
These access tokens allow you to access an account even without giving your password.

The said attackers successfully took the Facebook access tokens for potentially 50 million users. Especially when you consider that most people use Facebook to log in to other websites and services. I don’t know about you, but the assurance given by Facebook just does not suffice. What was the Damage and How can you Protect yourself? The loophole was sealed by Facebook temporarily disabling the ‘View As’ feature check to see if it is back up, though I doubt it. But Facebook assures us that it has since sealed that security loophole, and by them logging you out and asking you to log back in, the matter should be resolved. The attackers apparently exploited a vulnerability on Facebook – the ‘View As’ feature that allows you to view your account as other users views it – and took over the accounts of some people. Whoever the attackers were, they managed to take over some Facebook users accounts. The social network had been attacked from the looks of things, the attack was successful. So I logged in as instructed, but at the top of my News Feed on the main Facebook app, there was a security alert from Facebook.Īpparently, whatever was happening to my account, was happening to potentially 50 million users across the globe. Facebook security system picked up the attempt and logged me out on all my devices. The first thing that came into my mind is that someone somewhere must have tried to log into my account.

The message that I got went something like, my session has expired, and I need to log back in.

To my surprise, I was logged out on Messenger and the main Facebook app. Early morning on Saturday, Sept 29, I took my phone, went online on Facebook to catch up with the day’s updates.
