Facebook Applications Prove Insecure

Chris Soghoian has an interesting article about how a number of application developers are failing to protect against extremely basic security risks. For instance, a user can monitor all post and get requests (a system for passing data from a form which prompts users for information) coming from an application form and modify it prior to submitting the data to the application server.

The result is that hackers could theoretically spoof their identity. This is an issue that most websites are also vulnerable to. Not only are these applications vulnerable to potential spoofing attacks but occasionally they are at risk of typical SQL injection attacks. The experienced developer will build these protections into their scripts.

Given that many of these applications aren’t built by experienced developers though, there is an increasing risk that sensitive data gets manipulated. Personally, I think there are enough protections in place on Facebook’s end but the Surveillance State team is trying to paint a different picture.

I’m sure we will occasionally see an application get exploited but for the most part, Facebook has done a pretty good job in protecting against security risks.

 



Recommended Articles


Announcing The AllFacebook Marketing Conference 2012

The AllFacebook Marketing Conference is coming back to San Francisco on June 28-29. We are proud to announce our second conference that offers a how-to guide for marketing to Facebook’s 800 million users. Special early pricing is available for only $199 until today, so register now. A full agenda will be announced soon. Keep an eye on our event site for more information

5 Comments »

  1. All requests from fb pass a signature using a shared secret key. There is no way a hacker could generate this sig without knowing the secret key. The default libraries use this key to validate the user, so anyone simply following the example apps would have a pretty secure app.

    Comment by Tom — March 28, 2008 @ 6:45 am

  2. All requests from fb pass a signature using a shared secret key. There is no way a hacker could generate this sig without knowing the secret key. The default libraries use this key to validate the user, so anyone simply following the example apps would have a pretty secure app.

    Comment by Tom — March 28, 2008 @ 10:45 am

  3. Ha! I saw this coming five months ago. Scope this post….http://deftlabs.com/2007/10/facebook-applicatio…..

    Comment by Ryan — March 31, 2008 @ 3:49 am

  4. Ha! I saw this coming five months ago. Scope this post….

    http://deftlabs.com/2007/10/facebook-application-...

    Comment by Ryan — March 31, 2008 @ 4:49 am

  5. Actually,nothing is security absolutely in the network?while we

    only protect it as much as possible,such as firewall.

    Comment by evamagi — June 2, 2010 @ 8:41 pm

RSS feed for comments on this post. TrackBack URL

Leave a comment

Send us a Tip

tips@allfacebook.com
[Inside Social Apps 2012]
[AllFacebook Stats: Facebook Analytics for Your Business]
[How can Facebook change your business?]

Upcoming Events

Inside Social Apps

February 8-9, 2012 | San Francisco

Inside Social Apps

Developing & monetizing on social & mobile platforms

Social Gaming Summit

23-24 May, 2012 | Berlin

Social Gaming Summit

Where Gaming Meets the Social Web

AllFacebook Marketing Conference

June 28-29, 2012 | San Francisco

AllFacebook Marketing Conference

Your how-to guide for Facebook marketing.