Subscribe

0

  • Sign in with Email

By clicking the button, I accept the Terms of Use of the service and its Privacy Policy, as well as consent to the processing of personal data.

Don’t have an account? Signup

  • Bookmarks
  • My Profile
  • Log Out
  • NEWS
  • LEADERSHIP INSIGHTS
    • Interview
    • Opinion
    • Editors Blog
    • Features
    • DQ40YEARS
  • BUSINESS TECHNOLOGIES
  • DATA & AI
  • ESDM
  • UPSKILLING
  • BUSINESS SOLUTIONS
  • MORE
    • Annuals
    • Reviews
    • DQDEEPTECH
    • Events
    • Tech4Growth
    • DQConclave
    • TechSchools
  • Magazine
ad_close_btn
  • News
  • Business Technologies
  • DQDeepTech
  • Annuals
  • Events
  • Business Solutions
  • Interview
  • Module
  • Editors Blog
  • Opinion

Powered by :

You have successfully subscribed the newsletter.
banner
News Business Technologies

How the Facebook authentication security breach can compromise every account from Uber to Snapdeal to Zomato

author-image
Srikanth R P
19 Jun 2015 17:44 IST

Follow Us

New Update
Facebook hack
Mohit Bagga and Tajinder Pal Singh Chahal
Advertisment

Mohit Bagga, Co-Founder & CTO, Codebibber and Tajinder Pal Singh Chahal, describe the discovery of a major security breach in the Facebook login process, where one single access token received from Facebook for a particular app can be used to access the entire account history of a user on a series of big players like Zomato, Foodpanda or Snapdeal

Here is Mohit and Tajinder Pal Singh Chahal in their own words:

While researching for our new venture TOTUM, we hacked around Facebook login, looking for alternate login methods. This is when we discovered a major security breach, which can compromise your data across multiple platforms.

In simple words, whenever you choose the “Login Through Facebook” option on any website or mobile app, you expose every other account where you ‘logged in through Facebook’ including Uber, Snapdeal, Zomato and Foodpanda among the rest.

To understand this, let us first look at how Facebook Login works:

Advertisment
Facebook Login process

The security breach

Let’s say you login to app X via Facebook. X will receive an access token from Facebook and will send it to X’s server and save it.

But now X can use this same access token to login to any and every other platform impersonating you and access your data ranging from your recent orders on Zomato or your purchase history from Snapdeal to getting access to your private messages and the list goes on.

Advertisment

We tested out this security breach on our TOTUM app’s test run and to our amazement, by using a single access token that we received from Facebook, we were able to access the entire account history of that user on a series of big players like Zomato, Foodpanda, Snapdeal etc.

Facebook Login Token compromised

Our evil plan

We initially thought of creating a chrome plugin that can inspect the web pages before viewing and blur the text where GOT (Game of Thrones) related information is published, so that you do not read spoilers.  Our guess was such a plugin would have received a pretty generous number of user downloads. But this plugin would have been infected with a virus that reads your Facebook access token and scraps user data from different target sites. This would have given us a huge user account base to begin our exploits.

Advertisment

But the genius yet kind souls that we are, we decided instead to post about this breach and alert the unsuspecting net savvy souls who are ever so eager to ‘Login through Facebook’ and save the extra 2 minutes, about the consequences of this simple step.

Food for thought
Would you want every online account you ever create to be available for misuse by any random app? Isn’t it scary to think anyone can book rides using your Uber account and pay using your PayTM wallet?

Facebook has access to all the information about every platform which provides the ‘Login Through Facebook’ option. They can scrap from all the platforms anytime they want.

Until this issue is resolved, your online data is all up for grabs.

facebook-hack hacking-facebook login-through-facebook-security-breach login-through-facebook
Subscribe to our Newsletter! Be the first to get exclusive offers and the latest news
logo

Related Articles
Read the Next Article
banner
Latest Stories
Subscribe to our Newsletter! Be the first to get exclusive offers and the latest news

Latest Stories
Latest Stories
    Powered by


    Subscribe to our Newsletter!




    Powered by
    Select Language
    English

    Share this article

    If you liked this article share it with your friends.
    they will thank you later

    Facebook
    Twitter
    Whatsapp

    Copied!