Meta Doesn’t Want Your Data to End up in Hacker Databases ?
Meta Doesn’t Want Your Data to End up in Hacker Databases ?
Would it surprise you to know that automated programs sweep social media platforms like Facebook to harvest any publicly accessible information and collate them inside databases? Individual pieces of information might not be of much use, but together they can enable hackers to perpetrate all kinds of digital crimes, such as credential thefts and phishing attacks. And Meta has had enough of it.
http://sagasimono.squares.net/posts/view/257#comment_335712
While the social network itself takes steps to catch and curtail these automated programs called scrapers, the platform has now decided to enlist the help of independent security researchers by expanding its bug bounty programs. Its goal is to not just fix the bugs that leak such details about its users but also to help find such databases that hold scraped information.
http://sagasimono.squares.net/posts/view/104#comment_336604
"The bug bounty program will help fill the gaps in Facebook's defenses against scraping and alert Meta to scraped databases that surface on the web," Paul Bischoff, privacy advocate and editor of Infosec research outlet Comparitech, told Lifewire over email.
http://sagasimono.squares.net/posts/view/259#comment_336616
The Scraping Menace
Meta referred to scraping as an "internet-wide challenge" as it announced the expansion of its bug bounty program, which was initially designed to find software glitches in the code that powers the platform.
http://sagasimono.squares.net/posts/view/39#comment_336643
According to Bischoff, many platforms have outlawed the use of scrapers, even for the information they hold that's publicly accessible. That's because personally identifiable information (PII), such as usernames, birthdates, email addresses, and location, are often used by bad actors to target users in elaborate social engineering campaigns.
http://sagasimono.squares.net/posts/view/221#comment_336654
"The bug bounty program will help fill the gaps in Facebook's defenses against scraping and alert Meta to scraped databases... "
However, Bischoff adds that Facebook has struggled to distinguish between scrapers and legitimate users, which has resulted in huge data leaks in the past. He specifically points to the leak that surfaced in March 2020 when Comparitech teamed up with security researcher Bob Diachenko, and discovered a database that contained the user IDs and phone numbers of over 300 million Facebook users.
http://sagasimono.squares.net/posts/view/84#comment_336667
But scraping isn't outright illegal—at best it exists in a techno-legal gray area since it does have legitimate uses as well.
http://sagasimono.squares.net/posts/view/186#comment_336680
"Even though scraping is against Facebook's terms of use, it's not strictly illegal. Some scraping operations are malicious, but others are academic, or journalistic," clarified Bischoff.
http://sagasimono.squares.net/posts/view/233#comment_336692
Wanted DOA
In its announcement of the expansion of the bug bounty program, Facebook mentioned that since its inception, the bug bounty initiative had awarded over 800 bounties, totaling over $2.3 million to researchers from more than 46 countries. Tackling "new challenges" such as scraping was a natural extension of the program.
http://sagasimono.squares.net/posts/view/56#comment_336701
"Even though scraping is against Facebook’s terms of use, it's not strictly illegal."
According to Meta, the expanded bug bounty program will reward security researchers on two fronts.
http://sagasimono.squares.net/posts/view/156#comment_336712
One, as part of its larger security strategy to make scraping harder and "more costly" for threat actors, Meta will award reports about bugs in its platform that bad actors can exploit to bypass the barriers it's erected to dissuade scraping.
http://sagasimono.squares.net/posts/view/219#comment_336721
Secondly, the platform said it'll also award data bounty hunters who inform it about unprotected databases available online that contain the scraped PII of at least 100,000 unique Facebook users.
http://sagasimono.squares.net/posts/view/282#comment_336732
"If we confirm that user PII was scraped and is now available online on a non-Meta site, we will work to take appropriate measures, which may include working with the relevant entity to remove the dataset or seeking legal means to help ensure the issue is addressed," Meta noted in the announcement.
http://sagasimono.squares.net/posts/view/131#comment_336775
It added that if the scrape was because of a misconfiguration in the application of an external developer, the platform would work with the developer to plug the leak. On the other hand, it'll also make efforts to ensure that the hosting service where the hackers have housed the scraped database takes it down.
http://tattoo.freepage.cz/forum/
The rewards for the scraping bounties start at $500, and while the scraping bugs entail monetary payouts, information about scraped databases will be awarded in the form of charity donations to nonprofit organizations of the reporters' choosing.
https://p106906.typo3server.info/45.0.html?&L=999999.9%2F
"To the best of our knowledge, this is the first scraping bug bounty program in the industry," Meta summed up. "We will work to address feedback from our top bounty hunters before expanding the scope to a greater audience."
https://p106906.typo3server.info/45.0.html?&L=1%2F&cHash=a11ea8b032
Meta Wants Your Help Perfecting Its Animation AI
Meta has introduced a new artificial intelligence (AI) technology that turns your drawings into animations.
CEO Mark Zuckerberg posted on his Facebook page on Thursday about the new technology created for the metaverse, which can take simple drawings and give them life.
https://p106906.typo3server.info/45.0.html?&L=1%2F&cHash=a11ea8b032
"Meta AI researchers built a tool that lets you animate kids' drawings, so I tested it out with a sketch my daughter made," he said. "AI advancements can be used in storytelling and world-building tools—and in the future, they'll unlock new experiences and make creative expression in the metaverse as effortless as social posts today."
https://p106906.typo3server.info/45.0.html?&cHash=5e39f634d6
You can even upload your own drawing on a website and play around with it to make it move in various ways. Afterward, you can share the animations generated from the website to your Facebook page and other social media platforms.
https://p106906.typo3server.info/45.0.html?&cHash=af0d2a198a
The technology is great for any drawings your kids may have created to make them literally come to life. Keep in mind that the only drawings that will work with the AI are drawings of one character with a body, and it has to be on a white piece of paper.
However, it's important to note that the website's primary purpose is not solely for fun but to further Meta's research into this new AI. Therefore, before you upload your photo, you must agree to Meta's Terms and Conditions, which lays out what they will do with your drawings.
"In particular, we would like to use for research purposes the drawings that you've uploaded to the Demo ("Materials")," the terms state, "and any modifications or adjustments made by you using the tools and functionalities made available to you in connection with the Demo ("Modifications"), but first we'd like to make sure you're okay with how we'll use it for such purposes."