January 1, 2012
5199 days ago
Undisclosed
Confirmed
Hacking
Technology
A self-proclaimed security enthusiast has exposed a major flaw in Facebook, one in which nearly every user's phone number can be used to view their personal information. His name is Suriya Prakash, and his method of cultivating numbers involves using Facebook's mobile site to bypass security limits imposed on the social networking site's regular portal, or so he claims. Here's how he explains it. "About a month ago I was just browsing Facebook on my Facebook mobile application and it had an option called 'Find friends using contacts' -- what it does is that it compares the contact list from your phone to the Facebook database to see if you have any friends that are in your contacts but not on your Facebook account," Prakash told The Next Web. "I also later figured out that simply 'searching' a person's phone number (including country code) will show you their account." Prakash acknowledges that Facebook eventually blocked his script, but not before he was able to cultivate hundreds thousands of phone numbers. He also says he alerted Facebook about the vulnerability, but was ignored until his proof-of-concept started to receive media attention.