Feeds

AT&T snuffs mobile Facebook security glitch

Um, that's not my profile

Choosing a cloud hosting partner with confidence

AT&T says it has resolved a network glitch that caused some mobile customers to log into Facebook accounts belonging to complete strangers.

"In a limited number of instances, a server software connectivity error resulted in some AT&T wireless customers being logged into the wrong Facebook account when they accessed Facebook through their mobile phones," an AT&T spokesman told El Reg via email. "This error impacted the subscriber identification information used to automatically log-on the Facebook user if a current cookie was not available.

Over the weekend, a story from The Associated Press reported that an Atlanta, Georgia-area mother and her two daughters all found themselves looking at strangers' Facebook profiles when they accessed the social website from their mobiles. One of the daughters landed in another person's profile on her first visit to Facebook on her phone.

The mobile operator confirmed that server issues were to blame for the security breaches "in a limited number of instances," but it didn't say how widespread the glitch was.

And here's where it get a bit weird: AT&T told the AP that one of the family members had actually experienced a separate error that similarly granted her full access to another person's Facebook account. AT&T said that its investigation pointed to a "misdirected cookie" in one of the phones — and that its technicians were unable to determine how it was routed to the phone.

The mobile operator told us that it has added new security measures to prevent the server error from happening again, adding that it collaborated with Facebook to disable subscriber identification information as an option for automatic log-in.

"For customers to access their Facebook account from AT&T wireless devices, Facebook now only will accept cookies placed by Facebook or full customer log-on information," AT&T said. "If the cookie isn't current, customers will be prompted to log in to their account. With these steps, we've addressed all known server issues and we continue to work with Facebook to monitor the situation."

AT&T went on to claim the wayward cookie issue was merely an "isolated" case that it has resolved with the customer. "It is unclear how this cookie was set on the phone." it said. ®

Website security in corporate America

More from The Register

next story
Bono: Apple will sort out monetising music where the labels failed
Remastered so hard it would be difficult or impossible to master it again
Oi, Tim Cook. Apple Watch. I DARE you to tell me, IN PERSON, that it's secure
State attorney demands Apple CEO bows the knee to him
Your chance to WIN the WORLD'S ONLY HANDHELD ZX SPECTRUM
Reg staff not allowed to enter, god dammit
Phones 4u website DIES as wounded mobe retailer struggles to stay above water
Founder blames 'ruthless network partners' for implosion
Monitors monitor's monitoring finds touch screens have 0.4% market share
Not four. Point four. Count yer booty again, Microsoft
Getting to the BOTTOM of the great office seating debate
Belay that toil, me hearty, and park your scurvy backside
Hey, Mac fanbois. HGST wants you drooling over its HUGE desktop RACK
What vast digital media repository could possibly need 64 TERABYTES?
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.