Feeds

Facebook security glitch exposes user in-boxes

Cache glitch chaos forces users to work

Internet Security Threat Report 2014

Updated Office workers logging into Facebook on Tuesday morning were shocked to discover they were being served up other user's private pages.

Information going astray included other user's message inboxes. Fortunately more sensitive information - such as users' contact details - remained off limits to all but a member's friends.

The security glitch reared its head early on Tuesday, since when the site has been intermittently unavailable, at least in the UK. Access to the site from Spain, at least, has been fine since lunchtime.

The experience of Reg reader Wes seems typical.

"This morning I took part in my daily ritual of a cup of coffee and a quick look at my Face book account. However, when I logged in and click around, I was presented with other user's private pages, most notably other user's message inboxes. Further clicking around has exposed other areas of random people's accounts to me, but fortunately for them, so far all important information is still off limits," Wes reports.

Wes said the rest of his office are having similar difficulties accessing the service. Other Reg readers have written in reporting similar problems, some sending screen shots to illustrate their concerns.

In a statement, Facebook said the problem was due to a programming glitch - not the actions of external hackers - and has now been resolved, after the firm temporarily suspended services to apply an update. It apologised for any inconvenience.

"This morning, we temporarily took down the Facebook site to fix a bug we identified earlier today. This was not the result of a security breach. Specifically, the bug caused some third party proxy servers to cache otherwise inaccessible content. The result was that an isolated group of users could see some pages that were not intended for them. The site has now been restored, and we apologise for any inconvenience this may have caused," it said. ®

Bootnote

We can perhaps console ourselves with the observation that because Facebook was down for everyone for a short time on Tuesday - and unavailable for some for a much longer period - office workers were obliged to get on with their work, instead of posting photos and exchanging banter with their mates. Parts of the economy should be braced for unexpected end of month jump in productivity, perhaps.

Internet Security Threat Report 2014

More from The Register

next story
George Clooney, WikiLeaks' lawyer wife hand out burner phones to wedding guests
Day 4: 'News'-papers STILL rammed with Clooney nuptials
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
PEAK IPV4? Global IPv6 traffic is growing, DDoS dying, says Akamai
First time the cache network has seen drop in use of 32-bit-wide IP addresses
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
Stunned by Shellshock Bash bug? Patch all you can – or be punished
UK data watchdog rolls up its sleeves, polishes truncheon
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.