Facebook Hack Revealed Any User’s Private Email Address

skeleton_hackerA Facebook bug bounty hunter recently discovered a serious security vulnerability that allowed him to view the private email address of every Facebook user.

The security researcher, Tommy DeVoss, discovered the bug on Thanksgiving Day and reported it to Facebook. After going back and forth with the site for several weeks, he was finally awarded $5,000 through the site’s Bug Bounty program.

The security flaw stemmed from the Facebook Groups tool that allowed admins to invite any Facebook member to take on an admin role. These admin invitations were sent to the recipients’ private email addresses, and DeVoss discovered that when he canceled pending invitations, he was taken to a page where he could view the full email addresses of the people he’d invited.

As DeVoss pointed out, this hole in Facebook’s security could’ve caused massive problems for the site.

“The hack allowed me to harvest as many email addresses as I wanted from anybody on Facebook. It didn’t matter how private you thought your email address was — I could have grabbed it,” DeVoss said. “Harvesting email addresses this way contradicts Facebook’s privacy policy and could lead to targeted phishing attempts or other malicious purposes.”

It’s heartening that so many security researchers do the right thing and report these hacks when they find them. However, some don’t, and that’s always the concern with giving Facebook so much of your personal information.


Recommended Resources

bitdefender trafficlightBitDefender Traffic Light is a free cross-browser add-on that intercepts, processes and filters all Web traffic, blocking any malicious content and taking browser security to new levels.

PIAPrivate Internet Access is an award-winning, cost-effective VPN solution. The use of an anonymous and trusted VPN is essential to your online privacy, security and identity protection.

System Mechanic 14 – Make your computer run like new. Winner of 200+ Editor’s Choice awards!

Facebook is Free and Always Will Be Previous post Facebook is Free and Always Will Be Facebook Is Buying Your Private Data From Third-Party Brokers Next post Facebook Is Buying Your Private Data From Third-Party Brokers