Bookkeeping Service Providers

  • Accounting
  • Bookkeeping
  • US Taxation
  • Financial Planning
  • Accounting Software
  • Small Business Finance
You are here: Home / Uncategorized / Facebook Hack Did Not Affect Microsoft Azure AD B2C Service

Facebook Hack Did Not Affect Microsoft Azure AD B2C Service

October 8, 2018 by cbn Leave a Comment

News

Facebook Hack Did Not Affect Microsoft Azure AD B2C Service

  • By Kurt Mackie
  • 10/08/2018

In an Oct. 4, 2018, Service blog post Microsoft said that the Facebook hack last month that potentially exposed the access tokens of about 50 million Facebook users did not affect Microsoft’s Azure Active Directory B2C service.

The breach occurred because of three software flaws and was the largest breach to date for Facebook, according to a Sept. 28 explanation by Guy Rosen, vice president of product management at Facebook. Those flaws made it possible for user access tokens, which are used to keep users signed in to the service, to get stolen using the Facebook “View as” feature. The feature was supposed to just display how a person’s profile looked to others. With stolen access tokens, it’s possible to take over accounts.

The Facebook social media service can be used as an “identity provider” with Azure AD B2C, which is Microsoft’s identity service for connecting businesses with consumers. It’s been possible to use a Facebook ID (along with IDs from Amazon, Google and LinkedIn) with the service ever since Microsoft launched Azure AD B2C in 2016. More recently, Microsoft added GitHub and Twitter as accepted identity providers that can be used with the service.

While the Facebook hack exposed the access tokens of Facebook users, the breach didn’t affect users of the Azure AD B2C service, Microsoft contended, even if Facebook served as the identity provider. The Azure AD B2C service doesn’t use those Facebook tokens directly. Instead, it uses an authorization code that’s sent from the user’s browser, Microsoft explained in its announcement.

Here’s how the announcement expressed it:

Since B2C does not accept access tokens from the end user, the exploit that Facebook has described does not apply — even if an attacker presented B2C with the access token of another Facebook user, B2C is not configured to accept it to authenticate the user.

Facebook acted about two days after detecting the breach to address the issue, according to Rosen, in a video in Facebook’s announcement. The software flaws were fixed, the tokens were reset and Facebook temporarily turned off the View As feature, according to the company. All Facebook users (90 million accounts) will be compelled to sign back into their accounts as a precaution.

Rosen stated that “there’s no need for anyone to change their [Facebook] passwords.” However, the U.S. Federal Trade Commission, in a consumer advisory on the matter, recommending doing it anyway.

In an Oct. 2 announcement, Rosen said that analysis by Facebook had showed that no “third-party apps” had been accessed using Facebook logins as a consequence of the breach.

About the Author

Kurt Mackie is senior news producer for the 1105 Enterprise Computing Group.

Share on FacebookShare on TwitterShare on Google+Share on LinkedinShare on Pinterest

Filed Under: Uncategorized

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Archives

  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • May 2021
  • April 2021
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • September 2017
  • August 2017
  • July 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • March 2016

Recent Posts

  • How Azure Cobalt 100 VMs are powering real-world solutions, delivering performance and efficiency results
  • FabCon Vienna: Build data-rich agents on an enterprise-ready foundation
  • Agent Factory: Connecting agents, apps, and data with new open standards like MCP and A2A
  • Azure mandatory multifactor authentication: Phase 2 starting in October 2025
  • Microsoft Cost Management updates—July & August 2025

Recent Comments

    Categories

    • Accounting
    • Accounting Software
    • BlockChain
    • Bookkeeping
    • CLOUD
    • Data Center
    • Financial Planning
    • IOT
    • Machine Learning & AI
    • SECURITY
    • Uncategorized
    • US Taxation

    Categories

    • Accounting (145)
    • Accounting Software (27)
    • BlockChain (18)
    • Bookkeeping (205)
    • CLOUD (1,322)
    • Data Center (214)
    • Financial Planning (345)
    • IOT (260)
    • Machine Learning & AI (41)
    • SECURITY (620)
    • Uncategorized (1,284)
    • US Taxation (17)

    Subscribe Our Newsletter

     Subscribing I accept the privacy rules of this site

    Copyright © 2025 · News Pro Theme on Genesis Framework · WordPress · Log in