Technology content trusted by users in Australia and around the world.
5,018 Articles | 30,555 Posts
Select Your Edition:  
Giveaway time thanks to AMD! Win one of five A Series A8 6600K 3.9GHz CPU's 
Tweakipedia
A wealth of
tech information!

TRENDING NOW: Microsoft does 180 on Xbox One DRM, drops 24 hour requirement, other changes

AU EditionYou are located: Home > All News > Hacking & Security News > WARNING: Facebook Mobile for iOS and Android allows easy access to your login information

WARNING: Facebook Mobile for iOS and Android allows easy access to your login information

By: (more) | Hacking & Security News | Posted: Apr 5, 2012 9:29 pm

Once again, I get to be the bearer of bad news just to keep you, our reader, safe. Facebook's Mobile app for iOS and Android store your login information in a plaintext file that doesn't expire until the year 4001. The Facebook .plist file where your login data is stored could easily be swiped by a USB connection or via malicious apps.

 

warning_facebook_mobile_for_ios_and_android_allows_easy_access_to_your_login_information

 

Gareth Wright, a U.K.-based app developer for Android and iOS, is the discoverer of this bug. He discovered it after poking around in the application directories using the free tool iexplorer. He first found a plaintext Facebook Access token that was stored by DrawSomething and was able to query all of his data.

 

He then took a look at Facebook's directory where he found the .plist in question. He passed this file over to his friend and fellow blogger who, in the next few minutes, started posting status updates, sending private messages, and even liking websites. In other words, he had full control over the account.

 

Facebook is currently working on a fix, but there is no ETA. Additionally, other apps who use Facebook Access Tokens need to encrypt those as well. This is just another reason to be careful when selecting apps or plugging your device into a shared PC. Getting Facebook "jacked" just became real.


SOURCE #1

Related Tags



Further Reading: Read and find more Hacking & Security news at our Hacking & Security news index page.

TweakTown News RSS FeedDo you get our news RSS feed? Get It! Got a news tip? Tell Us!

Post a Comment about this news



Check out our
RSS feeds!


Hacking & Security News Posts

View More Hacking & Security News Posts


TweakTown Web Poll

Question: Now you have the facts, which is your next-gen gaming console?

Microsoft Xbox One

Sony PlayStation 4

I'm a PC gamer, or not interested, or buying something else

or View the Results

View More Polls

Forum Activity

View More Forum Posts

Hacking & Security Press Releases

View More Hacking & Security Press Releases