Risk
7/3/2012
11:57 AM
50%
50%

Facebook To Fix Smartphone Email Snafu

Android and iOS users report some contacts are being forcibly updated to an "@facebook.com" email address.

5 Social Networks To Achieve 10 Business Tasks
5 Social Networks To Achieve 10 Business Tasks
(click image for larger view and for slideshow)
Have your smartphone contacts' email addresses been automatically updated to make their "@facebook.com" email addresses the new default? If so, you're not alone.

"Some smartphone users, particularly those using older Android devices, are reporting that their on-phone address books have been silently updated to make @facebook.com email addresses the default way to send a message to their contacts," said Graham Cluley, senior technology consultant at Sophos, Tuesday in a blog post.

Some iOS 6 beta testers have reported similar issues. "This is presumably because one of iOS 6's features is greater synchronization for the iPhone/iPad with Facebook," he said.

[ Despite its disappointing IPO, does Facebook have potential for future greatness? Read more at The Second Coming Of Facebook. ]

Related bug reports have been appearing recently on online forums. "This morning my mother was complaining that many of the email addresses in her Droid Razr contacts had been replaced with Facebook ones," read one such post to Hacker News. "It would seem the Facebook app had been populating her address book with emails and contact photos and decided to migrate all her Facebook-using contacts over to this convenient new system."

Tuesday, a Facebook spokeswoman confirmed that the social network is working on a fix for two problems--one involving synchronizing contacts on mobile devices, and another relating to Facebook Messaging.

In terms of contact synchronization, which is performed using an API, the spokeswoman said via email, "For most devices, we've verified that the API is working correctly and pulling the primary email address associated with the users' Facebook account. However, for people on certain devices, a bug meant that the device was pulling the last email address added to the account rather than the primary email address, resulting in @facebook.com addresses being pulled."

"We are in the process of fixing this issue and it will be resolved soon," she continued. "After that, those specific devices should pull the correct addresses."

Meanwhile, Facebook is also working to resolve a messaging-related issue that could result in people's Facebook messages going undelivered, without the sender receiving a notification that the message hadn't been delivered. "If someone sends you an email to your @facebook.com email address and it's from an address associated with a Facebook friend or friend of friend's accounts, it will go into the inbox," the Facebook spokeswoman said. "If it's from an address not associated with a friend or friend of friend's Facebook account, it will go into your other folder. However, if you've specified in privacy settings that you only want to receive messages from friends or friend of friends, then the message will bounce." "We've noticed that in a very limited number of cases, the bounce e-mail back to the original sender may not be delivered because it may get intercepted by spam filters," she said. "We are working to make sure that e-mail senders consistently receive bounce messages."

Pending fixes aside, Sophos' Cluley advised all Facebook users to review which of their email addresses the social network is currently listing, especially in the wake of Facebook recently changing all users' default email addresses to "@facebook.com" based on the URL of their public profile. "I would still strongly recommend checking that you are happy with what email addresses (if any) you are showing on your Facebook profile, and whether you want to sync your smartphone's address book with the site," he said.

New apps promise to inject social features across entire workflows, raising new problems for IT. In the new, all-digital Social Networking issue of InformationWeek, find out how companies are making social networking part of the way their employees work. Also in this issue: How to better manage your video data. (Free with registration.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
ANON1245867443530
50%
50%
ANON1245867443530,
User Rank: Apprentice
7/4/2012 | 2:38:26 AM
re: Facebook To Fix Smartphone Email Snafu
Yeah, that's what happens when you give personal data to inept bunglers like Facebook. This policy alone should've made it clear that we're dealing with amateur hour: http://goldmanosi.blogspot.com...
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4807
Published: 2014-11-22
Sterling Order Management in IBM Sterling Selling and Fulfillment Suite 9.3.0 before FP8 allows remote authenticated users to cause a denial of service (CPU consumption) via a '\0' character.

CVE-2014-6183
Published: 2014-11-22
IBM Security Network Protection 5.1 before 5.1.0.0 FP13, 5.1.1 before 5.1.1.0 FP8, 5.1.2 before 5.1.2.0 FP9, 5.1.2.1 before FP5, 5.2 before 5.2.0.0 FP5, and 5.3 before 5.3.0.0 FP1 on XGS devices allows remote authenticated users to execute arbitrary commands via unspecified vectors.

CVE-2014-5395
Published: 2014-11-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R007B100D03SP01C03, E5180s-22 before 21.270.21.00.00, and E586Bs-2 before 21.322.10.00.889 allow remote attackers to hijack the authentication of users ...

CVE-2014-7137
Published: 2014-11-21
Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM before 3.6.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) contactid parameter in an addcontact action, (2) ligne parameter in a swapstatut action, or (3) project_ref parameter to projet/tasks/contact.php; (4...

CVE-2014-7871
Published: 2014-11-21
SQL injection vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev36 and 7.6.x before 7.6.0-rev23 allows remote authenticated users to execute arbitrary SQL commands via a crafted jslob API call.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?