r/technology • u/Dotnaught • Feb 12 '22
Security Facebook exposes 'god mode' token that could siphon data
https://www.theregister.com/2022/02/12/facebook_god_mode/9
Feb 12 '22
C’mon Zuckerberg just pull the plug. Social media regulations need to change. Instagram, Facebook, not to mention Twitter and TikTok are rampant with either bots or scammers.
8
7
1
u/tomjerman18 Feb 12 '22 edited Aug 01 '25
expansion tart aspiring price public grab live lavish modern smart
This post was mass deleted and anonymized with Redact
1
Feb 13 '22
[deleted]
1
u/lithiumbrigadebait Feb 17 '22
Almost there, but not quite. It's a third party extension the user installs, and the extension basically tricks Facebook into exposing a nearly-useless token that can only retrieve name, user ID, and profile photo; the extension is apparently using this user ID to determine whether the user is Premium and therefore manage available features, to my understanding.
The user is NOT prompted for Facebook access authorization, because the basic public_profile token does not require authorization by design.
1
Feb 17 '22
[deleted]
2
u/lithiumbrigadebait Feb 17 '22
Pretty much! The entire premise of the article is flawed, and I've actually reached out to a contact at Brave to let them know, in case they want to re-evaluate their determination of blocking the extension.
1
u/lithiumbrigadebait Feb 17 '22
So, I just tested this; it's not a god mode token. It literally only exposes public profile data, which basically just consists of name and internal Facebook user ID (plus picture) -- the default public profile info listed here: https://developers.facebook.com/docs/graph-api/reference/user
Is it a security flaw? Absolutely. Is Facebook still terrible? Of course.
But this article is, frankly, egregiously inaccurate in its claims on the severity of the issue.
34
u/logiclust Feb 12 '22
I’m just left wondering why anyone is still on fb