideshow

The attack not only allows access to non-public photos, but also lets the attacker potentially manipulate the Face.com app to automatically ‘recognize’ anyone walking down the street. - Independent researcher Ashkan Soltani

« Prev« Prev | Next »Next » Slideshow
My TakeCLICK BELOW TO VOTE
26%
18%
3%
3%
41%
9%
To report an error on this story, notify our editors.
COMMENTS
Be the first to comment on this story.
 

NEWS FROM OUR PARTNERS
Other Sites We Like:   24/7 Wall St.   |   BuzzFeed   |   Cracked   |   Timelines   |   POPSUGAR Tech   |   Business Insider   |   HuffPost Entertainment   |   NewsOne