Facebook myPersonality App Exposing its Sold Data on You

FrgMstr

Just Plain Mean
Staff member
Joined
May 18, 1997
Messages
55,596
I guess if you just leave all that personal data you collected for sale to others openly exposed on the web for years, you have to wonder how valuable it truly is. That said, the myPersonality Facebook app did actually scrub your name off before exposing your personal data online. Apparently someone working for the app shared some of the code on GitHub, and put working login credentials in the code as well that allowed access to the database, for four years.


Academics at the University of Cambridge distributed the data from the personality quiz app myPersonality to hundreds of researchers via a website with insufficient security provisions, which led to it being left vulnerable to access for four years. Gaining access illicitly was relatively easy.

The publicly available username and password were sitting on the code-sharing website GitHub. They had been passed from a university lecturer to some students for a course project on creating a tool for processing Facebook data. Uploading code to GitHub is very common in computer science as it allows others to reuse parts of your work, but the students included the working login credentials too.
 
This is what happens when non IT folks learn just enough coding skills to get done what they need done. Especially prevalent in the academic fields where paying for an real IT person has to be budgeted. "I don't need to hire an IT person and go through all of that University, State and Federal paperwork, I have a SQL and Javascript book and I sat in on Website Design 101 ten years ago!"
 
Don't hire college students straight from school to fill senior level positions? I always thought experience trumps education level every time. Maybe I'm just old school like that.
 
Hard coding the passwords, we weren't that dumb even in the 80's ;). This is just pathetic.
 
Hard coding the passwords, we weren't that dumb even in the 80's ;). This is just pathetic.

You may not have been that stupid in the 80s but I guarantee you there were plenty of people that were that stupid. It was just a whole lot less likely for anyone to care to report on it...
 
You may not have been that stupid in the 80s but I guarantee you there were plenty of people that were that stupid. It was just a whole lot less likely for anyone to care to report on it...
Hence my wink, yes I saw it done. Some things are never learned.
 
Back
Top