Stuff

    Subscribe to our newsletter

    What's Hot
    Vodacom

    Vodacom launches its ‘Good as New’ refurbished iPhone range

    July 6, 2022
    VS Gaming Weekly

    South African esports gets its own TV show – This is VS Gaming Weekly

    July 6, 2022
    Shanghai

    Shanghai hack sees over 23TB of personal information up for sale

    July 6, 2022
    Facebook Twitter Instagram YouTube SoundCloud
    Trending
    • Vodacom launches its ‘Good as New’ refurbished iPhone range
    • South African esports gets its own TV show – This is VS Gaming Weekly
    • Shanghai hack sees over 23TB of personal information up for sale
    • How Discovery Insure is making people better drivers and saving lives – T2S2
    • Glance is here to absolutely ruin your day. And your lock-screen
    • This is what a 3D-printed lunar base built by autonomous robots might look like
    • Nigeria’s latest lithium find: some key questions answered
    • Asus ROG Phone 6 and 6 Pro models announced, will land in SA (eventually)
    Facebook Twitter Instagram YouTube
    Stuff Stuff
    • News
      • App News
      • Business News
      • Camera News
      • Gaming News
      • Headphone News
      • Industry News
      • Internet News
      • Laptops News
      • Motoring News
      • Other Tech News
      • Phone News
      • Tablet News
      • Technology News
      • TV News
      • Wearables News
    • Reviews
      • Camera Reviews
      • Car Reviews
      • Featured Reviews
      • Game Reviews
      • Headphone Reviews
      • Laptop Reviews
      • Other Tech Reviews
      • Phone Reviews
      • Tablet Reviews
      • Wearables Reviews
    • Columns
    • Stuff Guides
    • Podcasts & Videos
      • Videos
      • Stuffed
      • Stuffing Around
      • Tech Byte
      • T2S2
    • Win
    • Subscribe
      • Print
      • Digital
        • Google Play
        • iTunes
        • Download
        • Zinio
    • Stuff Shop
      • Shop Now
      • My Account
      • Downloads
    • Contact Us
      • Get In Touch
      • Advertise
    0 Shopping Cart
    Stuff
    Home » News » Internet News » Facebook hack reveals the perils of using a single account to log in to other services
    Internet News

    Facebook hack reveals the perils of using a single account to log in to other services

    The ConversationBy The ConversationOctober 2, 2018Updated:October 1, 2021No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Facebook announced on Friday that its engineering team had discovered a security issue affecting almost 50 million accounts. Due to a flaw in Facebook’s code, hackers were able to take over an account and use it in the same way you would if you had logged into the account with a password.

    The company says it has now fixed the problem in its code and reset access tokens for those accounts – along with 40 million other accounts that were vulnerable to the flaw. If you found yourself logged out of your Facebook account last week, it’s likely you were affected.

    Beyond that, little is known about the extent of the security breach. In its security update, Facebook said:

    Since we’ve only just started our investigation, we have yet to determine whether these accounts were misused or any information accessed. We also don’t know who’s behind these attacks or where they’re based.

    What it means

    This is not the worst data breach to date. That accolade belongs to the credit bureau Equifax, which had personal data stolen from the accounts of 147 million people. But, unfortunately for Facebook, there are several flow-on effects from the recent hack.

    First, the breach may run afoul of the European Union’s General Data Protection Regulation (GDPR), which was introduced in May. Although the GDPR only applies to European citizens, the penalties for data breaches are severe – up to 4% of global turnover per breach.

    Second, any accounts on other platforms that use Facebook verification are also at risk. That’s because it’s now a common practice to use one account as an automatic verification to connect to other platforms, for example by using a Facebook account to log in to another social media platform such as Twitter, Spotify or Instagram. This is known as single sign-on (SSO).

    How single sign-on works

    If you connect to any system, you need some form of authentication – usually a login credential such as a username and password pair. When you have many different systems that all require credentials before you can use them, suddenly you’re faced with remembering ten different (ideally very long) passwords.

    Some people can do this, but many can’t. And we still want the systems to be secure. If we could connect to one system that was trusted by the others, and use the trusted system’s password, then we wouldn’t need ten passwords – just one. That’s the principle behind SSO.

    But this only works as long as the trusted system is secure. If it’s not, a cybercriminal could use the hacked account on one platform (in this case, Facebook), to access any other connected platform.

    What you should do

    Authentication usually works because of one of three factors:

    • something you know, such as a password
    • something you have, such as an access card
    • something you are, such as a fingerprint.

    Clearly, using more than one factor increases security. In your Facebook account, you can choose to use two-factor authentication. That means that you would need to enter your password plus a code sent to you via an SMS message when you next log in.

    The future of verification

    There is always a tension between usability and security. People want systems to be secure so that their identities aren’t stolen, and they also want the same systems to be easily accessible. SSO is an attempt to balance usability and security, but the Facebook hack reveals its limitations.

    Many people don’t like passwords, so they choose easily remembered, and therefore easily breakable, passwords. Cybercriminals have access to lists of millions of common passwords (hint: “Gandalf” isn’t as unique as you might think).

    Access tokens, such as cards or other physical devices (as used by some banks, for example) are a solution – as long as you don’t lose it. It might be that using a unique physical attribute is the best way forward. After all, you always carry your fingerprint, iris or voice with you.

    • Mike Johnstone is Security Researcher, Associate Professor in Resilient Systems, Edith Cowan University
    • This article first appeared on The Conversation

    Facebook hack password security The Conversation
    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    The Conversation

      Related Posts

      Vodacom

      Vodacom launches its ‘Good as New’ refurbished iPhone range

      July 6, 2022
      VS Gaming Weekly

      South African esports gets its own TV show – This is VS Gaming Weekly

      July 6, 2022
      Shanghai

      Shanghai hack sees over 23TB of personal information up for sale

      July 6, 2022

      Leave A Reply Cancel Reply

      In The Mag
      Stuff June-July 2022 Latest Issue

      In This Issue – The Outdoors (June-July 2022) Issue

      By Brett VenterMay 30, 20221

      Once again, we are asking you to check out a new issue of Stuff Magazine.…

      2021 Wish List
      wish list Stuff Wish List 2021

      Stuff Wish List: for the tech impaired

      By Duncan PikeDecember 22, 20210

      Are you from the time before being glued to a smartphone was considered normal? Here’s…

      Wishlist DIY Stuff tech

      Stuff Wish List: for the DIY Diehard

      December 21, 2021
      Wish List Gearhead

      Stuff Wish List: For the petrol-soaked gearhead

      December 20, 2021
      outsiders

      Stuff Wish List: for the Outsiders

      December 17, 2021

      Latest Video

      Sonos

      SONOS Roam SL unboxing by Toby Shapshak

      March 30, 2022
      Mini Cooper

      The Mini Cooper SE Electric with Toby Shapshak

      March 18, 2022
      MSI Crosshair 15 Rainbox Six Extraction Edition unboxing

      MSI Crosshair 15 Rainbox Six Extraction Edition unboxing

      March 16, 2022
      Samsung Galaxy S22 Ultra Unboxing

      Samsung Galaxy S22 Ultra unboxing with Toby Shapshak

      March 16, 2022
      Contact

      South Africa's Consumer Tech News Hub

      General: [email protected]
      Subscriptions: [email protected] or 087 353 1291
      Editorial: 072 735 2614
      Sales: 083 375 2418

      Facebook Twitter Instagram YouTube SoundCloud

      Subscribe to Updates

      • Terms and Conditions
      • Privacy & POPI
      • My account
      © 2022 Stuff Group. Designed by Chronon.

      Type above and press Enter to search. Press Esc to cancel.