Feeds

AT&T snuffs mobile Facebook security glitch

Um, that's not my profile

Choosing a cloud hosting partner with confidence

AT&T says it has resolved a network glitch that caused some mobile customers to log into Facebook accounts belonging to complete strangers.

"In a limited number of instances, a server software connectivity error resulted in some AT&T wireless customers being logged into the wrong Facebook account when they accessed Facebook through their mobile phones," an AT&T spokesman told El Reg via email. "This error impacted the subscriber identification information used to automatically log-on the Facebook user if a current cookie was not available.

Over the weekend, a story from The Associated Press reported that an Atlanta, Georgia-area mother and her two daughters all found themselves looking at strangers' Facebook profiles when they accessed the social website from their mobiles. One of the daughters landed in another person's profile on her first visit to Facebook on her phone.

The mobile operator confirmed that server issues were to blame for the security breaches "in a limited number of instances," but it didn't say how widespread the glitch was.

And here's where it get a bit weird: AT&T told the AP that one of the family members had actually experienced a separate error that similarly granted her full access to another person's Facebook account. AT&T said that its investigation pointed to a "misdirected cookie" in one of the phones — and that its technicians were unable to determine how it was routed to the phone.

The mobile operator told us that it has added new security measures to prevent the server error from happening again, adding that it collaborated with Facebook to disable subscriber identification information as an option for automatic log-in.

"For customers to access their Facebook account from AT&T wireless devices, Facebook now only will accept cookies placed by Facebook or full customer log-on information," AT&T said. "If the cookie isn't current, customers will be prompted to log in to their account. With these steps, we've addressed all known server issues and we continue to work with Facebook to monitor the situation."

AT&T went on to claim the wayward cookie issue was merely an "isolated" case that it has resolved with the customer. "It is unclear how this cookie was set on the phone." it said. ®

Beginner's guide to SSL certificates

More from The Register

next story
Ex-US Navy fighter pilot MIT prof: Drones beat humans - I should know
'Missy' Cummings on UAVs, smartcars and dying from boredom
Don't wait for that big iPad, order a NEXUS 9 instead, industry little bird says
Google said to debut next big slab, Android L ahead of Apple event
Xperia Z3: Crikey, Sony – ANOTHER flagship phondleslab?
The Fourth Amendment... and it IS better
Netscape Navigator - the browser that started it all - turns 20
It was 20 years ago today, Marc Andreeesen taught the band to play
A drone of one's own: Reg buyers' guide for UAV fanciers
Hardware: Check. Software: Huh? Licence: Licence...?
The Apple launch AS IT HAPPENED: Totally SERIOUS coverage, not for haters
Fandroids, Windows Phone fringe-oids – you wouldn't understand
Apple SILENCES Bose, YANKS headphones from stores
The, er, Beats go on after noise-cancelling spat
Here's your chance to buy an ancient, working APPLE ONE
Warning: Likely to cost a lot even for a Mac
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.