Skip to main content

Researchers disclose Facebook 'deactivated friend attack'

posted onMarch 20, 2012
by l33tdawg

University College of London student, Shah Mahmood, along with Yvo Desmedt, Chair of Information Communication Technology, has discovered what they're labelling as a “zero day privacy hole” in Facebook.

The vulnerability which they call “deactivated friend attack” was presented at the IEEE International workshop on security and social networking in Switzerland. They say the attack works like this:

“Our deactivated friend attack occurs when an attacker adds their victim on Facebook and then deactivates her own account. As deactivation is temporary in Facebook, the attacker can reactivate her account as she pleases and repeat the process of activating and deactivating for unlimited number of times. While a friend is deactivated on Facebook, she becomes invisible. She could not be unfriended (removed from friend’s list) or added to any specific list.”

Complicating matters further is the fact that Facebook users aren't told when friends deactivate or reactivate accounts. Unless of course they're using plug-ins like Unfriend Finder, a simple browser extension which allows users to know when one of their friends either removes them as a contact or deactivates their account. Honestly, I don't see how this could be called an ATTACK - but oh well. 

Source

Tags

Facebook Privacy Security Hackers

You May Also Like

Recent News

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th