<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:series="http://unfoldingneurons.com/"
	
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>The Inquisitr &#187; Security Flaw</title>
	<atom:link href="http://www.inquisitr.com/tag/security-flaw/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.inquisitr.com</link>
	<description>The Better Mix</description>
	<lastBuildDate>Fri, 24 May 2013 17:41:13 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>Face.com Security Flaw Discovered After Facebook Acquisition</title>
		<link>http://www.inquisitr.com/259125/face-com-security-flaw-discovered-after-facebook-acquisition/</link>
		<comments>http://www.inquisitr.com/259125/face-com-security-flaw-discovered-after-facebook-acquisition/#comments</comments>
		<pubDate>Wed, 20 Jun 2012 15:38:49 +0000</pubDate>
		<dc:creator>James Johnson</dc:creator>
				<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Face]]></category>
		<category><![CDATA[Face Security Flaw]]></category>
		<category><![CDATA[face.com]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Facebook Acquisition]]></category>
		<category><![CDATA[Security Flaw]]></category>

		<guid isPermaLink="false">http://www.inquisitr.com/?p=259125</guid>
		<description><![CDATA[<br />Facebook spent upwards of $100 million to acquire Israel-based facial recognition firm Face.com on Monday and now a security flaw in the company&#8217;s software has been revealed. The flaw came in the form of Face.com&#8217;s mobile app KLIK which allows real-time face-tagging for Facebook pictures. According to researcher Ashkan Saltani the app would grant access [...]<p><a href="http://www.inquisitr.com/259125/face-com-security-flaw-discovered-after-facebook-acquisition/">Face.com Security Flaw Discovered After Facebook Acquisition</a> is a post from: <a href="http://www.inquisitr.com">The Inquisitr</a></p>
<br /><br /><br />]]></description>
				<content:encoded><![CDATA[<p><img class="aligncenter size-full wp-image-259141" title="Face com Facebook Flaw" src="http://www.inquisitr.com/wp-content/uploads/2012/06/Face-com-Facebook-Flaw-e1340206610456.jpg" alt="Face com Facebook Flaw" width="475" height="275" /></p>
<p>Facebook spent upwards of $100 million to acquire Israel-based facial recognition firm Face.com on Monday and now a security flaw in the company&#8217;s software has been revealed.</p>
<p>The flaw came in the form of Face.com&#8217;s mobile app KLIK which allows real-time face-tagging for Facebook pictures. According to researcher Ashkan Saltani the app would grant access to a users private authentication tokens for Facebook and Twitter accounts, allowing hackers to easily gain access to personal photos and other information.</p>
<p>On his personal blog Saltani revealed the flaw after he reported it to Face.com and the issue was fixed.</p>
<blockquote><p>TECHNICAL DETAILS: Face.com was storing Facebook/Twitter OAUTH tokens on their servers insecurely, allowing them to be queried for *any user* without restriction. Specifically, once a user signed up for KLIK, the app would store their Facebook tokens on Face.com’s server for ‘safe keeping’. Subsequent calls to  returns the Facebook “service_tokens” for any user, allowing the attacker to access photos and post as that user. If the KLIK user has linked their Twitter account to KLIK App (say, to ‘tweet’ their photos à la Instagram), their ‘service_secret’ and ‘service_token’ was also returned.</p></blockquote>
<p>The flaw highlights the exact reason users should be wary when it comes to granting Twitter and <a title="Facebook To Target Ads Based On Website Browsing History" href="http://www.inquisitr.com/258407/facebook-to-target-ads-based-on-website-browsing-history/">Facebook</a> access to third-party apps which in turn can gather certain permissions.</p>
<p>The security issue was so easy to spot that Soltani says he spotted it out of &#8220;the corner of my eye.&#8221;</p>
<p>Since the flaw was fixed before it was announced users accounts should be safe.</p>

<p><a href="http://www.inquisitr.com/259125/face-com-security-flaw-discovered-after-facebook-acquisition/">Face.com Security Flaw Discovered After Facebook Acquisition</a> is a post from: <a href="http://www.inquisitr.com">The Inquisitr</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.inquisitr.com/259125/face-com-security-flaw-discovered-after-facebook-acquisition/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:thumbnail url="http://www.inquisitr.com/wp-content/uploads/2012/06/Face-com-Facebook-Flaw-e1340206610456-100x100.jpg" />
		<media:content url="http://www.inquisitr.com/wp-content/uploads/2012/06/Face-com-Facebook-Flaw-e1340206610456.jpg" medium="image">
			<media:title type="html">Face com Facebook Flaw</media:title>
			<media:thumbnail url="http://www.inquisitr.com/wp-content/uploads/2012/06/Face-com-Facebook-Flaw-e1340206610456-100x100.jpg" />
		</media:content>
	</item>
		<item>
		<title>HTC Confirms Security Flaw, Says Fix Is On The Way</title>
		<link>http://www.inquisitr.com/147542/htc-confirms-security-flaw-says-fix-is-on-the-way/</link>
		<comments>http://www.inquisitr.com/147542/htc-confirms-security-flaw-says-fix-is-on-the-way/#comments</comments>
		<pubDate>Tue, 04 Oct 2011 08:43:49 +0000</pubDate>
		<dc:creator>James Johnson</dc:creator>
				<category><![CDATA[Mobile]]></category>
		<category><![CDATA[htc]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Flaw]]></category>
		<category><![CDATA[smartphones]]></category>

		<guid isPermaLink="false">http://www.inquisitr.com/?p=147542</guid>
		<description><![CDATA[<br />HTC on Tuesday confirmed that a security vulnerability exists on their Smartphones that allows any app requesting internet access to look at a users account information, GPS location, system logs and other potentially private data. The manufacturer assured customers that while their own software won&#8217;t harm user data they have warned that third party malware [...]<p><a href="http://www.inquisitr.com/147542/htc-confirms-security-flaw-says-fix-is-on-the-way/">HTC Confirms Security Flaw, Says Fix Is On The Way</a> is a post from: <a href="http://www.inquisitr.com">The Inquisitr</a></p>
<br /><br /><br />]]></description>
				<content:encoded><![CDATA[<p><img class="aligncenter size-full wp-image-147543" title="HTC Logo" src="http://www.inquisitr.com/wp-content/uploads/2011/10/HTC-Logo-e1317717733920.jpg" alt="HTC Logo" width="361" height="200" /></p>
<p>HTC on Tuesday confirmed that a security vulnerability exists on their Smartphones that allows any app requesting internet access to look at a users account information, GPS location, system logs and other potentially private data.</p>
<p>The manufacturer assured customers that while their own software won&#8217;t harm user data they have warned that third party malware could exploit the security flaw and cause information to be stolen.</p>
<p>HTC programmers are already building a patch for the flaw and they promise that an over-the-air patch update will arrive as soon as possible.</p>
<p>Here&#8217;s the official security statement from <a title="HTC to Apple: Try Competing Instead of Suing Everyone In Sight" href="http://www.inquisitr.com/125759/htc-to-apple-try-competing-instead-of-suing-everyone-in-sight/">HTC</a>:</p>
<blockquote><p>HTC takes claims related to the security of our products very seriously. In our ongoing investigation into this recent claim, we have concluded that while this HTC software itself does no harm to customers&#8217; data, there is a vulnerability that could potentially be exploited by a malicious third-party application. A third party malware app exploiting this or any other vulnerability would potentially be acting in violation of civil and criminal laws. So far, we have not learned of any customers being affected in this way and would like to prevent it by making sure all customers are aware of this potential vulnerability.</p>
<p>HTC is working very diligently to quickly release a security update that will resolve the issue on affected devices. Following a short testing period by our carrier partners, the patch will be sent over-the-air to customers, who will be notified to download and install it. We urge all users to install the update promptly. During this time, as always, we strongly urge customers to use caution when downloading, using, installing and updating applications from untrusted sources.</p></blockquote>
<p>Customers are urged to avoid non-trusted apps until the patch is made available and installed.</p>
<p><a href="http://www.inquisitr.com/147542/htc-confirms-security-flaw-says-fix-is-on-the-way/">HTC Confirms Security Flaw, Says Fix Is On The Way</a> is a post from: <a href="http://www.inquisitr.com">The Inquisitr</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.inquisitr.com/147542/htc-confirms-security-flaw-says-fix-is-on-the-way/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:thumbnail url="http://www.inquisitr.com/wp-content/uploads/2011/10/HTC-Logo-e1317717733920-100x100.jpg" />
		<media:content url="http://www.inquisitr.com/wp-content/uploads/2011/10/HTC-Logo-e1317717733920.jpg" medium="image">
			<media:title type="html">HTC Logo</media:title>
			<media:thumbnail url="http://www.inquisitr.com/wp-content/uploads/2011/10/HTC-Logo-e1317717733920-100x100.jpg" />
		</media:content>
	</item>
	</channel>
</rss>
