PCMag editors select and review products independently. If you buy through affiliate links, we may earn commissions, which help support our testing.

Are Facebook Apps 'Leaking' User Information?

 & Chloe Albanesius Executive Editor, News

Our team tests, rates, and reviews more than 1,500 products each year to help you make better buying decisions and get more from technology.

Our Expert
LOOK INSIDE PC LABS HOW WE TEST
65 EXPERTS
43 YEARS
41,500+ REVIEWS

A Tuesday report from Symantec said that, until recently, Facebook apps have inadvertently been leaking user data to third-party developers. In response, Facebook said the problem has been fixed and that no unauthorized Facebook data was shared with third parties.

In a blog post, Symantec's Nishant Doshi said that third-parties, mostly advertisers, have "accidentally" had access to Facebook user information like profiles, photographs, and chat.

"Fortunately, these third-parties may not have realized their ability to access this information," Doshi wrote. "[But] we estimate that as of April 2011, close to 100,000 applications were enabling this leakage. We estimate that over the years, hundreds of thousands of applications may have inadvertently leaked millions of access tokens to third parties."

Facebook said it worked with Symantec to rectify the issue, but took issue with how it characterized the situation.

"We've conducted a thorough investigation which revealed no evidence of this issue resulting in a user's private information being shared with unauthorized third parties," Facebook said in a statement. "In addition, this report ignores the contractual obligations of advertisers and developers which prohibit them from obtaining or sharing user information in a way that violates our policies."

At issue is the permissions-based app menu to which users must agree when installing an app. Facebook has been working to transition from a legacy Facebook authentication system and HTTP to the more secure OAuth 2.0. In the wake of the Symantec investigation, Facebook said Tuesday that it will require all sites and apps to migrate to OAuth 2.0 and obtain an SSL certificate by October 1.

If an app is still using that legacy Facebook authentication system and has certain parameters as part of its redirect code, however, "Facebook subsequently returns the access token by sending an HTTP request containing the access tokens in the URL to the application host," Doshi wrote. "The Facebook application is now in a position to inadvertently leak the access tokens to third parties potentially on purpose and unfortunately very commonly by accident."

Doshi said there was "no good way" to know how much data has leaked, but Facebook insisted no one has had access. Still concerned? Doshi suggested changing your password.

"Changing the password invalidates these tokens and is equivalent to 'changing the lock' on your Facebook profile," he wrote.

The concept of "leaky apps" on Facebook is not particular new. In October, the Wall Street Journal published a story that said Facebook apps shared users' personal information with advertising networks and other Internet-tracking companies. That included the top 10 apps on Facebook. That prompted Reps. Edward Markey and Joe Barton, the co-chairman of the House Bi-Partisan Privacy Caucus, to write to Facebook asking for more answers. The social-networking site later defended its policies, and denied that the revelations constituted a privacy breach.

About Our Expert

Chloe Albanesius

Chloe Albanesius

Executive Editor, News

My Experience

I started out covering tech policy in DC for The National Journal, where my beat included state-level tech news and all the congressional hearings and FCC meetings I could handle. I later covered Wall Street trading tech before switching gears to consumer tech. I now lead PCMag's news coverage.

My Areas of Expertise

Getting my start in DC means I still have a soft spot for tech policy; Congressional hearings can sometimes be as entertaining as a Bravo reality show, for better or worse. But PCMag is all about the technology we use every day, as well as keeping an eye out for the trends that will shape the industry in the years ahead (or flop on arrival). I've covered the rise of social media, the iOS vs. Android wars, the cord-cutting revolution that's now left us with hefty streaming bills, and the effort to stuff artificial intelligence into every product you could imagine. This job has taken me to CES in Vegas (one too many times), IFA in Berlin, and MWC in Barcelona. I also drove a Tesla 1,000 miles out west as part of our Best Mobile Networks project. Of late, my focus is on our hard-working team of reporters at PCMag, guiding and editing their robust coverage.

Read full bio