• On TechRepublic: 10 cool USB flash drive tricks
July 16, 2008 2:13 PM PDT

Facebook fixes hole that exposed birth dates

by Elinor Mills
  • Font size
  • Print
  • 1 comment
Share

Facebook said on Wednesday that it fixed a hole that exposed the birth dates of members during a public beta of a new design for profile pages earlier this week.

Security company Sophos alerted Facebook to the problem and is suggesting that Facebook users input fake birth dates instead of real ones to prevent any similar problems going forward because of the risks from identity fraud.

"My advice to Facebook users would be, even if your data of birth is set to be non-visible, change it to a made-up date in case this kind of blunder happens again," Graham Cluley, senior technology consultant at Sophos, said in a statement. "Facebook and other social-networking Web sites need to be more careful about protecting their members' data, or risk losing users."

A Facebook representative released this statement in response: "For a brief period of time, a small number of users were able to access a private beta of Facebook's new site design meant only for developers. During that time, some of those users had their birthdays revealed due to a bug. The problem was identified and promptly resolved."

Cluley goes into more detail on his company's blog.

And here's a YouTube video that illustrates the problem:


Facebook is scheduled to roll out the new profile page design to users this week.

In an identity theft-related study done last year, Sophos found that 41 percent of Facebook users, or more than two in five, were willing to reveal personal information to a complete stranger.

Late last month, the company suspended the Top Friends app after it was learned that the app was revealing profile data that users wanted to keep private.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
advertisement
Click Here
Recent posts from Security
PC Tools Internet Security 2010 reviewed
Google Chrome now bundled with Avast
Some Avast users must reinstall flagged files
Defense Dept. pulls software over privacy issues
Microsoft to plug critical IE hole targeted by exploit code
Google wants to unclog Net's DNS plumbing
Avast update falsely flags good apps as malware
Character limitations in passwords considered harmful
Add a Comment (Log in or register)
by Harrison912 July 17, 2008 10:22 AM PDT
I use FaceBook daily for socially marketing safety and security awareness as well as my products that will enhance it. Thank you for alerting me to this problem.

I'm glad to hear FaceBook has fixed the problem. Since safety and security are my business, I'm concerned about my security as well as that of my customers, who many of them are FaceBook account holders.
Reply to this comment
advertisement

The yogurt makers of tech: Gadgets to avoid

Don't buy these one-trick ponies--unless you like gizmos that gather dust.

Google wants to unclog Net's DNS plumbing

The Net giant, ever eager for a faster Internet, debuts its Google Public DNS service. With it, Google could become even more central to the Net.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right