Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
In early December, Facebook’s developer team declared the discovery of a security bug that gave developers access to photos users hadn’t shared on their timeline, including photos they had posted in Facebook Marketplace or Stories.. More worryingly, apps could find access to images users might have uploaded to Facebook but didn’t post anywhere. For example, this could be pictures you uploaded to a profile update you abandoned and did not complete. These are pictures that users haven’t shared with anyone. The link for this article located at The Next Web is no longer available. . Applications were able to view photos that users had uploaded without publicly sharing them on Facebook. This raised serious issues regarding privacy and safety.. Facebook Privacy Breach, Security Bug, Data Exposure, Image Access, Software Flaw. . LinuxSecurity.com Team
After interviewing over 60 people, ranging from former Facebook employees and partners, as well as reviewing over 270 internal Facebook documents, The New York Times discovered that Facebook offered its users’ data to more than 150 companies. Those companies, the investigation revealed, ranged from tech and entertainment companies to online retailers, automakers, and even banks.. Without first obtaining users’ permission, Facebook “allowed Spotify, Netflix and the Royal Bank of Canada to read, write and delete users’ private messages, and to see all participants on a thread.” It let Bing “see the names of virtually all Facebook users’ friends without consent.” Amazon could “obtain users’ names and contact information through their friends.” Yahoo could view streams of friends’ posts. The list goes on and on. The link for this article located at CSO Online is no longer available. . Without first obtaining users’ permission, Facebook “allowed Spotify, Netflix and the Royal Bank. interviewing, people, ranging, former, facebook, employees, partners. . LinuxSecurity.com Team
A bug in Facebook’s photo API may have exposed up to 6.8 million users’ photos to app developers, the company announced on Friday. . Facebook said that normally, when a user gives permission for an app to get at their Facebook photos, the developers are only supposed to get access to photos that are posted onto their timeline. The link for this article located at NakedSecurity / Sophos is no longer available. . A glitch in Facebook's image API might have inadvertently revealed countless users' private images, sparking issues related to user confidentiality.. Facebook API, User Privacy, Data Breach, Photo Security. . LinuxSecurity.com Team
After asking for their customers' personal information in Fallout 76 support tickets, American video game publisher Bethesda Software LLC exposed those tickets to public access allowing anyone to view, edit, and resolve them. . The support tickets were accessible by anyone who submitted their own, with tickets containing names, usernames, addresses, and emails opened by other people automatically being sent to the wrong accounts for a limited period. The link for this article located at Softpedia News is no longer available. . The support tickets were accessible by anyone who submitted their own, with tickets containing names. asking, their, customers', personal, information, fallout, support, tickets, american, video. . LinuxSecurity.com Team
The US Postal Service has fixed a security bug in its website that allowed anyone with an account to see the account details of the site's 60 million users.. The flaw was patched this week after USPS was informed of the issue by Krebs on Security, which reports that an unnamed independent researcher reported the bug a year ago but never received a response. The link for this article located at ZDNet is no longer available. . A newly discovered vulnerability on the FedEx website compromised personal information of 75 million individuals; this problem has since been resolved.. USPS Security, User Data Exposure, Website Bug, Privacy Breach, Data Integrity. . LinuxSecurity.com Team
In April, with the GDPR deadline and its requirement for data portability looming, Instagram released the long-anticipated download your data tool. The feature gave users the ability to download images, posts and comments.. Unfortunately, Instagram turned the task of downloading your data into an exercise in exposing people’s passwords in plain text. Thankfully, the bug in the “download your data” tool only affected a handful of users, it said. The link for this article located at Naked Security/Sophos is no longer available. . Unfortunately, Instagram turned the task of downloading your data into an exercise in exposing peopl. april, deadline, requirement, portability, looming, instagram, release. . LinuxSecurity.com Team
A Google software problem inadvertently exposed the names, addresses, email addresses and phone numbers used to register websites after people had chosen to keep the information private. . The privacy breach involves whois, a database that contains contact information for people who. The privacy breach involves whois, a database that contains contact information for people who. addresses, google, software, problem, inadvertently, exposed, names, email, phone. . LinuxSecurity.com Team
The parents of a 10-month-old baby in Ohio were left reeling when an unknown hacker took control of the infant. Heather and Adam Schreck were asleep at their home in Hebron, Cincinnati, when they heard a strange voice around midnight, FOX19 reported. The link for this article located at Independent UK is no longer available. . A family in Texas experienced a chilling scare when their smart thermostat was breached, resulting in an unsettling late-night event that left them rattled.. Baby Monitor Security, Hacked IoT Devices, Home Surveillance Safety. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.