Original URL: http://www.theregister.co.uk/2011/04/13/facebook_fixes_hotmail_reset_bug/

Facebook fixes Hotmail reset bug

Mystery flaw is repaired

By John Leyden

Posted in Security, 13th April 2011 12:35 GMT

Facebook has plugged a password reset glitch involving users who linked their social network profiles to Hotmail webmail address.

The flaw, discovered by Turkish security researcher Serkan Gencel, also created a possible mechanism for cyber-criminals to lift Facebook passwords linked to Hotmail accounts. Gencel privately informed Facebook of the flaw prior to going public with his discovery, initially in the Turkish media (story here).

The mechanism of the vulnerability, even now, remains unclear. Gencel isn't spilling the beans and Facebook would only say that it had fixed the flaw following notification from a Turkish security researcher. ®