Do you use Timehop? If you’re not sure what that is, it’s a popular, clever little app that reminds social media users about posts they’ve made in the past. It can be quite handy, especially if you’re active on numerous social media accounts.
Unfortunately, the bloom is off the rose for Timehop. Recently, the company announced that it had suffered a breach on the Fourth of July, which gave the hackers virtually unfettered access to the company’s cloud servers for more than two hours. During that time, the hackers were able to make off with the names, email addresses and other account details of more than twenty-one million users.
Nearly five million of the records stolen (4.7 million) had phone numbers in the data. As bad as that sounds, it gets worse. Because of what Timehop is and how it works, it’s got hooks into all of the social media accounts of every member who uses the app.
Timehop uses tokens to access social media information. Tokens that are now in the hands of the hackers, who could use them to view and/or “scrape” social media content (including private posts) uploaded by every one of the 21 million impacted users. In short, even if you keep tight control over who can see your social media content, if you’re one of the impacted users, the cat is officially out of the bag.
The company says that they deactivated all tokens shortly after the incident was detected, but there was still a small window of time in which they could have been used.
As is the norm in cases like these, Timehop has issued an apology, is in the process of informing all affected users, and is working with law enforcement and an outside agency to assist with the forensic investigation. This incident, however, underscores how easily it is to lose control of one’s data.
It’s not enough to simply exercise caution and be mindful of security on the social media channels you frequent. You’ve also got to be mindful of what third parties you allow to access those channels, because any one of them could provide an inroad for a hacker.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
Researchers from the digital security firm ESET have recently spotted a new malware campaign with a nasty twist. It was created using a legitimate security certificate stolen from D-Link.
Apple recently released an updated version of iOS, 11.4.1. They did so quietly, and without much fanfare, but the update includes one very powerful and exciting security update that’s deserving of special attention.
There’s a lot to like about the contents of Adobe’s most recent “Patch Tuesday” update. It’s well worth downloading and installing, even if you normally take a pass on all but the most critical updates.
It’s no secret that there are legions of scammers and spammers haunting the virtual halls of Facebook. As the world’s largest and most influential social networking site, it’s a natural target, making its masses of users natural targets, too.
Internet security researcher Vinny Trola recently made a huge and disturbing discovery. A marketing firm called Exactis had left a massive database unsecured, allowing anyone who stumbled across it to access it.
While a significant percentage of Americans are suspicious of government spending beyond the essentials, there’s at least one notable exception, according to a recent survey conducted by SecurityFirst.
File this one away under “watch your permissions.” It’s recently come to light that an unknown number of third party apps have access to read emails sitting in your Gmail account.
Another week, another high-profile data breach. This time, Adidas and their online store was the target.
Facebook recently announced a site bug that impacted the privacy settings of more than 800,000 of its users. If you’re one of the unfortunate souls who has been affected, then people you had formerly blocked may have become unblocked, and can now see your posts.