Risk
7/3/2012
11:57 AM
50%
50%

Facebook To Fix Smartphone Email Snafu

Android and iOS users report some contacts are being forcibly updated to an "@facebook.com" email address.

5 Social Networks To Achieve 10 Business Tasks
5 Social Networks To Achieve 10 Business Tasks
(click image for larger view and for slideshow)
Have your smartphone contacts' email addresses been automatically updated to make their "@facebook.com" email addresses the new default? If so, you're not alone.

"Some smartphone users, particularly those using older Android devices, are reporting that their on-phone address books have been silently updated to make @facebook.com email addresses the default way to send a message to their contacts," said Graham Cluley, senior technology consultant at Sophos, Tuesday in a blog post.

Some iOS 6 beta testers have reported similar issues. "This is presumably because one of iOS 6's features is greater synchronization for the iPhone/iPad with Facebook," he said.

[ Despite its disappointing IPO, does Facebook have potential for future greatness? Read more at The Second Coming Of Facebook. ]

Related bug reports have been appearing recently on online forums. "This morning my mother was complaining that many of the email addresses in her Droid Razr contacts had been replaced with Facebook ones," read one such post to Hacker News. "It would seem the Facebook app had been populating her address book with emails and contact photos and decided to migrate all her Facebook-using contacts over to this convenient new system."

Tuesday, a Facebook spokeswoman confirmed that the social network is working on a fix for two problems--one involving synchronizing contacts on mobile devices, and another relating to Facebook Messaging.

In terms of contact synchronization, which is performed using an API, the spokeswoman said via email, "For most devices, we've verified that the API is working correctly and pulling the primary email address associated with the users' Facebook account. However, for people on certain devices, a bug meant that the device was pulling the last email address added to the account rather than the primary email address, resulting in @facebook.com addresses being pulled."

"We are in the process of fixing this issue and it will be resolved soon," she continued. "After that, those specific devices should pull the correct addresses."

Meanwhile, Facebook is also working to resolve a messaging-related issue that could result in people's Facebook messages going undelivered, without the sender receiving a notification that the message hadn't been delivered. "If someone sends you an email to your @facebook.com email address and it's from an address associated with a Facebook friend or friend of friend's accounts, it will go into the inbox," the Facebook spokeswoman said. "If it's from an address not associated with a friend or friend of friend's Facebook account, it will go into your other folder. However, if you've specified in privacy settings that you only want to receive messages from friends or friend of friends, then the message will bounce." "We've noticed that in a very limited number of cases, the bounce e-mail back to the original sender may not be delivered because it may get intercepted by spam filters," she said. "We are working to make sure that e-mail senders consistently receive bounce messages."

Pending fixes aside, Sophos' Cluley advised all Facebook users to review which of their email addresses the social network is currently listing, especially in the wake of Facebook recently changing all users' default email addresses to "@facebook.com" based on the URL of their public profile. "I would still strongly recommend checking that you are happy with what email addresses (if any) you are showing on your Facebook profile, and whether you want to sync your smartphone's address book with the site," he said.

New apps promise to inject social features across entire workflows, raising new problems for IT. In the new, all-digital Social Networking issue of InformationWeek, find out how companies are making social networking part of the way their employees work. Also in this issue: How to better manage your video data. (Free with registration.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
ANON1245867443530
50%
50%
ANON1245867443530,
User Rank: Apprentice
7/4/2012 | 2:38:26 AM
re: Facebook To Fix Smartphone Email Snafu
Yeah, that's what happens when you give personal data to inept bunglers like Facebook. This policy alone should've made it clear that we're dealing with amateur hour: http://goldmanosi.blogspot.com...
Register for Dark Reading Newsletters
Dark Reading Live EVENTS
INsecurity - For the Defenders of Enterprise Security
A Dark Reading Conference
While red team conferences focus primarily on new vulnerabilities and security researchers, INsecurity puts security execution, protection, and operations center stage. The primary speakers will be CISOs and leaders in security defense; the blue team will be the focus.
White Papers
Video
Cartoon Contest
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
Enterprises are spending more of their IT budgets on cybersecurity technology. How do your organization's security plans and strategies compare to what others are doing? Here's an in-depth look.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.