{"id":63527,"date":"2018-04-19T07:06:56","date_gmt":"2018-04-19T07:06:56","guid":{"rendered":"https:\/\/www.biphoo.com\/bipnews\/?p=63527"},"modified":"2018-04-19T07:06:56","modified_gmt":"2018-04-19T07:06:56","slug":"facebooks-login-sites-service-lets-scum-slurp-stuff","status":"publish","type":"post","link":"https:\/\/www.biphoo.com\/bipnews\/technology\/facebooks-login-sites-service-lets-scum-slurp-stuff.html","title":{"rendered":"Facebook&#8217;s login to other sites service lets scum slurp your stuff"},"content":{"rendered":"<h2 style=\"text-align: justify\"><strong><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 18pt\">Facebook&#8217;s login to other sites service lets scum slurp your stuff<\/span><\/strong><\/h2>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt\">A security researcher has claimed it&#8217;s possible to extract user information from Facebook&#8217;s Login service, the tool that lets you sign into third-party sites with a Facebook ID.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt\">Readers will be familiar with Steven Englehardt (a Mozilla privacy engineer who pursues privacy research for his PhD at Princeton), whose work on browser fingerprinting led him to identifying a remarkable degree of privacy invasion by analytical scripts.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt\">In Englebardt&#8217;s latest work, in partnership with Gunes Acar and Arvind Narayanan, the three explain that they identified seven sites accessing Facebook user data, and one site using Facebook&#8217;s application to track users around the Web.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt\">For users, Facebook Login looks like a boon: they only need to use their Facebook password to log into multiple sites or apps. That, however, puts a very strong onus on Facebook to make sure the whole process is secure.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt\">What Englebardt discovered is simple: \u201cwhen a user grants a website access to their social media profile, they are not only trusting that website, but also third parties embedded on that site.\u201d<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt\">The third parties were able to grab Facebook user ID, e-mail, name, and other profile information including (in one case) gender.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt\">\u201cWe found seven scripts collecting Facebook user data using the first party\u2019s Facebook access\u201d, he wrote. The practice isn&#8217;t yet widespread, thankfully: scripts to gather this user information were only found on 434 of the Alexa top million sites, including \u201cfiverr.com, bhphotovideo.com, and mongodb.com\u201d.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt\">The table below shows some a sample of some sites&#8217; data collection Englehardt&#8217;s team identified.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt\">Engledhardt noted that OnAudience stopped the data collection when he&#8217;d previously spotted them misusing browser autofill features.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt\">The second tracker Engledhardt discovered was that sites can abuse iFrames to de-anonymise users who had used Facebook Login to access their sites. In the example given in the article, Bandsintown (an online gig guide) was carrying a hidden tracker that passed user information to an embedded iFrame script (meaning Bandsintown could read the Facebook profile).<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt\">He added that having linked the logged in user to their Facebook profile, Bandsintown could then pass that information up to advertisers.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt\">When notified, the site discontinued the practice.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt\">Englehardt emphasised that this kind of third-party data gathering shouldn&#8217;t be regarded as a bug on Facebook&#8217;s part, although having announced \u201canonymous login\u201d four years ago, it might be time for the Social Network\u2122 to implement the feature.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt\">As he wrote: &#8220;It is straightforward for a third party script to grab data from the Facebook API.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 8pt\">Source:-https:\/\/www.theregister.co.uk\/2018\/04\/19\/facebook_third_party_site_login_security_leak\/<\/span><\/p>\n<div class=\"fb-background-color\">\n\t\t\t  <div \n\t\t\t  \tclass = \"fb-comments\" \n\t\t\t  \tdata-href = \"https:\/\/www.biphoo.com\/bipnews\/technology\/facebooks-login-sites-service-lets-scum-slurp-stuff.html\"\n\t\t\t  \tdata-numposts = \"10\"\n\t\t\t  \tdata-lazy = \"true\"\n\t\t\t\tdata-colorscheme = \"light\"\n\t\t\t\tdata-order-by = \"social\"\n\t\t\t\tdata-mobile=true>\n\t\t\t  <\/div><\/div>\n\t\t  <style>\n\t\t    .fb-background-color {\n\t\t\t\tbackground: #ffffff !important;\n\t\t\t}\n\t\t\t.fb_iframe_widget_fluid_desktop iframe {\n\t\t\t    width: 630px !important;\n\t\t\t}\n\t\t  <\/style>\n\t\t  ","protected":false},"excerpt":{"rendered":"<p>Facebook&#8217;s login to other sites service lets scum slurp your stuff A security researcher has claimed it&#8217;s possible to extract user information from Facebook&#8217;s Login service, the tool that lets you sign into third-party sites with a Facebook ID. Readers will be familiar with Steven Englehardt (a Mozilla privacy engineer [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":63528,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[132402,692,14505,12073,14823],"class_list":["post-63527","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-facebooks-login-to-other-sites-service-lets-scum-slurp-your-stuff","tag-latest-technology-news","tag-technology-news-headlines","tag-technology-news-today","tag-technology-news-usa"],"_links":{"self":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts\/63527","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/comments?post=63527"}],"version-history":[{"count":0,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts\/63527\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/media\/63528"}],"wp:attachment":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/media?parent=63527"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/categories?post=63527"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/tags?post=63527"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}