Slashdot Mirror


Facebook Fixes Bug That Allowed Users To Set Other Users' Passwords

An anonymous reader writes: Facebook has paid $15,000 (€13,600) to an independent security researcher who discovered a simple way of resetting passwords for other people's Facebook accounts, setting a new passphrase and effectively taking over profiles.

The problem was in the fact that Facebook also runs a Beta platform on beta.facebook.com. This platform's "reset password" feature did not include brute-force protection and allowed anyone to guess the six-digit verification code sent to someone's phone when resetting the password. This issue also raises another question: How many unsafe features are on Facebook's beta platform that have not been patched simultaneously with the main platform?

1 of 49 comments (clear)

  1. Re:beta? by OzPeter · · Score: 4, Funny

    You'd normally expect more features in beta, even if not stable. Weird to see less protection on the beta platform

    You never saw /. beta did you?

    --
    I am Slashdot. Are you Slashdot as well?