Download the
Tom's Guide App from the AppsStore
News and trends on internet
/ mobile / "sound & picture" / IT
Yes No

Facebook Security Hole Shows Your Friends' Chats

- By - Source : Tom's Guide US

Facebook has patched a security hole that inadvertently allowed users to see what their friends were instant messaging to other people.

One of Facebook's privacy tools gives you the ability to see how your profile looks to other people. You can use it to make sure all of your settings are set to 'friends only' or check that certain people can't see certain aspects of your profile. It's a useful tool if you're always trying to block your boss or family from seeing incriminating vacation pictures, or stop them from seeing wall posts. However, a glaring problem with this neat little tool became apparent on Wednesday: in showing you your profile through your boss' eyes, Facebook also showed you your boss' IM conversation if he or she happened to be online and chatting with someone else on Facebook. You could also see any pending friend requests.

TechCrunch made a video demonstrating how the bug worked:

Facebook Privacy Settings Exploit

Facebook then sent the site the following statement:

“For a limited period of time, a bug permitted some users’ chat messages and pending friend requests to be made visible to their friends by manipulating the “preview my profile” feature of Facebook privacy settings. When we received reports of the problem, our engineers promptly diagnosed it and temporarily disabled the chat function. We also pushed out a fix to take care of the visible friend requests which is now complete. Chat will be turned back on across the site shortly. We worked quickly to resolve this matter, ensuring that once the bug was reported to us, a solution was quickly found and implemented.”

Did any of you see this bug in action? Let us know in the comments below!

Share:
31
Comments
X

Comments

xbeater 05/06/2010 9:49 PM
Hide
-20+

I seriously need to get off Facebook... who agrees?

mlopinto2k1 05/06/2010 9:50 PM
Hide
-2+

Damnit!!!! WHY DIDN'T I KNOW ABOUT THIS BEFORE I DELETED MY ACCOUNT!!!

kyeana 05/06/2010 9:58 PM
Hide
-4+

mlopinto2k1 :
Damnit!!!! WHY DIDN'T I KNOW ABOUT THIS BEFORE I DELETED MY ACCOUNT!!!



What does that have to do with anything?

dman3k 05/06/2010 10:00 PM
Hide
-8+

xbeater :
I seriously need to get off Facebook... who agrees?

me too

Bolbi 05/06/2010 10:03 PM
Hide
-16+

I never saw this bug. It's simple, really: I don't use Facebook! :)

babybeluga 05/06/2010 10:05 PM
Hide
-8+

Oh no, my super hot cyber sexing is public =/

babybeluga 05/06/2010 10:14 PM
Hide
-7+

babybeluga :
Oh no, my super hot cyber sexing is public =/



"sup lady, I'll fill your security hole"

That's how it usually goes =D

counselmancl 05/06/2010 10:23 PM
Hide
-11+

Using facebook is a security breach.

micr0be 05/06/2010 10:51 PM
Show
JMcEntegart 05/06/2010 10:55 PM
Hide
-12+

micr0be :
but seriously if you use facebook then you truly have... 0 friends.



I understand that you either hate facebook or just don't see the point in social networking but that statement is completely false.

ksampanna 05/06/2010 11:17 PM
Hide
-4+

I did see the bug in action. Thanks to that, my bro's girlfriend is no longer a secret.

daworstplaya 05/06/2010 11:27 PM
Hide
-6+

micr0be :
OH NOZ HE ACCEPTED Kip Drory, thats int3rnets suicideZ !!!but seriously if you use facebook then you truly have... 0 friends.



LOL! Too bad most folks giving you the "Thumbs down" don't realize it's from South Park.

JMcEntegart :
I understand that you either hate facebook or just don't see the point in social networking but that statement is completely false.



Obviously you don't watch SouthPark. That statement is from one of the episodes and utterly hilarious. Facebook has its uses but for the most part is a waste of time.

JMcEntegart 05/06/2010 11:30 PM
Hide
-2+

daworstplaya :
LOL! Too bad most folks giving you the "Thumbs down" don't realize it's from South Park.Obviously you don't watch SouthPark. That statement is from one of the episodes and utterly hilarious. Facebook has its uses but for the most part is a waste of time.



I do watch Southpark and I know the episode he's referring to but I'm not sure if that second statement was a reference to it (no quotations to indicate whether it was or not). Feel free to correct me if I'm wrong; I didn't commit much of the episode to memory other than "Kip Drory = Bad friend stock."

babybeluga 05/06/2010 11:42 PM
Show
JMcEntegart 05/06/2010 11:46 PM
Hide
-7+

babybeluga :
People who watch Southpark have 0 friends.



Also not true! We're all just equally immature. :)

daworstplaya 05/07/2010 12:01 PM
Hide
-0+

JMcEntegart :
I do watch Southpark and I know the episode he's referring to but I'm not sure if that second statement was a reference to it (no quotations to indicate whether it was or not). Feel free to correct me if I'm wrong; I didn't commit much of the episode to memory other than "Kip Drory = Bad friend stock."



It was in the episode. :)

http://www.youtube.com/watch?v=2LmAMa-SE8o

LOL!

JMcEntegart 05/07/2010 12:06 PM
Hide
-0+

daworstplaya :
It was in the episode. http://www.youtube.com/watch?v=2LmAMa-SE8oLOL!



I stand corrected! :)

longshotthe1st 05/07/2010 12:08 PM
Hide
-0+

I'm in!!! giggity giggity giggity giggity

Kelavarus 05/07/2010 12:11 PM
Hide
-1+

Aw, crud. Why didn't I know about this before? C'mon Tom's, find the bug BEFORE they fix it! :P

rionaam 05/07/2010 12:16 PM
Hide
-0+

babybeluga :
People who watch Southpark have 0 friends.


Maybe you should have said "People who watch the new seasons of South Park have 0 friends"...

JMcEntegart 05/07/2010 12:37 PM
Hide
-1+

Kelavarus :
Aw, crud. Why didn't I know about this before? C'mon Tom's, find the bug BEFORE they fix it!



Found yesterday, fixed yesterday!

babybeluga 05/07/2010 12:45 PM
Hide
-0+

rionaam :
Maybe you should have said "People who watch the new seasons of South Park have 0 friends"...



I really wouldn't know the difference.

eddieroolz 05/07/2010 12:46 PM
Hide
-0+

Didn't go on FB yesterday. Kinda happy about it.

rionaam 05/07/2010 1:28 AM
Hide
--2+

babybeluga :
I really wouldn't know the difference.


South Park was a great show, until it reached the 12th season, it just went downhill from there (I couldn't stand to watch the entire 13th season, I stopped watching in the middle of an episode).

Bruceification73 05/07/2010 2:45 AM
Hide
-0+

Yeah, but FB is still more secure than most sites with chat. AIM for example will let you find out the ip address of the person you are chatting with. And not the hidden AIM version of the ip, like facebook, but the actual ip address. Freaking hilarious when you tell someone what their ip is while you're chatting, and they freak out.

Anonymous 05/07/2010 11:21 AM
Hide
-0+

wtf so it was real! i always thought it was a huge prank

digiex 05/07/2010 4:38 PM
Hide
-0+

I know a bug but I wont tell anyone, I will exploit it until facebook will discover it themselves... Lol

gm0n3y 05/07/2010 6:17 PM
Hide
-0+

Facebook = evil.

sonnywoj 05/07/2010 7:58 PM
Hide
-0+

so has anyone else tried this yet? i just tried it.. not workin for me.

gm0n3y 05/07/2010 8:17 PM
Hide
-0+

sonnywoj :
so has anyone else tried this yet? i just tried it.. not workin for me.


First line in the article: "Facebook has patched a security hole..."

husker 05/07/2010 8:22 PM
Hide
-0+

I find it interesting that they chose to disable the chat feature, rather than the preview feature itself while the bug was fixed. That tells me the problem was with chat and that's the code that was altered.