Researchers unveil new Facebook password vulnerabilities

December 05, 2011 16:13
Although Facebook engineers have been vigilant in their cybersecurity efforts, Brazilian researchers recently discovered a loophole that compromises the site's latest set of password protection features.

The overwhelming popularity of Facebook has made it a veritable magnet for online security threats. But although company engineers have been vigilant in their cybersecurity efforts, Brazilian researchers recently discovered a loophole that compromises Facebook's latest set of password protection features.

At a recent online security conference in Sao Paolo, industry expert Nelson Novaes Neto walked guests through his strategy for combining Amazon, LinkedIn and Facebook to compromise the online identity of a model target. According to SlashGear, Neto began by creating a cloned account of a colleague through online research and sent friend requests and invitations to her legitimate contacts.

Within one hour, 24 Facebook users and 14 LinkedIn contacts confirmed the requests. In fact, it only took seven hours to trick the colleague into accepting the friend request from her own cloned account. After the initial progress was made, Neto could have exploited Facebook's Three Trusted Friends App to acquire the legitimate account password from site administrators.

"People have simply ignored the threat posed by adding a profile without checking if this profile is true," Neto noted, according to Ars Technica. "Privacy is a matter of social responsibility."

Instead of relying solely on the third-party security assurance, experts have long recommended a more proactive approach from consumers. One such strategy is the use of password manager tools that generate and store strong passwords for each unique account.

Online Scams

March 07, 2012 As part of National Consumer Protection Week, the attorney general's office of the state of Ohio has issued a ...

December 29, 2011 The international cybercriminal ring known as Anonymous has once again caught the attention of the online ...

December 22, 2011 With online security breaches affecting organizations of all kinds, financial institutions are now on high ...

December 19, 2011 When musicians want to protect their recordings from digital piracy, they turn to online security specialist ...

December 09, 2011 Emerging research has suggested that cybercriminals are becoming increasingly interested in mobile platforms, ...

December 05, 2011 Although Facebook engineers have been vigilant in their cybersecurity efforts, Brazilian researchers recently ...

December 01, 2011 Danish online security firm CSIS has discovered a new strand of malware being spread across Facebook that ...