Skip to main content

Do you need to worry about that Facebook iOS security issue?

Probably not.

The “hacks” require the attacker to have physical access to your device (whether it be Android or iOS). That could be a speaker dock, a charging station, or a friend’s computer, but it still requires you to plug the iPhone into something compromised or give up physical access to it.

The issue, as Gareth Wright first discovered, is that Facebook stores saved account information in a plaintext file that can be transferred to another phone and used to log into your Facebook account without signing in. Other services, like Dropbox, were also shown to have the same vulnerability (but that is disputed).

This is why, when you restore a phone from a backup, you already have access to your Facebook app without having to sign-in again. Facebook attempted to dispel the concern by claiming that a phone would need to be compromised for this to work. That is untrue.

However, as we know, once someone with the right software has your iPhone, your information is pretty much his or hers to use.

The bigger issue here is the software that people use to access your data. It is free—and the process is very simple. I expect Facebook and Apple will probably make it more difficult in forthcoming updates.

Enhanced by Zemanta

FTC: We use income earning auto affiliate links. More.

You’re reading 9to5Mac — experts who break news about Apple and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Mac on Twitter, Facebook, and LinkedIn to stay in the loop. Don’t know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel