Modern Australian
The Times Real Estate

.

Facebook hack reveals the perils of using a single account to log in to other services

  • Written by Mike Johnstone, Security Researcher, Associate Professor in Resilient Systems, Edith Cowan University
Facebook hack reveals the perils of using a single account to log in to other services

Facebook announced on Friday that its engineering team had discovered a security issue affecting almost 50 million accounts. Due to a flaw in Facebook’s code, hackers were able to take over an account and use it in the same way you would if you had logged into the account with a password.

The company says it has now fixed the problem in its code and reset access tokens for those accounts – along with 40 million other accounts that were vulnerable to the flaw. If you found yourself logged out of your Facebook account last week, it’s likely you were affected.

Read more: Overcoming 'cyber-fatigue' requires users to step up for security

Beyond that, little is known about the extent of the security breach. In its security update, Facebook said:

Since we’ve only just started our investigation, we have yet to determine whether these accounts were misused or any information accessed. We also don’t know who’s behind these attacks or where they’re based.

What it means

This is not the worst data breach to date. That accolade belongs to the credit bureau Equifax, which had personal data stolen from the accounts of 147 million people. But, unfortunately for Facebook, there are several flow-on effects from the recent hack.

First, the breach may run afoul of the European Union’s General Data Protection Regulation (GDPR), which was introduced in May. Although the GDPR only applies to European citizens, the penalties for data breaches are severe – up to 4% of global turnover per breach.

Read more: Regulating Facebook won't prevent data breaches

Second, any accounts on other platforms that use Facebook verification are also at risk. That’s because it’s now a common practice to use one account as an automatic verification to connect to other platforms, for example by using a Facebook account to log in to another social media platform such as Twitter, Spotify or Instagram. This is known as single sign-on (SSO).

How single sign-on works

If you connect to any system, you need some form of authentication – usually a login credential such as a username and password pair. When you have many different systems that all require credentials before you can use them, suddenly you’re faced with remembering ten different (ideally very long) passwords.

Some people can do this, but many can’t. And we still want the systems to be secure. If we could connect to one system that was trusted by the others, and use the trusted system’s password, then we wouldn’t need ten passwords – just one. That’s the principle behind SSO.

But this only works as long as the trusted system is secure. If it’s not, a cybercriminal could use the hacked account on one platform (in this case, Facebook), to access any other connected platform.

What you should do

Authentication usually works because of one of three factors:

  • something you know, such as a password
  • something you have, such as an access card
  • something you are, such as a fingerprint.

Clearly, using more than one factor increases security. In your Facebook account, you can choose to use two-factor authentication. That means that you would need to enter your password plus a code sent to you via an SMS message when you next log in.

Read more: The age of hacking brings a return to the physical key

The future of verification

There is always a tension between usability and security. People want systems to be secure so that their identities aren’t stolen, and they also want the same systems to be easily accessible. SSO is an attempt to balance usability and security, but the Facebook hack reveals its limitations.

Many people don’t like passwords, so they choose easily remembered, and therefore easily breakable, passwords. Cybercriminals have access to lists of millions of common passwords (hint: “Gandalf” isn’t as unique as you might think).

Access tokens, such as cards or other physical devices (as used by some banks, for example) are a solution – as long as you don’t lose it. It might be that using a unique physical attribute is the best way forward. After all, you always carry your fingerprint, iris or voice with you.

Authors: Mike Johnstone, Security Researcher, Associate Professor in Resilient Systems, Edith Cowan University

Read more http://theconversation.com/facebook-hack-reveals-the-perils-of-using-a-single-account-to-log-in-to-other-services-104227

Managed IT Services for Australian Retailers

Australian retailers are constantly being compelled to deliver flawless customer experiences with tight security measures. Managed IT services, or M...

What to Consider When Looking for Family Lawyers in Brisbane

Family law issues can be deeply personal and emotionally charged, making it important to choose the right family lawyers in Brisbane. Whether you're...

Construction and Surveying: The Foundation of Modern Infrastructure

Precision and accuracy are the name of the game in construction. Construction and surveying are crucial disciplines that most public members remain ...

Why the Demand for Tutors is Growing Across Australia

As the academic stakes rise each year, students across Australia are increasingly turning to tutors to maximise their chances of success. But why the ...

House Movers in Perth: Tips for a Successful Relocation

Moving houses can be exciting, but it can also be an overwhelming process. The mere anticipation of packing up your life and transporting it somewhe...

Why Rental Property Inspections Are Important for Tenants and Landlords

Regular property inspection is one of the key components of a smooth rental experience, benefitting both the tenant and the landlord.  Experts sugge...

Beer Label Design for New Breweries: Where to Start in 2025

Imagine a customer picking up your beer based purely on its striking label. In a crowded market full of craft brews and new brands, first impression...

Functional and Fashionable: The Rise of Ladies Workwear in Australia

A perfect change in the Australian workforce has been happening in recent days. Women are contributing a lot in the male-dominated workplaces. They ...

Concrete Trailer Pump for Sale: Your Ultimate Solution for Efficient Concrete Placement

In construction projects where efficiency, precision, and flexibility are paramount, concrete trailer pumps for sale stand out as an essential piece...

Exploring Different Types of Solar Panels: Monocrystalline, Polycrystalline, and Thin-Film

The demand for solar energy continues to grow as more Australians embrace sustainable energy solutions. A crucial step in transitioning to solar pow...

Common Mistakes in Food and Wine Pairing (And How to Avoid Them)

Pairing food and wine is often considered an art, but it doesn’t have to be intimidating. The right pairing can elevate a dining experience, while...

Wine Tasting 101: A Beginner’s Guide to Smelling, Swirling, and Sipping

Wine tasting is an art form that can seem daunting to beginners, but with a little knowledge and a lot of enthusiasm, anyone can master the basics. ...

How to Fix a Clogged Shower Drain: Tips for Homeowners

A clogged shower drain is a common household issue that can be both frustrating and inconvenient. Over time, hair, soap scum, and other debris can a...

Top Trends in Electric Recliner Sofas for 2024

Electric recliner sofas have taken center level in the world of furniture layout, combining consolation, comfort, and superior generation. As we pas...

Setting Up the Perfect Home Studio for Drummers

Creating the perfect home studio for drumming is a fulfilling project that goes beyond just having a space to practice. A well-designed studio can a...

Essential Guide to Surveying Services for Land and Construction

Surveying is indispensable in all land development, real estate transactions, and construction. The core of surveys, including metric geodetic and pre...

A Step in the Right Direction: Choosing the Best Nursing Shoes and Socks for Australian Healthcare Workers

Australian healthcare professionals need to work long hours for the people. They have to be on their feet in demanding situations. So, it will be ne...

Understanding Modern Art Movements – Surrealism, Cubism, and Beyond

Modern art movements have always challenged conventions, pushing the boundaries of creativity and expression. From the fragmented perspectives of Cu...