{"id":33299,"date":"2018-10-03T10:30:20","date_gmt":"2018-10-03T02:30:20","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=33299"},"modified":"2018-10-03T10:30:32","modified_gmt":"2018-10-03T02:30:32","slug":"no-evidence-attackers-accessed-any-apps-using-facebook-login-says-company-exec","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2018\/10\/03\/no-evidence-attackers-accessed-any-apps-using-facebook-login-says-company-exec\/","title":{"rendered":"No evidence attackers accessed any apps using Facebook Login, says exec"},"content":{"rendered":"<p>Facebook\u2019s investigation on the security attack it announced last week has so far found no evidence that the attackers accessed any apps using Facebook Login, according to the social media giant.<\/p>\n<p>In a post on Facebook last week, Mark Zuckerberg shared that \u201can attacker exploited a technical vulnerability to steal access tokens that would allow them to log into about 50 million people&#8217;s accounts on Facebook. We do not yet know whether these accounts were misused but we are continuing to look into this and will update when we learn more.\u201d<\/p>\n<p>In its latest security update issued on Oct. 2, <a href=\"https:\/\/www.facebook.com\/guyro\">Guy Rosen<\/a>,\u00a0VP of Product Management said that the vulnerability has been fixed and that they have reset the access tokens for a total of 90 million accounts \u2014 50 million that had access tokens stolen and 40 million that were subject to a \u201cView As\u201d look-up in the last year.<span class=\"Apple-converted-space\">\u00a0<\/span><\/p>\n<p>\u201cResetting the access tokens protected the security of people\u2019s accounts and meant they had to log back in to Facebook or any of their apps that use Facebook Login,\u201d noted Rosen. \u201cWe\u2019ve had questions about what exactly this attack means for the apps using Facebook Login. We have now analyzed our logs for all third-party apps installed or logged in during the attack we discovered last week. That investigation has so far found no evidence that the attackers accessed any apps using Facebook Login.\u201d<\/p>\n<p>Rosen further noted that any developer using the official Facebook SDKs \u2014 and all those that have regularly checked the validity of their users\u2019 access tokens \u2013 were automatically protected when people\u2019s access tokens were reset.<span class=\"Apple-converted-space\">\u00a0<\/span><\/p>\n<p>\u201cHowever, out of an abundance of caution, as some developers may not use our SDKs \u2014 or regularly check whether Facebook access tokens are valid \u2014 we\u2019re building a tool to enable developers to manually identify the users of their apps who may have been affected, so that they can log them out,\u201d said Rosen.<\/p>\n<p>Facebook recommends developers stick to the Facebook Login <a href=\"https:\/\/developers.facebook.com\/docs\/facebook-login\/security\/\">security best practices<\/a>:<\/p>\n<ul>\n<li>Use our official Facebook SDKs for Android, iOS and JavaScript \u2014 these will automatically check the validity of access tokens on a daily basis and force a fresh login when they are reset by Facebook, protecting the security of users accounts.<\/li>\n<li>Use the Graph API to keep information updated regularly and always log <a href=\"https:\/\/developers.facebook.com\/docs\/facebook-login\/access-tokens\/debugging-and-error-handling#errors\">users out of apps where error codes show that any Facebook session is invalid<\/a>.<\/li>\n<\/ul>\n<p>\u201cWe\u2019re sorry that this attack happened \u2014 and we\u2019ll continue to update people as we find out more,\u201d said Rosen.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Facebook\u2019s investigation on the security attack it announced last week has so far found no evidence that the attackers accessed any apps using Facebook Login, according to the social media giant. In a post on Facebook last week, Mark Zuckerberg shared that \u201can attacker exploited a technical vulnerability to steal access tokens that would allow [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":33300,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[495,441,6151,286,508],"class_list":["post-33299","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-cybersecurity-and-cybercrime","tag-facebook","tag-high-tech","tag-it-security","tag-social-media"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/33299","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=33299"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/33299\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/33300"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=33299"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=33299"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=33299"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}