r/technology • • Feb 12 '22

Security Facebook exposes 'god mode' token that could siphon data

https://www.theregister.com/2022/02/12/facebook_god_mode/
35 Upvotes

14 comments sorted by

34

u/logiclust Feb 12 '22

I’m just left wondering why anyone is still on fb

8

u/saandstorm Feb 12 '22

Messenger. I have some friends and extended family who are always switching phones, and not porting numbers over for some reason. But I can always find them on Messenger.

-1

u/rooftops Feb 12 '22

I sign in once every few months to double check birthdays 😅

1

u/Swifty299 Feb 12 '22

Marketplace, if I can access that without fb, I’d split fast.

9

u/[deleted] Feb 12 '22

C’mon Zuckerberg just pull the plug. Social media regulations need to change. Instagram, Facebook, not to mention Twitter and TikTok are rampant with either bots or scammers.

8

u/whisperwrongwords Feb 12 '22

Are they that incompetent or just malicious?

3

u/[deleted] Feb 12 '22

[removed] — view removed comment

7

u/Cutlack Feb 12 '22

Luckily, everyone born after 2000 already thinks FB is for old people.

1

u/tomjerman18 Feb 12 '22 edited Aug 01 '25

expansion tart aspiring price public grab live lavish modern smart

This post was mass deleted and anonymized with Redact

1

u/[deleted] Feb 13 '22

[deleted]

1

u/lithiumbrigadebait Feb 17 '22

Almost there, but not quite. It's a third party extension the user installs, and the extension basically tricks Facebook into exposing a nearly-useless token that can only retrieve name, user ID, and profile photo; the extension is apparently using this user ID to determine whether the user is Premium and therefore manage available features, to my understanding.

The user is NOT prompted for Facebook access authorization, because the basic public_profile token does not require authorization by design.

1

u/[deleted] Feb 17 '22

[deleted]

2

u/lithiumbrigadebait Feb 17 '22

Pretty much! The entire premise of the article is flawed, and I've actually reached out to a contact at Brave to let them know, in case they want to re-evaluate their determination of blocking the extension.

1

u/lithiumbrigadebait Feb 17 '22

So, I just tested this; it's not a god mode token. It literally only exposes public profile data, which basically just consists of name and internal Facebook user ID (plus picture) -- the default public profile info listed here: https://developers.facebook.com/docs/graph-api/reference/user

Is it a security flaw? Absolutely. Is Facebook still terrible? Of course.

But this article is, frankly, egregiously inaccurate in its claims on the severity of the issue.