Hacker News new | ask | show | jobs
by Mithrandir 4972 days ago
Weird. I clicked on one of the links and it asked me if I was that user, and, if so, that I should click the login button. When I did, it logged me in as that user.

Edit: This happens for multiple users.

Edit2: It looks like if you click on the link, it automatically expires. bCODE is "an identifier that can be sent to a mobile phone/device and used as a ticket/voucher/identification or other type of token." I'm guessing somehow these tokens (the ones that auto log you in) never got used, plus the old ones were saved and contain email info. Not sure how Google could have gotten them though. Probably just got accidentally listed, despite robots.txt.

3 comments

One of the links redirected me to:

https://www.facebook.com/autologin.php?bcode=csVZIlpL_1.1351...

Which just says "Please try again later." but is probably part of the auto login path you discovered.

It's not an accident. You can even get fake urls indexed

http://www.seomofo.com/experiments/spam-search-results.html

It's really weird.
how? I am unable to replicate this bug