Security Vulnerabilities in Facebook Data Breach
摘要
This research explores the intricate landscape of data breaches within Facebook (now Meta) from 2018 to 2021. The goal of this case study is to discover valuable lessons learned for online security improvements by analyzing the security vulnerabilities and causes leading to the recent data breaches at Facebook. Over 2.5 billion users were affected across 11 significant data breaches, predominantly involving Personal Identifiable Information (PII). The breaches emerged due to flawed data sharing practices, API issues, and privacy design flaws. Remarkably, most breaches went unnoticed during data security assessments but were discovered during product testing or by third parties. Facebook’s recurrent mishaps, particularly the storage of user passwords in plaintext, underscore its inadequate privacy design implementation. This study proposes an emphasis shift towards privacy-centric product design, more rigorous privacy change management, and stringent data access controls in order to safeguard user data and ensure regulatory compliance for social media platforms. Facebook’s mishandling of data security, resulted in regulatory intervention and substantial fines, serves as a cautionary case example for organizations worldwide.