Facebook Monday announced it is expanding its bug bounty program to include vulnerabilities related to access token exposure.Tokens allow people to log into another app using Facebook and are uniquely generated for the specific person and app and the social media giant will now be offering at least $500 for vulnerabilities found in third-party apps and websites that involve improper exposure of these tokens, according to a September 17 blog post.facebook“If exposed, a token can potentially be misused, based on the permissions set by the user,” said Dan Gurfinkel, security engineering manager at Facebook, in the post. “We want researchers to have a clear channel to report these important issues, and we want to do our part to protect people’s information, even if the source of a bug is not in our direct control.”
Facebook said it will promptly suspend all apps that don’t comply and will also automatically revoke access tokens that could have been compromised to prevent potential misuse, and alert those we believe to be affected, as appropriate.The announcement comes roughly six months after news broke of the Cambridge Analytic scandal which prompted Facebook director Mark Zuckerburg to pledge to make changes and reforms to the firm’s policy to better protect user data.
There are many ways to do DevSecOps, and each organization — each security team, even — uses a different approach. Questions such as how many environments you have and the frequency of deployment of those environments are important in understanding how to integrate a security scanner into your DevSecOps machinery. The ultimate goal is speed […]
It’s Cybersecurity Awareness Month, but security awareness is about much more than just dedicating a month to a few activities. Security awareness is a journey, requiring motivation along the way. And culture. Especially culture.That’s the point Proofpoint Cybersecurity Evangelist Brian Reed drove home in a recent appearance on Business Security Weekly.“If your security awareness program […]