How I Hacked Into Facebook Login To Get Access To Uber, Ola, Zomato, Snapdeal & More

How I Hacked Into Facebook Login To Get Access To Uber, Ola, Zomato, Snapdeal & More

While researching for our new venture TOTUM, we hacked around facebook login,  looking for alternate login methods. This is when we discovered  a major security breach, which can compromise your data across multiple platforms.

In simple words,  whenever you choose the “Login Through Facebook” option on any website or mobile app, you expose every other account where you ‘logged in through Facebook’ including Uber, Snapdeal, Zomato and Foodpanda among the rest.

How Facebook Login Works

security breach

 

Security Breach

Let’s say you login to app X via Facebook. X will receive an access token from Facebook and will send it to X’s server and save it.

But now X can use this same access token to login to any and every other platform impersonating you and access your data ranging from your recent orders on Zomato or your purchase history from Snapdeal to getting access to your private messages and the list goes on.

We tested out this security breach on our TOTUM app’s test run and to our amazement, by using a single access token that we received from Facebook, we were able to access the entire account history of that user on a series of big players like Zomato, Foodpanda, Snapdeal etc.

login access

Our Evil Plan

We initially  thought of creating a chrome plugin that can inspect the web pages before viewing and blur the text where GOT (Game of Thrones) related information is published, so that you do not read spoilers.

Our guess was such a plugin would have received a pretty generous number of user downloads. But this plugin would have been infected with a virus that reads your Facebook access token and scraps user data from different target sites. This would have given us a huge user account base to begin our exploits.

But the genius yet kind souls that we are, we decided instead to post about this breach and alert the unsuspecting net savvy souls who are ever so eager to ‘Login through Facebook’ and save the extra 2 minutes, about the consequences of this simple step.

Food For Thought

Would you want every online account you ever create to be available for misuse by any random app? Isn’t it scary to think anyone can book rides using your Uber account and pay using your PayTM wallet ?

Facebook has access to all the information about every platform which provides the ‘Login Through Facebook’ option. They can scrap from all the platforms anytime they want.

Until this issue is resolved, your online data is all up for grabs.

[This article is contributed by Mohit Bagga, Co-Founder & CTO @ Codebibber & Tajinder Pal Singh Chahal]

Note: The views and opinions expressed are solely those of the author and does not necessarily reflect the views held by Inc42, its creators or employees. Inc42 is not responsible for the accuracy of any of the information supplied by guest bloggers.

You have reached your limit of free stories
Become An Inc42 Plus Member

Become a Startup Insider in 2024 with Inc42 Plus. Join our exclusive community of 10,000+ founders, investors & operators and stay ahead in India’s startup & business economy.

2 YEAR PLAN
₹19999
₹7999
₹333/Month
Unlock 60% OFF
Cancel Anytime
1 YEAR PLAN
₹9999
₹4999
₹416/Month
Unlock 50% OFF
Cancel Anytime
Already A Member?
Discover Startups & Business Models

Unleash your potential by exploring unlimited articles, trackers, and playbooks. Identify the hottest startup deals, supercharge your innovation projects, and stay updated with expert curation.

How I Hacked Into Facebook Login To Get Access To Uber, Ola, Zomato, Snapdeal & More-Inc42 Media
How-To’s on Starting & Scaling Up

Empower yourself with comprehensive playbooks, expert analysis, and invaluable insights. Learn to validate ideas, acquire customers, secure funding, and navigate the journey to startup success.

How I Hacked Into Facebook Login To Get Access To Uber, Ola, Zomato, Snapdeal & More-Inc42 Media
Identify Trends & New Markets

Access 75+ in-depth reports on frontier industries. Gain exclusive market intelligence, understand market landscapes, and decode emerging trends to make informed decisions.

How I Hacked Into Facebook Login To Get Access To Uber, Ola, Zomato, Snapdeal & More-Inc42 Media
Track & Decode the Investment Landscape

Stay ahead with startup and funding trackers. Analyse investment strategies, profile successful investors, and keep track of upcoming funds, accelerators, and more.

How I Hacked Into Facebook Login To Get Access To Uber, Ola, Zomato, Snapdeal & More-Inc42 Media
How I Hacked Into Facebook Login To Get Access To Uber, Ola, Zomato, Snapdeal & More-Inc42 Media
You’re in Good company