Convenience trumped security bypassing passwords on Facebook

JMH

Emeritus, Contributor
Joined
Apr 2, 2012
Posts
7,197
We've all seen the emails, "*FRIEND* wants to be friends with you on Facebook", or "*FRIEND* commented on your status."
When you receive these messages there is a convenient button "Confirm friend request" or "See comment" embedded in the email message.
To ensure a frictionless experience, Facebook was embedding a cookie-like identifier in the links so you would not need to login to Facebook to acknowledge friend requests and other messages.
Anytime there is a method to bypass a security mechanism it will be abused and this feature was no exception.
http://nakedsecurity.sophos.com/201...Feed:+nakedsecurity+(Naked+Security+-+Sophos)
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top