A Nice Big FriendFeed Bug: Impersonate Anyone!

Mg Siegler

MG Siegler is a general partner at Google Ventures and a columnist for TechCrunch, where he has been writing since 2009. Previously, MG was a general partner at CrunchFund. And before TechCrunch, MG covered various technology beats for VentureBeat. Originally from Ohio, MG attended the University of Michigan in Ann Arbor, MI. He’s previously lived in Los Angeles where he worked... → Learn More

Friday, September 11th, 2009

Screen shot 2009-09-11 at 3.48.15 PM

There’s quite a big vulnerability with FriendFeed right now. Using the FriendFeed By Email function, apparently anyone can post a message as anyone else on FriendFeed. For example, someone posted this pretending to be FriendFeed co-founder Bret Taylor.

Obviously, this is a huge security problem. When it was spotted just about an hour ago, FriendFeed jumped on it quickly, and has shut down email posting while they look into the issue. (Good to know they can still hop on these problems with FriendFeed even though they are now technically Facebook employees.) Still, you have to wonder if this bug has existed for months, or however long this feature has existed?

We’ve reached out to FriendFeed to see if there have been any serious compromises because of this bug.

blog comments powered by Disqus