Facebook: A Privacy Error ??


If you want to identify your facebook account there are 3 ways you can Identify yourself:

1. Provide your e-mail ID.
2. Provide your Phone number (If you have given this in you profile).
3. Provide your user ID(your unique id assigned by the facebook).

Screenshot below shows the page (https://www.facebook.com/login/identify?ctx=recover) to identify your account in case you want to recover.


The other way to look into this is this can also be misused to validate someones phone number. Let say my phone number is 9739141XXX. I put it there and I see myself.So the phone number and profile relation can be seen successfully.


But I have kept my privacy settings to most secure that "Only Friends"(shown in screenshot below) can look to my phone numbers. Isn't this is a privacy breach.


But here is the catch.Facebook is smart and keeps the log of Public IPs you are coming from. If you have logged in from the same Public IP before this privacy settings can be bypassed.And hence threat is limited to the users those who are sharing their public IP with others like cyber cafes, corporate offices etc. So if you are coming from a new public IP this is what you will get.


Facebook will confirm that this is a valid FB users number but the phone number and profile relationship can not be established. But this could be used to profile the valid phone numbers. Well I will elaborate on this on my next post.

I reported this issue to Facebook and this is what reply I got after multiple round of communication, discussions. Facebook was keen enough to know it more and the support was quite good.This is the final mail from them:

Hi Shashank,

I believe it is more than just ip but I do know ip is part of it. I believe it is not so much if you are coming from a given IP (cyber cafe in example) right at that moment but if over time we have seen you come from the same computer or ip a number of times.

I believe this to be safe. The worst case scenario here is that in the process of brute-forcing phone numbers you get lucky and run across someone in the same cyber cafe as you, you can learn their first/last name. Since brute-force protections are in place to stop you after some number of requests (1000 would be a reasonable guess) I find this scenario very unlikely.

I appreciate your continued effort with this issue but I dont think this has big security implications.

Thanks,

Emrakul
Security
Facebook










Comments

Post a Comment

Popular posts from this blog

DevSecOps Expeditions

HackIM 2018 Walkthrough OSINT 1 to 4