Security Researchers Expose Facebook Flaws

Security researcher Nitesh Dhanjani told CNET Facebook is vulnerable to attacks that allow hackers to hijack accounts while users of the social-networking site are interacting with other Websites, adding that a Facebook design flaw is enabling third-party apps to access user profile data without their permission.

Facebook spokesman Simon Axten responded to CNET:

The only information apps can access without first showing the “Allow” screen is publicly available information (the limited set of info that includes name, profile picture, gender, networks, friend list and pages) and information set to be visible to everyone on the Internet.

Dhanjani

AW+

WORK SMARTER - LEARN, GROW AND BE INSPIRED.

Subscribe today!

To Read the Full Story Become an Adweek+ Subscriber

View Subscription Options

Already a member? Sign in