• Hacking News
    • Defacement Hack
    • Data Breach
    • Credit Card Hacking
    • Smartphone Hacking
    • SCADA System Hacking
    • Password Cracking
    • Browser Security
  • Malware
    • Ransomware Malware
    • Banking Trojan
    • Malware/Virus
    • Botnet attack
    • Smartphone Malware
    • Stuxnet Worm
    • Cyber Espionage
  • Cyber Attack
    • DDoS Attack
    • Cyber Security
    • Malware/Virus
    • State Sponsored Hackers
    • Email/Gmail Hacking
    • Cyber Warfare
    • Cyber Espionage
  • Vulnerabilities
    • Vulnerability Disclosure
    • Zero-Day Vulnerability
    • Android Vulnerability
    • iPhone Vulnerability
    • SQL Injection
    • MITM Attack
    • XSS Vulnerability
    • Brute Force attack
  • Hacking Groups
    • Syrian Electronic Army
    • Anonymous Hacker
    • Chinese Hacker
    • Pakistani Hacker
    • Indian Hacker
    • Russian Hacker
    • Iranian Hacker
    • Israeli Hacker
  • NSA Spying
    • Edward Snowden
    • National Security Agency(NSA)
    • Online Privacy
    • Encryption Tools
    • Surveillance
    • Tor Anonymity Network
    • Bitcoin/Blockchain
Menu
The Hacker News

+1,440,800

180,200

443,500

Facebook Employees can Access your Account without Password

2015-02-27T21:39:00-11:00Friday, February 27, 2015 Swati Khandelwal

Facebook Employees can Access your Account without your Password
Do you know that your Facebook account can be accessed by Facebook engineers and that too without entering your account credentials? Recent details provided by the social network giant show who can access your Facebook account and when.

No doubt, Facebook and other big tech companies including Google, Apple and Yahoo! are trying to keep their data out of reach from law enforcement and spies agencies by adopting encrypted communication and end-to-end encryption solutions in near future, but right now they have access to your personal data, and at least few of their employees can access it with one click.

Earlier this week, director at the record label Anjunabeats, Paavo Siljamäki, brought attention to this issue by posting a very interesting story on his Facebook wall. During his visit to Facebook office in LA, a Facebook engineer logged into his Facebook account after his permission, but the strange part — they did it without asking him for the password.

ACCESS WITHOUT NOTIFICATION
Facebook even didn’t notify Siljamäki that someone else accessed his private Facebook profile, as the company does when your Facebook account is accessed from any new device or from a different Geo-location.

Siljamäki got in contact with Facebook in order to know how many of Facebook's staff have this kind of 'master' access to anyone's Facebook account and when exactly they can access users’ private data, and also, how would anyone know if his/her Facebook account has been accessed.

When the social network giant asked about how the employee got access to user’s Facebook account without entering the account credentials, Facebook issued the following statement:
"We have rigorous administrative, physical, and technical controls in place to restrict employee access to user data. Our controls have been evaluated by independent third parties and confirmed multiple times by the Irish Data Protection Commissioner’s Office as part of their audit of our practices."
WHO CAN ACCESS MY FACEBOOK ACCOUNT?
The company didn’t explain exactly who can access what, but it assured its users that the accounts access is tiered and limited to specific job function. The access to accounts are granted to most employees in order to reply to a customer request for information or error report.
"Designated employees may only access the amount of information that’s necessary to carry out their job responsibilities, such as responding to bug reports or account support inquiries," Facebook goes on explaining. "We have a zero tolerance approach to abuse, and improper behavior results in termination."
In short, the social network giant has a customer service tool that can grant Facebook employees access to a user’s account. Facebook runs two separate monitoring systems that generate weekly reports on suspicious behavior which are then reviewed and analyses by two independent security teams, specifically a selected group of employees.

Facebook gives a strict warning when hired employees to use this tool and fired any employee directly who abuse it. So, you need not to worry about Mark Zuckerberg accessing your account, unless you yourself ask Facebook for help with something and have given permission.

Subscribe to Quick News Updates

Account Manager

,

customer service

,

Facebook account hacking

,

Facebook account password

,

Hacking Facebook account

,

Mark Zuckerberg

,

social networking

Follow 'Swati Khandelwal' on Google+, Twitter or LinkedIn or Contact via Email.
The Hacker News
Latest Stories

Comments

AlienVault USM

Popular Stories

  • The Hacker News

    Windows? NO, Linux and Mac OS X Most Vulnerable Operating System In 2014

  • The Hacker News

    Lenovo Website has been Hacked

  • The Hacker News

    Facebook Employees can Access your Account without Password

  • The Hacker News

    Record-breaking 1Tbps Speed achieved Over 5G Mobile Connection

  • The Hacker News

    FBI Offers $3 Million Reward For Arrest Of Russian Hacker

  • The Hacker News

    Superfish-like Vulnerability Found in Over 12 More Apps

  • The Hacker News

    Tor Browser 4.0.4 Released

  • The Hacker News

    Onion.City — Search Engine for Deep Web that Works From Normal Web Browser

  • The Hacker News

    The Pirate Bay Goes Down Again and Again... and Then Once Again

  • The Hacker News

    Is It Possible to Track Smartphone Location By Monitoring Battery Usage?

LIKE Us on Facebook

About | THN Magazine |The Hackers Conference |Sitemap |Advertise on THN | Our Authors |Submit News |Privacy Policy | Contact