Skip to main content

Facebook pays $15,000 bounty to close bug that can access any user’s account

facebook jobs tab woman using
A major flaw in Facebook’s account security has been brought to light by a security researcher, who has received a cool $15,000 payout from the social network for his efforts.

Anand Prakash spotted the flaw, which allowed him access to any user’s account on the platform, last month. The bug was related to the Facebook account reset process, which results in the site sending a six-digit PIN to a user’s phone to be used as a temporary password.

Usually, the individual resetting an account is granted approximately 10-12 wrong password guesses. Prakash noticed that those security measures were missing from the Facebook beta site for developers, where every single user account is also readily available. Consequently, the bug allowed Prakash to seemingly flood the site with PIN guesses, and hack into any account he wanted.

Instead of exploiting the flaw, however, Prakash notified Facebook through its report vulnerability page. The following day, the social network confirmed that the bug occurred due to a change to the beta page a few days earlier. Although Facebook assures that the flaw was not misused in that time frame, it still felt compelled to pay the $15,000 bug bounty to Prakash.

The resulting award and Facebook’s rapid response in stamping out the bug hints at the major risk involved. It may not have been the most complicated security issue, but it could have resulted in complete chaos if utilized through the site’s main page.

“One of the most valuable benefits of bug bounty programs is the ability to find problems even before they reach production,” Facebook said in a statement to The Verge. “We’re happy to recognize and reward Anand for his excellent report.”

Since its inception, Facebook’s bug bounty program has forked out over $4 million to hackers and security researchers for responsibly disclosing issues in its system.

Saqib Shah
Former Digital Trends Contributor
Saqib Shah is a Twitter addict and film fan with an obsessive interest in pop culture trends. In his spare time he can be…
Twitter CEO claims platform had best day last week
A stylized composite of the Twitter logo.

Twitter CEO Linda Yaccarino tweeted on Monday that despite the current fuss over Meta’s new and very similar Threads app, Twitter had its largest usage day last week.

Subtly including the name of Meta’s new app, which launched to great fanfare last Wednesday, Yaccarino did her best to sing Twitter’s praises, tweeting: “Don’t want to leave you hanging by a thread … but Twitter, you really outdid yourselves! Last week we had our largest usage day since February. There’s only ONE Twitter. You know it. I know it.”

Read more
Meta brings cartoon avatars to video calls on Instagram and Messenger
Meta's cartoon avatars for Instagram and Messenger.

The pandemic was supposed to have made us all comfortable with video calls, but many folks still don’t particularly enjoy the process.

Having to think about what to wear, or how our hair looks, or even fretting about puffy eyes following another bout of hay fever can sometimes be a bit much, even more so if it’s an early-morning call and your brain is still in bed.

Read more
Twitter is now giving money to some of its creators
A lot of white Twitter logos against a blue background.

Some Twitter users are now earning money via ads in the replies to their tweets.

New Twitter owner Elon Musk announced the revenue-sharing program in February, and on Thursday some of those involved have been sharing details of their first payments.

Read more