There is no evidence that the leak of keys to user accounts resulted in private information being shared with advertisers, Facebook says.
The company was responding in a statement to a report posted by the internet security company Symantec on Tuesday on its blog that said the keys, called access tokens, were being leaked through Facebook applications such as games and quizzes.
The keys could allow third parties such as advertisers and web analytics companies to view user profiles and photographs, post messages and chat, Symantec wrote. Fortunately, it said, the third parties that received the tokens may not have realized their ability to access users' personal information.
In a statement emailed to CBC News on Thursday, Facebook said it appreciated Symantec raising the issue and it had worked with Symantec to address it immediately.
"Unfortunately, the report has a few inaccuracies," the statement said. "Specifically, we've conducted a thorough investigation which revealed no evidence of this issue resulting in a user's private information being shared with unauthorized third parties."
The company added that the report ignores the fact that advertisers and developers have contracts that bar them from "obtaining or sharing user information in a way that violates our policies."
Symantec had warned that some of the access tokens might still be available in log files on servers belonging to third parties or might still be used by advertisers. It suggested concerned users could change their passwords so any tokens that still exist will no longer work.
However, Facebook said the "vast majority" of tokens cited by Symantec expire within two hours.
The company reiterated that, as posted on its developer blog Tuesday, it is removing the outdated tool that could leak the tokens.
The company was responding in a statement to a report posted by the internet security company Symantec on Tuesday on its blog that said the keys, called access tokens, were being leaked through Facebook applications such as games and quizzes.
The keys could allow third parties such as advertisers and web analytics companies to view user profiles and photographs, post messages and chat, Symantec wrote. Fortunately, it said, the third parties that received the tokens may not have realized their ability to access users' personal information.
In a statement emailed to CBC News on Thursday, Facebook said it appreciated Symantec raising the issue and it had worked with Symantec to address it immediately.
"Unfortunately, the report has a few inaccuracies," the statement said. "Specifically, we've conducted a thorough investigation which revealed no evidence of this issue resulting in a user's private information being shared with unauthorized third parties."
The company added that the report ignores the fact that advertisers and developers have contracts that bar them from "obtaining or sharing user information in a way that violates our policies."
Symantec had warned that some of the access tokens might still be available in log files on servers belonging to third parties or might still be used by advertisers. It suggested concerned users could change their passwords so any tokens that still exist will no longer work.
However, Facebook said the "vast majority" of tokens cited by Symantec expire within two hours.
The company reiterated that, as posted on its developer blog Tuesday, it is removing the outdated tool that could leak the tokens.