Bodybuilders expose Facebook's Zuckerburg to the world
By Tom Brewster,
A number of Mark Zuckerburg's private Facebook photos have been posted online after a flaw in the site was uncovered by users of a bodybuilding message forum.
Users were able to see private photos by exploiting a weakness in Facebook's reporting functions. Prior to Facebook addressing the issue, users could highlight a photo as inappropriate and then choose to include and view additional photos in the report, some of which could have been private.
Facebook needs to stop making mistakes when it comes to its members' privacy.
It took personal images of Zuckerburg, showing snippets from his personal life including an image of the social network's chief holding a dead chicken, for Facebook to fix the issue.
"In many ways it's good that Zuckerberg's account was targeted - if it such a high profile figure hadn't fallen victim, the flaw might have continued to have been exploited for much longer opening up opportunities for stalkers and others to view private photos," said Sophos chief technology consultant Graham Cluley, in a blog post.
"Facebook's programmers are experimenting with new features and are testing them out on the live site without, in this case at least, the code being properly reviewed with privacy in mind."
Facebook said the flaw was only live for a limited period of time and it was working on a permanent fix for the bug.
"Facebook needs to stop making mistakes when it comes to its members' privacy. Once users' trust is broken, it will be very hard to restore," Cluley added.
This is not the first time Facebook has found itself under the spotlight over photo privacy. In January, IT Pro found that by simply right clicking and selecting ‘copy image location’ on a photo, whether private or not, friends who had seen the picture could then paste the image URL to share it with unauthorised users, even those not on Facebook.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
What is your password worth?
Would you be tempted to sell off company passwords for a fee? If not, seems like you're in the minority, acccording to research.
- Macs under attack?
- Intel: security inside
- Are you spending too much on IT security?
- Does the government want to snoop on your data?
- Eurocrats versus the cyber criminals
- The truth about spam
- Google and privacy: What’s the problem?
- Q&A: Symantec’s CISO on the source code hack
- RSA: Back from the breach?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- UK regulator shuts down Angry Birds scam
- Apple iPad 3 vs iPad 2 head-to-head review
- IBM bans use of Siri on iPhones
- Chromebooks: What's gone wrong?
- HP plans massive job cuts
- EMC World 2012: Tucci declares Documentum is here to stay
- Dell EqualLogic PS6100XS review
- Macs and Android under malware threat
- RIM loses its head of sales
- Local fibre broadband needs common standards
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.






MISSPELLING
"Zuckerburg" is spelled Zuckerberg.
By alphaa10 on Sunday Dec 11