iPhone app iPad app Android phone app Android tablet app More

Facebook Flaw Exposes Your Chats, Lets Friends See Your Conversations (VIDEO)

Facebook Security Flaw

Huffington Post   First Posted: 07/05/10 06:12 AM ET Updated: 05/25/11 05:20 PM ET

UPDATE 5/5/2010 1:59AM ET: Facebook issued a statement to TechCrunch acknowledging the bug.

"For a limited period of time, a bug permitted some users’ chat messages and pending friend requests to be made visible to their friends by manipulating the “preview my profile” feature of Facebook privacy settings. When we received reports of the problem, our engineers promptly diagnosed it and temporarily disabled the chat function. We also pushed out a fix to take care of the visible friend requests which is now complete," the site said. Read the full statement on TechCrunch here.

--
UPDATE 5/5/2010 10:09AM ET: Facebook seems to be on top of the security hole. A notice on Facebook at approximately 10AM ET alerted users that chat was "down for maintenance."

--
Watch out! TechCrunch reports that a new Facebook security flaw can expose personal information by enabling your Facebook friends to see both your live chats, as well as your pending friend requests.

TechCrunch explains that the exploit is "enabled by they way that Facebook lets you preview your own privacy settings. In other words, a privacy feature contains a flaw that lets others view private information if they are aware of the exploit."

The video below offers a glimpse of the Facebook security flaw in action.

Some users have noted that Facebook chat is down. TechCrunch alerted Facebook to the exploit, and it's possible the social network may be down for maintenance. We'll keep you updated.

Facebook suffered another security glitch earlier this year that exposed users' private email addresses.

WATCH:

FOLLOW HUFFPOST TECH

UPDATE 5/5/2010 1:59AM ET: Facebook issued a statement to TechCrunch acknowledging the bug. "For a limited period of time, a bug permitted some users’ chat messages and pending friend requests to...
UPDATE 5/5/2010 1:59AM ET: Facebook issued a statement to TechCrunch acknowledging the bug. "For a limited period of time, a bug permitted some users’ chat messages and pending friend requests to...
 
 
  • Comments
  • 66
  • Pending Comments
  • 0
  • View FAQ
Comments are closed for this entry
View All
Favorites
Recency  | 
Popularity
Page: 1 2  Next ›  Last »  (2 total)
This user has chosen to opt out of the Badges program
09:13 AM on 05/06/2010
Who caught it? Did they get a badge?
photo
HUFFPOST SUPER USER
malcolmnext
08:47 AM on 05/06/2010
Beginning about 3-4 years ago, I began to notice what I percieved as a conscious effort by social networking sites, and Google in particular to link your activities online. The latest FB privacy issues don't surprise me. Really look at the way things are being done and there is a briskness, a target speed by which these things are happening. I'm not going to get all conspiracy theorist on you guys, but pay attention to the speed of these developments. It's being done in stages, which means there is a goal and a deadline. What those goals are and when that deadline is, I don't know. All I can say is that the internet , not only facebook, is obsessed with your privacy and WHO you are. Everything requires a " profile" and some kind of footprint. If I WERE a conspiracy theorist, I would say people have volunteered wayyyy too much personal information, and big brother is delighted. It would sure save them a ton of trouble with everyone just giving all their private info. Even the photo link or " tag" of friends would be great in this hypothesis. Not only do they know who you are, now you are doing their job and identifying everyone else, until they get a complete picture. Think about it.
This user has chosen to opt out of the Badges program
09:14 AM on 05/06/2010
yet you participate in this "badge" nonsense????
photo
HUFFPOST SUPER USER
malcolmnext
09:37 AM on 05/06/2010
LOL....Come on man...give me some credit. The badges are linked to a FB account that has Robert DeNiro in Taxi Driver as the profile. I am still a mystery......muahhh haha haha. Besides, this collection of information is so vast, not participating is purely for self-respect, in the end, everything about us can be known if anyone wants to know it bad enough. Sorry to say. Unless you smoke-screen your IP and bounce it off some poor schmuck in southeast asia, which I may or may not have done. wink
10:30 AM on 05/06/2010
Check this out. Include the phrase BP in your status, or even a post on Facebook, and it shows up on in a stream on the fb pages "BP organization" and "BP company"
Each page has two streams, one that shows all your friend's status updates and posts containing BP and the other shows "global" posts, or those of strangers. All following comments are also visible.
So, if you write "BP Clean Up that mess or you won't get your allowance" it appears on that page. Likewise, if you post "My mother-in-law puts my blood pressure through the roof. Seriously, my BP is 140/90" that will also appear.
On the downside, I haven't found a way to block it yet. On the plus side, you can say some funny (and potentially libelous) things about BP!
photo
HUFFPOST SUPER USER
malcolmnext
07:09 PM on 05/06/2010
That's crazy!! I told ya...this whole thing is meant to collect information in a big way. Those are triggers.! I'm starting to see it clearly now. I wonder if accepting applications or joining group pages are also meant to access your private info on FB. ? Dude..I'm going rogue.....i'm probably gonna pull the plug on my FB account. This just doesn't smell right...
photo
HUFFPOST SUPER USER
clsmithj
Wanna Raise Some Hell
08:54 AM on 05/07/2010
I checked this out and I must say you are quite the spammer.
photo
HUFFPOST COMMUNITY MODERATOR
KIVPossum
Moldova Marsupial
02:40 AM on 05/06/2010
Rule of thumb - Don't put anything on the internet you wouldn't want you mother to read aloud at the church social.
photo
HUFFPOST SUPER USER
mastacoupe
02:59 AM on 05/06/2010
What a boring life your thumbs advocate.
photo
HUFFPOST COMMUNITY MODERATOR
KIVPossum
Moldova Marsupial
03:19 AM on 05/06/2010
Or,

Mom's church socials are fun events
HUFFPOST SUPER USER
NoMoFearNoMoHate
08:07 AM on 05/06/2010
As long as someone gets the video of my mom reading that stuff and uploads it to YouTube... this is going to be LARGE!
HUFFPOST SUPER USER
Jim Pasterczyk
Banned!
02:31 AM on 05/06/2010
FB has been doing a lot of questionable changes to their terms of service and privacy policy lately. I'm starting to wonder if they really are just a data mining company.
02:46 AM on 05/06/2010
Hahaha!
03:22 AM on 05/06/2010
Of course it is. That's how they make their money, by selling your information to corporations.
02:07 AM on 05/06/2010
yeah sure it was a "bug"
01:33 AM on 05/06/2010
It seems that they really like sharing their users' information.... yet I can't even see who views my profile.
12:21 AM on 05/06/2010
What's Facebook???
photo
HUFFPOST SUPER USER
gcogs
"You can fly?" "No, jump good."
12:42 AM on 05/06/2010
haha I'm surprised you made it this far. Bravo!
This user has chosen to opt out of the Badges program
11:02 PM on 05/05/2010
Pro Tip:
If you want to make sure it's private, don't use teh internetz...
This user has chosen to opt out of the Badges program
photo
11:57 PM on 05/05/2010
And how would you suggest you talk to someone that's not in the room with you? Phones can be over heard. Smoke signals?
HUFFPOST SUPER USER
Brooke Steele
12:00 AM on 05/06/2010
mental telepathy?
This user has chosen to opt out of the Badges program
12:17 AM on 05/06/2010
life is a b*tch...and then you die...
11:00 PM on 05/05/2010
Nothing on the internet is private. Once people realize that, they can finally stop being shocked at things like this. And that includes your email.
photo
HUFFPOST SUPER USER
gcogs
"You can fly?" "No, jump good."
12:18 AM on 05/06/2010
Good call...agreed
This user has chosen to opt out of the Badges program
07:29 AM on 05/06/2010
Disagree, there is much that could be kept private generally speaking (outside of a planned hacking attack, which is no different then a planned burglary). However, certain platforms from IE to Facebook to Google Wave are inherently bad at privacy and should only be used by those who just plain don't care what happens to their information.
10:46 PM on 05/05/2010
I ran across a video on youtube the other day teaching people how to hack into someone's FB account. Facebook should investigate this problem
This user has chosen to opt out of the Badges program
10:25 PM on 05/05/2010
Hey, according to Facebook founder Marc Zuckerberg, privacy is dead.

So who cares if your private chats weren't so private?

Zuckerberg doesn't.

Still want to give him your traffic?
HUFFPOST SUPER USER
NoMoFearNoMoHate
08:10 AM on 05/06/2010
Yeah, there's always Rupert "Fox News" Murdoch's Myspace!
09:56 PM on 05/05/2010
Never liked Facebook. They're either too strict on privacy or too stupid with it.
photo
soundping
Candygram for Mongo..
10:36 PM on 05/05/2010
Same here.
09:16 PM on 05/05/2010
this is what you get when you let a bunch of college kids take unsupervised decisions.
HUFFPOST SUPER USER
Jim Pasterczyk
Banned!
02:28 AM on 05/06/2010
Sort of like the whole Dubya years.
09:08 PM on 05/05/2010
Is it true that if you deactivate your FB account it will be deleted in 2 weeks? I deactivated mine last month but I don't want to look because if it wasn't totally deleted it might reactivate just by checking in to see (using my former password). The hassle I went through (still) just trying to get off is enough to not want anything to do with it. You should be able to just click a DELETE ACCOUNT box if you so desire. That this is so elusive makes FB's agenda highly suspicious.
photo
laaambchop
Cheerfulness is a sign of wisdom
This user has chosen to opt out of the Badges program
photo
12:56 AM on 05/06/2010
Thanks. Good to know.
photo
HUFFPOST SUPER USER
2CLEVER
08:51 PM on 05/05/2010
baby i was hacked really hes justa friend