• Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
What's Hot

56 Days season 1 review: It felt like 56 days passed watching this show

February 17, 2026

10 Apple Tech Myths to Stop Believing in 2026

February 16, 2026

Leep Ring review: A sleep-first smart ring

February 16, 2026
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
Behind The ScreenBehind The Screen
Home»Security»Meta’s Account Center came with a 2FA-defeating bug
Security

Meta’s Account Center came with a 2FA-defeating bug

February 2, 2023No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Meta’s Account Center came with a 2FA-defeating bug
Share
Facebook Twitter LinkedIn Pinterest Email

Meta’s Accounts Middle characteristic had a bug that allow hackers brute drive SMS two-factor authentication, permitting them to bypass the extra safety (via TechCrunch). The vulnerability, which Meta says it fixed in December, was reported by Nepalese safety researcher Gtm Mänôz, who detailed the exploit in a Medium post earlier this month.

It was a big discover, as Meta appears to be placing an increasing number of give attention to its Accounts Middle characteristic, letting you handle settings and safety data from it, in addition to use it to modify to your different accounts. In accordance with Mänôz, the assault was comparatively easy; should you knew the cellphone quantity the opposite particular person used for two-factor authentication, you may hyperlink it to your individual account, which might take away it from the sufferer’s.

The factor that’s supposed to stop this can be a six-digit authentication code that will get despatched to the opposite particular person’s account or cellphone quantity, which you don’t have entry to. (For those who did, you wouldn’t want an exploit.) The bug Mänôz discovered, nevertheless, let an attacker guess that code nevertheless many occasions they wished — set a program or script to try this job, and it will ultimately guess proper.

Within the worst-case state of affairs (the strategy had completely different results based mostly on whether or not the particular person had totally or partially confirmed their contact information), this is able to completely flip off 2FA on the sufferer’s account. The truth that it was operating by Account Middle additionally defeated another safety measures; based on Mänôz’s submit, Fb wouldn’t normally allow you to add an already-registered e mail handle to your account, however this methodology bypassed that.

See also  US: Your AI has to explain its decisions

Meta appears to have mounted the difficulty comparatively rapidly. Mänôz reported it on September 14th, 2022, and it was handled by mid-October after the corporate’s safety staff really found out find out how to check it. (In accordance with Mänôz, the Accounts Middle hadn’t rolled out for the staff’s accounts, and it disappeared from Mänôz’s account after he gave them the credentials so they may check with it.) Meta ended up paying Mänôz a $27,200 bug bounty for reporting the difficulty. Meta wouldn’t present an on-the-record assertion concerning the bug’s affect, however spokesperson Gabby Curtis told TechCrunch that it was caught throughout a small public check, and that there didn’t seem like proof that it was exploited earlier than being mounted.

Correction January thirtieth, 3:50 PM ET: A earlier model of this text acknowledged the bug affected email-based two-factor authentication, however Meta spokesperson Gabby Curtis says it solely impacted SMS-based 2FA. We remorse the error.

Replace January thirtieth, 3:50 PM ET: Up to date to notice the bug doesn’t seem to have been exploited.

Source link

2FAdefeating account bug Center Metas
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Master These New iPhone Control Center Features in iOS 18.5

May 30, 2025

Secure Your iCloud Account After Big Password Leak

May 22, 2025

Gemini app on iPhone adds Control Center, lockscreen widgets

March 3, 2025

Bug in macOS and iOS updates re-enables Apple Intelligence for some refuseniks

February 11, 2025
Add A Comment

Comments are closed.

Editors Picks

Sweden and GDPR – four years on

July 9, 2022

Dubai-based Stake raises $8 million to let people across the globe invest in local properties – DailyTech

August 30, 2022

Fourth year rise in students sitting A-level computing

August 18, 2022

‘Siri Natural Language Generation’ Framework to Give Siri a Needed Boost

March 17, 2023

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

56 Days season 1 review: It felt like 56 days passed watching this show

10 Apple Tech Myths to Stop Believing in 2026

Leep Ring review: A sleep-first smart ring

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 behindthescreen.fr - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.