|
My name is Matt Jones, and I work on the Facbook security team that looked into this tonight. We only send these URLs to the email address of the account owner for their ease of use and never make them publicly available. Even then we put protection in place to reduce the likelihood that anyone else could click through to the account. For a search engine to come across these links, the content of the emails would need to have been posted online (e.g. via throwaway email sites, as someone pointed out - or people whose email addresses go to email lists with online archives). As jpadvo surmised, the nonces expire after a period of time. They also only work for certain users, and even then we run additional security checks to make sure it looks like the account owner who's logging in. Regardless, due to some of these links being disclosed, we've turned the feature off until we can better ensure its security for users whose email contents are publicly visible. We are also securing the accounts of anyone who recently logged in through this flow. In the future if you run into something that looks like a security problem with Facebook, feel free to disclose it responsibly through our whitehat program: https://www.facebook.com/whitehat. That way, in addition to making some money, you can avoid a bunch of script kiddies exploiting whatever the issue is that you've found. |
https://www.google.com/search?q=%22wants+to+be+friends+on+Fa...
And you'll find at the time of writing 250.000 more results where the "wants to be friends" email with the auto-login link is posted on blogs. Many of these blogs are also hacked, in that they redirect you to Russian dating sites if you visit the homepage.
An example of such a blog with password reset email is: http://papajimummyji.blogspot.com/
An example of a spam-redirecting blog is: http://demiansyahhh.blogspot.com/ (possibly unsafe)
For some more Facebook reset emails see:
https://www.google.com/search?q=%22You+recently+asked+to+res...
EDIT: Twitter emails are also exposed: https://www.google.com/search?q=%22Forgot+your+Twitter+passw...
Youtube emails: https://www.google.com/search?q=%22YouTube+sends+email+summa...
Twoo emails: https://www.google.nl/search?q=%22Massive+Media+NV%2C+Emile+...
And likely more web services.