Tuesday, November 10, 2009

Warning: Facebook Group Hacked

In Mashable Stan schroeder wrote
On Facebook, anyone can start a group. And the admin of a group controls various aspects of it: he can change its name, edit its info and picture or send messages to the members.

But when an admin leaves, anyone else can join the group and register as the new admin. From what we can gather, this behavior is WAI (working as intended), or at least it’s been that way for quite some time now. But it’s also an obvious design flaw, and now a group called Control Your Info is abusing it (or raising awareness about it, depending on how you look at it) by finding groups without admins and taking them over.

We’ve tried it out (on a group we own) and it works. Once an admin leaves, any FacebookFacebookFacebook user can join the group, take over, and do pretty much whatever he/she wants with it.

admin_stanNow, you may perceive this as normal behavior. After all, when an admin leaves, someone has to run the group, right? Wrong. There needs to be a mechanism that prevents abuse – for example, if you’re the leader of a clan in most MMO games, and you stop being leader, the leadership cannot be assumed by just any random player (it’s usually automatically transferred to the next in rank).

And there’s plenty of potential for abuse here. Let’s say that an admin of a popular group, with thousands of members, leaves Facebook. A malicious person can take over the leadership of the group (it’s relatively easy to find such groups by conducting a simple GoogleGoogleGoogle search) and change the name and the picture of the group into something offensive.

In a way, it’s good that Control Your Info is raising awareness about the issue, because Facebook needs to change the mechanism for transferring group leadership; I doubt, however, that taking over hundreds of Facebook groups is the right way to do it. In any case, if you’re a member of a Facebook group, be careful: you may find that the group has been taken over and changed into something you probably wouldn’t like to be a part of.






For more: http://controlyour.info/blog/aboutus

No comments:

Post a Comment