WARNING: a flaw in the Facebook app can lead to identity theft
Anyone using the Facebook app iPhone OS should try to stay away from connections wi-fi public because it was discovered a serious security flaw that could give hackers access to their account ...
The security expert Gareth Wright has published an article on his blog yesterday, raising serious questions about how developers IOS handles your personal data stored (logins, etc). It seems that many applications do not use the proper safety measures to encrypt the data ...
Using the free tool iExplorer and a non-jailbroken iPhone , Wright is able to extract any type of account information from applications such as Facebook and Draw Something , which are stored in plain text in a plist file in " clear "...
"Addentrandomi Facebook application directory I immediately discovered a whole bunch of images in the cache and the com.Facebook.plist. What was shocking was contained inside. No key access token but all saved in plain text ... "
After sending the file plist to a friend, Wright has found that any stranger could have free access to your account, post photos or write messages on the bulletin board ...
In regard to this discovery Facebook said it is working to resolve the problem quickly, assuring users that the vulnerability only affects devices Android with iPhone OS and ROM modified with jailbreak. In fact, as demonstrated by Gareth Wright , the bug is also present on non-Jailbroken devices. For a hacker is very easy to create a malware or a program that extracts data from the file access plist .
But it was not Gehot to manage security Facebook ? Here Cat in the Cradle ...
No comments:
Post a Comment