HN user

tam7t

18 karma

Developer.

Posts4
Comments10
View on HN

Kickstarter requests access to "your public profile, friend list, email address, hometown, current city and likes" from Facebook on logon. With stolen access tokens the attackers could query Facebook for that information with limitations:

1) only available until the tokes were revoked

2) if enabled, attacker must also obtain the 'app secret' and sign requests

3) if enabled, attacker must use the tokens from a white-listed IP address

The post only makes reference to encrypted passwords. Not sure if Facebook access tokens are included in that or not.

Whenever I get any account information emails from "facebookmail.com" I spend 10 minutes trying to figure out if it's a phishing attempt. My opinion: Just use your real domain or if you must a subdomain, ie notify@mailer.startup.com.