Modern Australian

Facebook hack reveals the perils of using a single account to log in to other services

  • Written by Mike Johnstone, Security Researcher, Associate Professor in Resilient Systems, Edith Cowan University
Facebook hack reveals the perils of using a single account to log in to other services

Facebook announced on Friday that its engineering team had discovered a security issue affecting almost 50 million accounts. Due to a flaw in Facebook’s code, hackers were able to take over an account and use it in the same way you would if you had logged into the account with a password.

The company says it has now fixed the problem in its code and reset access tokens for those accounts – along with 40 million other accounts that were vulnerable to the flaw. If you found yourself logged out of your Facebook account last week, it’s likely you were affected.

Read more: Overcoming 'cyber-fatigue' requires users to step up for security

Beyond that, little is known about the extent of the security breach. In its security update, Facebook said:

Since we’ve only just started our investigation, we have yet to determine whether these accounts were misused or any information accessed. We also don’t know who’s behind these attacks or where they’re based.

What it means

This is not the worst data breach to date. That accolade belongs to the credit bureau Equifax, which had personal data stolen from the accounts of 147 million people. But, unfortunately for Facebook, there are several flow-on effects from the recent hack.

First, the breach may run afoul of the European Union’s General Data Protection Regulation (GDPR), which was introduced in May. Although the GDPR only applies to European citizens, the penalties for data breaches are severe – up to 4% of global turnover per breach.

Read more: Regulating Facebook won't prevent data breaches

Second, any accounts on other platforms that use Facebook verification are also at risk. That’s because it’s now a common practice to use one account as an automatic verification to connect to other platforms, for example by using a Facebook account to log in to another social media platform such as Twitter, Spotify or Instagram. This is known as single sign-on (SSO).

How single sign-on works

If you connect to any system, you need some form of authentication – usually a login credential such as a username and password pair. When you have many different systems that all require credentials before you can use them, suddenly you’re faced with remembering ten different (ideally very long) passwords.

Some people can do this, but many can’t. And we still want the systems to be secure. If we could connect to one system that was trusted by the others, and use the trusted system’s password, then we wouldn’t need ten passwords – just one. That’s the principle behind SSO.

But this only works as long as the trusted system is secure. If it’s not, a cybercriminal could use the hacked account on one platform (in this case, Facebook), to access any other connected platform.

What you should do

Authentication usually works because of one of three factors:

  • something you know, such as a password
  • something you have, such as an access card
  • something you are, such as a fingerprint.

Clearly, using more than one factor increases security. In your Facebook account, you can choose to use two-factor authentication. That means that you would need to enter your password plus a code sent to you via an SMS message when you next log in.

Read more: The age of hacking brings a return to the physical key

The future of verification

There is always a tension between usability and security. People want systems to be secure so that their identities aren’t stolen, and they also want the same systems to be easily accessible. SSO is an attempt to balance usability and security, but the Facebook hack reveals its limitations.

Many people don’t like passwords, so they choose easily remembered, and therefore easily breakable, passwords. Cybercriminals have access to lists of millions of common passwords (hint: “Gandalf” isn’t as unique as you might think).

Access tokens, such as cards or other physical devices (as used by some banks, for example) are a solution – as long as you don’t lose it. It might be that using a unique physical attribute is the best way forward. After all, you always carry your fingerprint, iris or voice with you.

Authors: Mike Johnstone, Security Researcher, Associate Professor in Resilient Systems, Edith Cowan University

Read more http://theconversation.com/facebook-hack-reveals-the-perils-of-using-a-single-account-to-log-in-to-other-services-104227

Innovative Solar Conduit Solutions: Why Solarflex Stands Out

When it comes to solar installations, efficiency, safety, and regulatory compliance are essential — particularly when tight schedules and diverse en...

Loaded Potato Snacks: Perfectly Crispy French Fries and Air-Fried Hash Browns

Are you craving a crunchy, flavorful potato snack that goes beyond the usual French fries? Let me introduce you to two of my favorite recipes: Loade...

Bulk Liquid Storage Tanks: Essential Solutions for Modern Industry

In industries where managing large quantities of liquids is a daily requirement, bulk liquid storage tanks play a vital role. These tanks are desi...

Bistro Blinds for Seasonal Changes: Adapting Your Outdoor Space

Bistro blinds are outdoor designs that can be adapted for seasonal changes. They warm up the environment by making it wind-free, wet-free, and sun...

Advantages of Using Digital Printing Services

The demand for quick, efficient, and high-quality printing solutions has seen remarkable growth in our modern, fast-paced world. This increasing nee...

Benefits of Professional Strata Management

Navigating the complexities of strata management can be a daunting endeavor for any strata property owner or committee member. Strata management inv...

The Hidden Benefits of Bundling Utilities with Moving Services

Moving can feel overwhelming with so many things to juggle. Hiring a moving company in Brisbane helps make it easier, but did you know you can make it...

Family Mediation: The Path to Resolution, Healing, and Lasting Solutions

In an era where family challenges are often met with emotional and financial strain, family mediation has quietly gained traction as a life-changing...

Surprise Party Ideas That Will Leave Your Guests Speechless

Throwing a surprise party is one of the most exciting ways to celebrate a special occasion. The thrill of keeping it a secret combined with the joy ...

“North of the River” Vs “Over the Bridge” – What’s in Brisbane’s ongoing North Vs South Feuds?

Greater Brisbane Australia’s largest capital city by land area, coming in at 15,824 square kilometers, and ranks number three worldwide. It has Au...

Income Stream Integration: 7 Ways to Earn Money Through Your Website

Whether you sell Vietnamese coffee, review Japanese gadgets, or rent Melbourne self storage, your website is more than just an online presence—it...

Top 10 Benefits of Practicing Taekwondo for All Ages

Taekwondo is more than just a martial art; it’s a way of life that offers profound physical, mental, and emotional benefits. Whether you're a chil...

Plasterboarding and Ceiling Repair: The PlasterX Advantage for Long-Lasting Results

Contacting professionals who are well-versed in the nuances of the task is essential to preventing headaches during plastering ceiling repair work. ...

Snake Catcher’s Life-Saving Advice: What to Do When You Encounter a Snake

Australia is home to some of the most venomous snakes in the world, and if you live here, you're already well aware of how dangerous these creatures...

The Best Dumplings in Melbourne

Melbourne offers the best dumplings in the world, with variety of tastes and styles. The perfect dumpling is boiled, fried, or steamed - the best ...

The Ultimate Guide to Daily Dental Hygiene: Tips for a Healthy Smile

Maintaining good oral hygiene is essential for a healthy smile that lasts a lifetime. While regular visits to your dentist are important, establishi...

Mixing Vintage and Modern: How to Create a Timeless Interior

Achieving a timeless interior that blends both vintage charm and modern sophistication can transform any home into a stylish, curated space. When do...

Sugar-Free Chocolate Treats: A Guilt-Free Indulgence

People are very conscious about their health and sugar-free chocolates are becoming a popular option. This is a delicious and very satisfying option...