Skip to main content
  1. Home
  2. Social Media
  3. News

Facebook pays $15,000 bounty to close bug that can access any user’s account

Add as a preferred source on Google

A major flaw in Facebook’s account security has been brought to light by a security researcher, who has received a cool $15,000 payout from the social network for his efforts.

Anand Prakash spotted the flaw, which allowed him access to any user’s account on the platform, last month. The bug was related to the Facebook account reset process, which results in the site sending a six-digit PIN to a user’s phone to be used as a temporary password.

Recommended Videos

Usually, the individual resetting an account is granted approximately 10-12 wrong password guesses. Prakash noticed that those security measures were missing from the Facebook beta site for developers, where every single user account is also readily available. Consequently, the bug allowed Prakash to seemingly flood the site with PIN guesses, and hack into any account he wanted.

Instead of exploiting the flaw, however, Prakash notified Facebook through its report vulnerability page. The following day, the social network confirmed that the bug occurred due to a change to the beta page a few days earlier. Although Facebook assures that the flaw was not misused in that time frame, it still felt compelled to pay the $15,000 bug bounty to Prakash.

The resulting award and Facebook’s rapid response in stamping out the bug hints at the major risk involved. It may not have been the most complicated security issue, but it could have resulted in complete chaos if utilized through the site’s main page.

“One of the most valuable benefits of bug bounty programs is the ability to find problems even before they reach production,” Facebook said in a statement to The Verge. “We’re happy to recognize and reward Anand for his excellent report.”

Since its inception, Facebook’s bug bounty program has forked out over $4 million to hackers and security researchers for responsibly disclosing issues in its system.

Saqib Shah
Saqib Shah is a Twitter addict and film fan with an obsessive interest in pop culture trends. In his spare time he can be…
Instagram is finally giving your old posts a soundtrack do-over
Instagram lets creators refresh old posts without nuking their engagement
Opening settings in Instagram

Instagram is rolling out a Replace Audio feature that lets users change the in-app music attached to feed posts and carousels after they have already been published. The original post stays live throughout the process, preserving its likes, comments, and shares.

Your post keeps all its engagement

Read more
X finally rebuilt its neglected Android app, and it only took a year
X’s Android app was so rough, the company rebuilt the whole thing
X Android app gets a complete overhaul

Android users have spent years receiving the rougher version of X. Now, the company has finally decided that patching the old app was no longer enough. X has released a completely rebuilt Android app following nearly a year of development. Existing users can access it by installing the latest update through the Google Play Store, so there is no separate replacement app to download.

X tore the old foundation out

Read more
New X phishing scam uses fake login alerts to steal your account
Scammers have copied X's own security emails almost pixel for pixel, and people are falling for it.
X app store listing on iPhone

You open your inbox and see an alert claiming someone just logged into your X account from an unfamiliar device. Your first instinct is to click through and lock things down immediately. That instinct is exactly what a new phishing scam is counting on.

As reported by The Guardian, a wave of fake X security emails is currently doing the rounds. They claim a new device has logged into your account and urge you to click a link to reset your password or review app access. 

Read more