Skip to content
  • Friday, July 1, 2022
Blokland Prive Vakantiehuizen

Blokland Prive Vakantiehuizen

  • Home
  • Website checker
  • Website login
  • Website file
  • Website maker
  • Website Store
  • Privacy Policy
  • Terms and Conditions
  • Home
  • Website login
  • Security warning for Facebook users logging in with Gmail OAuth code
Website login

Security warning for Facebook users logging in with Gmail OAuth code

May 21, 2022
Sarah N. Randall

How do you log in to the services? Because a recently revealed Facebook exploit could change the way you do things in the future…

In a revealing blog post, security researcher Youssef Sammouda revealed that chaining Gmail’s OAuth authentication code with vulnerabilities in Facebook allowed it to hijack Facebook accounts when users logged in with their Gmail credentials.

Gmail has been


SOPA Images/LightRocket via Getty Images

Speaking to The Daily Swing, Sammouda explained that he was able to use redirects in Google OAuth and chain them together with elements of Facebook’s logout, checkpoint and sandbox systems to break into Accounts. He explained that although he demonstrated proof of concept with Gmail credentials, “it was possible to target all Facebook users”

Sammouda says Facebook paid him a “bug bounty” of $44,625 for his disclosure of the vulnerability in February. Facebook then patched it in March, although it was only made public this week.

And while he’s not directly responsible for the exploit, the fact that OAuth was chained to the Facebook vulnerability highlights this popular security standard and the additional risks it carries.

What is OAuth? The name derives from “Open Authorization” and it is an open standard adopted by many of the world’s largest technology companies, including Amazon, Microsoft, Twitter, Google and many more. Its calling card is convenient: It allows users to link their existing accounts with a major tech company to third-party sites for registration and use those credentials to log in. No new account is required.

And this is where the concerns arise. Commenting on Sammouda’s findings, security vendor Malwarebytes Labs issued a warning to anyone using linked accounts:

“Linked accounts were invented to make logging in easier,” writes Pieter Arntz, the company’s Malware Intelligence Researcher. “You can use an account to sign in to other apps, sites, and services… All you have to do to access the account is confirm that the account is yours.”

“We wouldn’t recommend it, because if someone gets the one password that controls them all, you’ll be in even more trouble than if a single site’s password were compromised,” he explains.

That’s it in a nutshell and OAuth is far from impenetrable. Here’s a how-to guide to exploiting vulnerabilities in OAuth authentication. All of this raises a serious convenience-security puzzle, and I’m leaning towards the safety side.

The good news is that it is possible to unlink accounts. In the case of Facebook, go to: Settings & Privacy > Settings > Account Center button > Accounts & Profiles. Similar dissociation processes may be used on other third-party sites.

___

Follow Gordon on Facebook

Learn more about Forbes

MORE FORBESGoogle reports (and fixes) 13 new Chrome vulnerabilitiesBy Gordon Kelly

Post navigation

2 former Mayo Clinic employees sue for wrongful termination
NECO Result Checker 2022 | www.result.neco.gov.ng

Categories

  • Website checker
  • Website file
  • Website login
  • Website maker
  • Website Store

asia pacific east africa email address forecast period growth rate market report market research market share market size middle east north america official website phone number press release united states

Recent Posts

  • Beginner’s Guide to Applying a Loan with the Controversial Lender: Citrus North

  • Complaint checker tool tells you how to fix your money problem as soon as possible

  • 5 impacts on the commercial waffle maker industry – Indian Defense News

  • Chrome Password Manager Update Brings New Design, Touch Login, and More

  • This Free Online File Converter Changed the Way I Work

  • Raspberry Pi Pico W projects to inspire your inner creator

Archives

  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • February 2021
  • December 2020

You may Missed

Website checker

Complaint checker tool tells you how to fix your money problem as soon as possible

July 1, 2022
Sarah N. Randall
Website maker

5 impacts on the commercial waffle maker industry – Indian Defense News

July 1, 2022
Sarah N. Randall
Website login

Chrome Password Manager Update Brings New Design, Touch Login, and More

July 1, 2022
Sarah N. Randall
Website file

This Free Online File Converter Changed the Way I Work

June 30, 2022
Sarah N. Randall
Copyright © 2022 Blokland Prive Vakantiehuizen
Privacy Policy