Feeds

AT&T snuffs mobile Facebook security glitch

Um, that's not my profile

Secure remote control for conventional and virtual desktops

AT&T says it has resolved a network glitch that caused some mobile customers to log into Facebook accounts belonging to complete strangers.

"In a limited number of instances, a server software connectivity error resulted in some AT&T wireless customers being logged into the wrong Facebook account when they accessed Facebook through their mobile phones," an AT&T spokesman told El Reg via email. "This error impacted the subscriber identification information used to automatically log-on the Facebook user if a current cookie was not available.

Over the weekend, a story from The Associated Press reported that an Atlanta, Georgia-area mother and her two daughters all found themselves looking at strangers' Facebook profiles when they accessed the social website from their mobiles. One of the daughters landed in another person's profile on her first visit to Facebook on her phone.

The mobile operator confirmed that server issues were to blame for the security breaches "in a limited number of instances," but it didn't say how widespread the glitch was.

And here's where it get a bit weird: AT&T told the AP that one of the family members had actually experienced a separate error that similarly granted her full access to another person's Facebook account. AT&T said that its investigation pointed to a "misdirected cookie" in one of the phones — and that its technicians were unable to determine how it was routed to the phone.

The mobile operator told us that it has added new security measures to prevent the server error from happening again, adding that it collaborated with Facebook to disable subscriber identification information as an option for automatic log-in.

"For customers to access their Facebook account from AT&T wireless devices, Facebook now only will accept cookies placed by Facebook or full customer log-on information," AT&T said. "If the cookie isn't current, customers will be prompted to log in to their account. With these steps, we've addressed all known server issues and we continue to work with Facebook to monitor the situation."

AT&T went on to claim the wayward cookie issue was merely an "isolated" case that it has resolved with the customer. "It is unclear how this cookie was set on the phone." it said. ®

The essential guide to IT transformation

More from The Register

next story
Apple's iWatch? They cannae do it ... they don't have the POWER
Analyst predicts fanbois will have to wait until next year
Barnes & Noble: Swallow a Samsung Nook tablet, please ... pretty please
Novelslab finally on sale with ($199 - $20) price tag
Apple to build WORLD'S BIGGEST iStore in Dubai
It's not the size of your shiny-shiny...
Just in case? Unverified 'supersize me' iPhone 6 pics in sneak leak peek
Is bigger necessarily better for the fruity firm's flagship phone?
Steve Jobs had BETTER BALLS than Atari, says Apple mouse designer
Xerox? Pff, not even in the same league as His Jobsiness
Apple analyst: fruity firm set to shift 75 million iPhones
We'll have some of whatever he's having please
TV transport tech, part 1: From server to sofa at the touch of a button
You won't believe how much goes into today's telly tech
The agony and ecstasy of SteamOS: WHERE ARE MY GAMES?
And yes it does need a fat HDD (or SSD, it's cool with either)
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
7 Elements of Radically Simple OS Migration
Avoid the typical headaches of OS migration during your next project by learning about 7 elements of radically simple OS migration.
BYOD's dark side: Data protection
An endpoint data protection solution that adds value to the user and the organization so it can protect itself from data loss as well as leverage corporate data.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?