UPDATED 07:38 EDT / JULY 14 2012

NEWS

Instagram Patches Privacy Vulnerability, Hammers a Quick Fix

Instagram, the mobile photo-sharing network recently suffered a flaw in its image application, recently discovered by Spanish researcher Sebastián Guerrero. As described in the advisory published by Guerrero, there was a logical flaw in the authorization that he called ‘friendship vulnerability’.

Accordingly, an attacker can perpetrate a brute force attack in the context of user application and add himself as a friend of all the users on Instagram, being possible in this way to get access to private albums and profile information.

As soon as Instagram discovered the flaw and a public disclosure was made, the developers hammered out a quick fix.

“We don’t have any evidence that this bug was taken advantage of at any other scale than very minimal experiments by a technical researcher. The technical researcher was not able to follow private users, nor were private users’ data ever at risk,” Explained Instagram’s bug fix notes.

Instagram was acquired by Facebook back in April, where the social networking giant paid a hefty price of $1 billion for the deal. Photo-sharing is something really important to Facebook, and this deal was a great in-move for its long term mobile strategy. Just last week, Instagram has received an update for the first time since Facebook snapped it up. The upgrade has been rolled out on both the iOS and Android versions of the application, which is now available as version 2.5 and 1.1.4.

The reported flaw in Instagram, if lasted for a long time, could have tarnished the Facebook’s image as it is already facing issues from some of its acquisitions. Earlier in June, Face.com, the Israel-based facial recognition maker, suffered a big security flaw in its functionality, resulting in hijacking of the Facebook and Twitter accounts of users. The popular Face.com mobile app KLIK that lets users tag faces in photos using Facebook allowed almost anyone to hack the Facebook and Twitter accounts of KLIK’s users.


A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.