Complete Story


Facebook Had Years to Fix the Flaw That Leaked 500 Million Users’ Data

The company had ample warning about its “contact import” privacy problems

The profile names, email addresses, and phone numbers of more than 500 million Facebook users have been circulating publicly online for nearly a week. It took days for Facebook to finally acknowledge the root cause, an issue the company says it fixed in 2019. But now researchers are saying Facebook knew about similar vulnerabilities for years before that, and it could have made a far greater effort to prevent the mass scraping in the first place.

At issue is Facebook's “content importer,” a feature that combs a user's address book to find people they know who also use Facebook. Many social networks and communication apps offer some version of this as a sort of social lubricant. But Facebook's contact import tool in particular has had a number of known problems and supposed fixes, over the years.

"I'm sure other companies are sweating as well now. It's not just Facebook," said Inti De Ceukelaire, a Belgian security researcher who reported a vulnerability in Facebook's contact import feature to the company in 2017. "But it's a recurring theme for Facebook that whenever growth is at stake, they will think twice about fixing something to benefit the user's privacy."

Please select this link to read the complete article from WIRED.

Printer-Friendly Version