Risk
7/3/2012
11:57 AM
Connect Directly
RSS
E-Mail
50%
50%

Facebook To Fix Smartphone Email Snafu

Android and iOS users report some contacts are being forcibly updated to an "@facebook.com" email address.

5 Social Networks To Achieve 10 Business Tasks
5 Social Networks To Achieve 10 Business Tasks
(click image for larger view and for slideshow)
Have your smartphone contacts' email addresses been automatically updated to make their "@facebook.com" email addresses the new default? If so, you're not alone.

"Some smartphone users, particularly those using older Android devices, are reporting that their on-phone address books have been silently updated to make @facebook.com email addresses the default way to send a message to their contacts," said Graham Cluley, senior technology consultant at Sophos, Tuesday in a blog post.

Some iOS 6 beta testers have reported similar issues. "This is presumably because one of iOS 6's features is greater synchronization for the iPhone/iPad with Facebook," he said.

[ Despite its disappointing IPO, does Facebook have potential for future greatness? Read more at The Second Coming Of Facebook. ]

Related bug reports have been appearing recently on online forums. "This morning my mother was complaining that many of the email addresses in her Droid Razr contacts had been replaced with Facebook ones," read one such post to Hacker News. "It would seem the Facebook app had been populating her address book with emails and contact photos and decided to migrate all her Facebook-using contacts over to this convenient new system."

Tuesday, a Facebook spokeswoman confirmed that the social network is working on a fix for two problems--one involving synchronizing contacts on mobile devices, and another relating to Facebook Messaging.

In terms of contact synchronization, which is performed using an API, the spokeswoman said via email, "For most devices, we've verified that the API is working correctly and pulling the primary email address associated with the users' Facebook account. However, for people on certain devices, a bug meant that the device was pulling the last email address added to the account rather than the primary email address, resulting in @facebook.com addresses being pulled."

"We are in the process of fixing this issue and it will be resolved soon," she continued. "After that, those specific devices should pull the correct addresses."

Meanwhile, Facebook is also working to resolve a messaging-related issue that could result in people's Facebook messages going undelivered, without the sender receiving a notification that the message hadn't been delivered. "If someone sends you an email to your @facebook.com email address and it's from an address associated with a Facebook friend or friend of friend's accounts, it will go into the inbox," the Facebook spokeswoman said. "If it's from an address not associated with a friend or friend of friend's Facebook account, it will go into your other folder. However, if you've specified in privacy settings that you only want to receive messages from friends or friend of friends, then the message will bounce." "We've noticed that in a very limited number of cases, the bounce e-mail back to the original sender may not be delivered because it may get intercepted by spam filters," she said. "We are working to make sure that e-mail senders consistently receive bounce messages."

Pending fixes aside, Sophos' Cluley advised all Facebook users to review which of their email addresses the social network is currently listing, especially in the wake of Facebook recently changing all users' default email addresses to "@facebook.com" based on the URL of their public profile. "I would still strongly recommend checking that you are happy with what email addresses (if any) you are showing on your Facebook profile, and whether you want to sync your smartphone's address book with the site," he said.

New apps promise to inject social features across entire workflows, raising new problems for IT. In the new, all-digital Social Networking issue of InformationWeek, find out how companies are making social networking part of the way their employees work. Also in this issue: How to better manage your video data. (Free with registration.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
ANON1245867443530
50%
50%
ANON1245867443530,
User Rank: Apprentice
7/4/2012 | 2:38:26 AM
re: Facebook To Fix Smartphone Email Snafu
Yeah, that's what happens when you give personal data to inept bunglers like Facebook. This policy alone should've made it clear that we're dealing with amateur hour: http://goldmanosi.blogspot.com...
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6306
Published: 2014-08-22
Unspecified vulnerability on IBM Power 7 Systems 740 before 740.70 01Ax740_121, 760 before 760.40 Ax760_078, and 770 before 770.30 01Ax770_062 allows local users to gain Service Processor privileges via unknown vectors.

CVE-2014-0232
Published: 2014-08-22
Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a (1)...

CVE-2014-3525
Published: 2014-08-22
Unspecified vulnerability in Apache Traffic Server 4.2.1.1 and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.

CVE-2014-3563
Published: 2014-08-22
Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified impact via vectors related to temporary file creation in (1) seed.py, (2) salt-ssh, or (3) salt-cloud.

CVE-2014-3587
Published: 2014-08-22
Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists bec...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Three interviews on critical embedded systems and security, recorded at Black Hat 2014 in Las Vegas.