. Military Space News .
CYBER WARS
Facebook says hackers accessed data of 29 mn users
By Glenn CHAPMAN
San Francisco (AFP) Oct 12, 2018

Facebook said Friday that hackers accessed personal data of 29 million users in a breach at the world's leading social network disclosed late last month.

The company had originally said up to 50 million accounts were affected in a cyberattack that exploited a trio of software flaws to steal "access tokens" that enable people to automatically log back onto the platform.

"We now know that fewer people were impacted than we originally thought," Facebook vice president of product management Guy Rosen said in a conference call updating the investigation.

The hackers -- whose identities are still a mystery -- accessed the names, phone numbers and email addresses of 15 million users, he said.

For another 14 million people, the attack was potentially more damaging.

Facebook said cyberattackers accessed that data plus additional information including gender, religion, hometown, birth date and places they had recently "checked in" to as visiting.

No data was accessed in the accounts of the remaining one million people whose "access tokens" were stolen, according to Rosen.

The attack did not affect Facebook-owned Messenger, Messenger Kids, Instagram, WhatsApp, Oculus, Workplace, Pages, payments, third-party apps or advertising or developer accounts, the company said.

- 'Vulnerability' in the code -

Facebook said engineers discovered a breach on September 25 and had it patched two days later.

That breach allegedly related to a "view as" feature -- described as a privacy tool to let users see how their profiles look to other people. That function has been disabled for the time being as a precaution.

Facebook reset the 50 million accounts believed to have been affected, meaning users would need to sign back in using passwords.

The breach was the latest privacy embarrassment for Facebook, which earlier this year acknowledged that tens of millions of users had their personal data hijacked by Cambridge Analytica, a political firm working for Donald Trump in 2016.

"We face constant attacks from people who want to take over accounts or steal information around the world," chief executive Mark Zuckerberg said on his own Facebook page when the breach was disclosed.

"While I'm glad we found this, fixed the vulnerability, and secured the accounts that may be at risk, the reality is we need to continue developing new tools to prevent this from happening in the first place."

Facebook said it took a precautionary step of resetting "access tokens" for another 40 million accounts which had accessed the "view as" function.

- 'Seed' accounts -

Hackers evidently started the cyber-onslaught on September 14 with 400,000 "seed accounts" they had a hand in or were otherwise close to, according to Rosen.

"The attackers started with a set of accounts they controlled directly, then moved to their friends, and their friend's friends, and so on -- each time taking advantage of the vulnerability," he added.

The exploit allowed hackers to steal copies of access tokens from accounts of "friends" by using the "view as" feature.

Once they had keys to accounts, hackers had the ability to get into them and control them as though they were the real owner.

Hackers could have seen the last four digits of credit card data in people's accounts, with the rest hidden for security, but there was no sign that data was taken, according to Facebook.

Rosen said they found no reason yet to believe hackers were in interested in people's information, rather that it appeared the mission was to harvest access tokens from friends associated with breached accounts.

He declined to discuss progress regarding figuring out who was behind the attack, saying Facebook had been asked by the FBI to remain quiet on the topic.

The California-based social network says it is cooperating with the FBI, US Federal Trade Commission, Irish Data Protection Commission and other authorities regarding the breach.

Rosen said the FBI investigation also limited what he could disclose about what the hackers' end-goal may have been, but maintained that Facebook had "no reason to believe this attack was related to the mid-term elections" in the US.


Related Links
Cyberwar - Internet Security News - Systems and Policy Issues


Thanks for being here;
We need your help. The SpaceDaily news network continues to grow but revenues have never been harder to maintain.

With the rise of Ad Blockers, and Facebook - our traditional revenue sources via quality network advertising continues to decline. And unlike so many other news sites, we don't have a paywall - with those annoying usernames and passwords.

Our news coverage takes time and effort to publish 365 days a year.

If you find our news sites informative and useful then please consider becoming a regular supporter or for now make a one off contribution.
SpaceDaily Contributor
$5 Billed Once


credit card or paypal
SpaceDaily Monthly Supporter
$5 Billed Monthly


paypal only


CYBER WARS
US arrests alleged Chinese spy after extradition from Belgium
Washington (AFP) Oct 10, 2018
US authorities said Wednesday they have arrested a Chinese intelligence agent after he was extradited from Belgium, accusing him of a state-sponsored effort to steal American trade secrets. The Justice Department said Xu Yanjun, an official of the Ministry of State Security, had plotted since 2013 to obtain trade secrets of GE Aviation and other companies. An indictment suggested he was lured to Belgium in a counterintelligence operation where he was arrested under a US warrant on April 1. T ... read more

Comment using your Disqus, Facebook, Google or Twitter login.



Share this article via these popular social media networks
del.icio.usdel.icio.us DiggDigg RedditReddit GoogleGoogle

CYBER WARS
Lockheed Martin selects payload providers for OPIR missile warning system

Raytheon receives contract for new AEGIS radars

Raytheon receives $1.5B contract for Patriot systems for Poland

Pentagon to pull some Patriots from Middle East: US official

CYBER WARS
Lockheed tapped for JASSM production for foreign military sales

Russia completed S-300 delivery to Syria: defence minister

Russia, India set to sign S-400 deal; Russia completed S-300 delivery to Syria

US, Chinese unease as Putin seeks India arms deals

CYBER WARS
Airbus, Boeing and Uber partner with Amsterdam Drone Week

Air Force designates GO1 hypersonic flight research vehicle as X-60A

General Atomics to provide technical services for Gray Eagle drones

Raytheon to deliver small drone decoys to the U.S. Navy

CYBER WARS
Multi-domain command and control is coming

Airbus tests 4G 5G stratospheric balloons for defence comms

Lockheed Martin embraces agile software development to evolve signals intelligence capabilities

Lockheed Martin Introduces Mission Planning System That Connects Systems and Assets Across Domains

CYBER WARS
Trump report bemoans Pentagon reliance on Chinese parts

DARPA Selects Teams to Explore Underground Domain in Subterranean Challenge

BAE to provide Paladin 155mm artillery systems for U.S. Army

Russia accuses US of running bio arms lab in Georgia

CYBER WARS
Germany open to selling arms to Saudis despite Yemen war

Indian defence chief rebuts Rafale allegations on France visit

Hugs as Putin clinches India defence deal

US Congress passes major spending bill, sending it to Trump

CYBER WARS
British NATO troops to show post-Brexit 'commitment'

Sri Lanka says no Chinese military base at port

Pence warns Central American leaders on China ties

Trump says China thinks US is 'stupid,' vows more pain

CYBER WARS
Big discoveries about tiny particles

Precise control of multimetallic one-nanometer cluster formation achieved

Two quantum dots are better than one: Using one dot to sense changes in another

Nucleation a boon to sustainable nanomanufacturing









The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us.