Facebook Now Confirms 30 Million Accounts Breached

Reports of Facebook data breach is not slowing down the Zuckerbergs train in any way, the social media  platform continues to add new users every minute and has seen his company’s quarterly earnings grow in the double digit regions year on year. But do us, as users of the service have to be seriously concerned about our data being hijacked or ‘viewed’ by strangers, even though we don’t pay for the services?

It’s this dilemma that gives Facebook all the smug to only release press statements and go on to mention that hacks into it’s system “is not as severe as initially thought” where earlier reports over the latest breach listed over 50 million accounts could have been compromised, the social giant claims only 30 million have been hijacked. So everything is okay now? As the saying goes if you’re not paying for the service than you’re probably the product, Facebook makes money (loads of it) off its users, by pushing advertisements and in the Cambridge incident even database. Just like most free-to-use apps, we the users become the commodity and our profile and behaviour is marketed to very interested parties. Why do you think the Lazada advertisement keeps popping-up on your Facebook page even after you have left their website?!

Does that mean we can be exploited, here’s where policy makers need to step up, these tech giants are impossible to take on, in the process of commercialisation morality and ethics are often overlooked. The company’s either have their own strict code of conduct on issues pertaining security and data protection or they don’t. There is no legal repercussion as users like you and me tick on all the ‘Allow’ boxes to use the service and waived presumably all our rights to the provider. And since the service is free they are outside the ambit of Consumer Protection acts. The onus is left to consumers to restrict these from having to much knowledge about us, but that will be easily dealt with by offering more free features that will get us hooked to the platform.

Here’s what Facebook said about the attacks:

First, the attackers already controlled a set of accounts, which were connected to Facebook friends. They used an automated technique to move from account to account so they could steal the access tokens of those friends, and for friends of those friends, and so on, totaling about 400,000 people. In the process, this technique automatically loaded those accounts’ Facebook profiles, mirroring what these 400,000 people would have seen when looking at their own profiles. That includes posts on their timelines, their lists of friends, Groups they are members of, and the names of recent Messenger conversations and even possibly the message content.

The attackers then used a portion of these 400,000 people’s lists of friends to steal access tokens for about 30 million people. For 15 million people, attackers accessed two sets of information – name and contact details (phone number, email, or both, depending on what people had on their profiles). For 14 million people, the attackers accessed the same two sets of information, as well as other details people had on their profiles. This included username, gender, locale/language, relationship status, religion, hometown, self-reported current city, birthdate, device types used to access Facebook, education, work, the last 10 places they checked into or were tagged in, website, people or Pages they follow, and the 15 most recent searches.

As you would realise the amount of information on You the attackers now have is frightening and not even your spouse or girlfriend could have so much detailed private info even if you speak in your sleep. It is grim and real. The likes of Facebook need to be taught a lesson for allowing such incidents from occurring and not play victim to attacks and seek for sympathy. Policy makers and governments should impose stricter guidelines on those who amass huge data of users and have them be transparent how they are stored and shared to others. Europe began with GDPR and this should be continually strengthened as these tech company will always find a way to circumvent around rules. After all they were thought to break them and disrupt the status quo.

Share this post:

Comment what you think!