Facebook glitch reveals private photos -- including Zuckerberg's

A glitch in the system used to report inappropriate images on Facebook briefly allowed users to view others' private photos. No one's pictures were safe — not even those belonging to Facebook founder and CEO Mark Zuckerberg.

Members of the BodyBuilding.com forums were among the first to discover the glitch and they quickly put together detailed instructions on how it could be exploited by those wishing to view private images of friends and strangers.

It didn't take long for a link to those instructions to make its way around the Internet and for folks to start snooping on their former lovers, enemies, teachers, bosses, employees ... and on Facebook's own Mark Zuckerberg.

Imgur

Private photos belonging to Facebook founder and CEO Mark Zuckerberg were revealed as a result of a recent glitch in the system used to report inappropriate images on the social network. They got attention after being uploaded to an album on photo-sharing service Imgur.

At some point someone even posted a small collection of the social network founder's private photos to image-sharing service Imgur with a caption proclaiming that "it's time to fix those security flaws Facebook." (Those once hidden images have now been viewed nearly half a million times.)

Imgur

Private photos belonging to Facebook founder and CEO Mark Zuckerberg were revealed as a result of a recent glitch in the system used to report inappropriate images on the social network. They got attention after being uploaded to photo-sharing service Imgur.

The method used to acquire those — and other private photos — was pretty simple, as explained by BodyBuilding.com forum member ThePoz:

Facebook

All someone needed to do is pick a target, click the "report/block" button on his or her profile and then select "inappropriate profile photo" when asked why the profile is being reported.

Facebook

On the next prompt, the snooping user would have to claim that the image is inappropriate because it contains "nudity or pornography." After that, he or she would check a box to "report [the image] to Facebook."

Facebook

The final step is to helpfully offer to "help [Facebook] take action by selecting additional photos to include with [the] report." And tada! Suddenly a selection of the reported users photos appears — including the ones which are private.

We reached out to Facebook for an explanation of what happened when we first heard about this privacy glitch. The company replied as it issued a fix:

Earlier today, we discovered a bug in one of our reporting flows that allows people to report multiple instances of inappropriate content simultaneously. The bug allowed anyone to view a limited number of another user's most recently uploaded photos irrespective of the privacy settings for these photos.  This was the result of one of our recent code pushes and was live for a limited period of time. Upon discovering the bug, we immediately disabled the system, and will only return functionality once we can confirm the bug has been fixed.

The privacy of our user's data is a top priority for us, and we invest significant resources in protecting our site and the people who use it. We hire the most qualified and highly-skilled engineers and security professionals at Facebook, and with the recent launch of our Security Bug Bounty Program (http://www.facebook.com/whitehat/), we continue to work with the industry to identify and resolve legitimate threats to help us keep the site safe and secure for everyone. 

Long story short? Your private Facebook photos are private once again — or as private as anything uploaded to the Internet could be.

Related stories:

Want more tech news, silly puns, or amusing links? You'll get plenty of all three if you keep up with Rosa Golijan, the writer of this post, by following her on Twitter, subscribing to her Facebook posts, or circling her on Google+.

Discuss this post

Wow that's interesting. Except, not. Now maybe if the woman were naked...

  • 2 votes
Reply#1 - Wed Dec 7, 2011 11:02 AM EST

Woman is not the same as WOMEN you moron.

  • 2 votes
#1.1 - Wed Dec 7, 2011 3:25 PM EST

If he was referring to zuckerberg's girlfriend, "if the woman were naked" uses a perfectly grammatical past subjective form of "be".

Here's a grammar lesson you moron: http://www.englishclub.com/grammar/verbs-subjunctive.htm

  • 2 votes
#1.2 - Thu Dec 8, 2011 6:41 AM EST
Reply

PROTIP: Do not upload pictures to the internet that you do not want the WHOLE WORLD TO SEE! The internet is not private.

  • 22 votes
Reply#2 - Wed Dec 7, 2011 11:23 AM EST

Agreed completely. You may as well just assume if it's on the internet, everyone is going to see it, so don't be stupid about uploading pictures that you REALLY want to be private.

  • 1 vote
#2.1 - Wed Dec 7, 2011 12:52 PM EST

Keep in mind, once it's out there, it cannot be deleted.

  • 3 votes
#2.2 - Wed Dec 7, 2011 3:00 PM EST

Technically it can...it would just require a LOT of effort. =P

  • 2 votes
#2.3 - Thu Dec 8, 2011 7:46 AM EST

Once the search engine caches get ahold of it, it's pretty much impossible without legal remedies :/

  • 1 vote
#2.4 - Thu Dec 8, 2011 10:56 AM EST

It's not a matter of privacy as much as it displays the fact that Facebook does not have a mature or very experienced engineering team.

  • 2 votes
#2.5 - Thu Dec 8, 2011 11:26 AM EST

I feel like that's more of a novice tip, i cant believe anyone younger than 70 or younger than 10 would put anything they dont want people to see forever on the internet, they should know by now.

    #2.6 - Thu Dec 8, 2011 12:13 PM EST
    Reply

    “They 'trust me'. Dumb @!$%#s.”
    - Mark Zuckerberg, Facebook

    • 8 votes
    Reply#3 - Wed Dec 7, 2011 11:45 AM EST

    In the spirit of The Simpson's Nelson character:

    To Mark Zuckerbutt,

    Ha Ha!

    • 4 votes
    Reply#4 - Wed Dec 7, 2011 11:46 AM EST

    No one is untouchable these days.

    • 1 vote
    Reply#5 - Wed Dec 7, 2011 11:55 AM EST

    How ironic (and APPROPRIATE!) that Zuck got outed!

    • 7 votes
    Reply#6 - Wed Dec 7, 2011 11:55 AM EST

    Couldn't of happened to a better person! Now he knows how is users felt when they made security changes that exposed all of their private information!

    • 4 votes
    Reply#7 - Wed Dec 7, 2011 12:58 PM EST
    Comment author avatarSteve Weltmanvia Facebook

    (MarkZ...phonecall) Oh Really? They hacked MY private photos? Crap...I thought I was smarter than to post that stuff up there...Well, there goes the neighborhood."

    Boorrriing... At least these were clean photos. I am not all that into criticizing a 220 IQ kid that built an empire from people's personally shared information, but they (FB IT) should address changes in a more mature manner (and TELL us what they are changing on the interfaces _before— they do it). Sorry they had a glitch, but I was not affected (I am pretty 'John Q Public' so noone would care if my images were posted all over the web).

    • 1 vote
    Reply#8 - Wed Dec 7, 2011 1:24 PM EST

    That's ironic I just had to log in to my facebook account to make this post. :) Every website is going to have bugs and vulnerabilities. It is no different for the largest social network. They are still governed by the same laws of Internet security. New exploits happen weekly. Internet security will always be one step behind those that reverse engineer it. As long as it is accessible via a public network there is a chance that someone will be able to access information that wasn't meant for them.

    • 2 votes
    Reply#9 - Wed Dec 7, 2011 2:06 PM EST

    Truer words were never spoken!

    When will they ever learn?

    • 1 vote
    #9.1 - Sat Dec 31, 2011 2:18 PM EST
    Reply

    Your data privacy is very important to us, except when we sell it to attain massive amounts of money.

    • 6 votes
    Reply#10 - Wed Dec 7, 2011 2:59 PM EST

    More true words.

    • 1 vote
    #10.1 - Sat Dec 31, 2011 2:19 PM EST
    Reply

    Today Show: If you clearly know these are his private photos, that were accessed by a mistake or glitch, why do you think it your right to violate that intended privacy exponentially and show the photos to millions more people?

    • 3 votes
    Reply#11 - Wed Dec 7, 2011 3:16 PM EST

    ANSWER: Ethics NULL

    • 2 votes
    #11.1 - Wed Dec 7, 2011 3:31 PM EST

    Because someone else did it first. That's the justification in all media reporting, don't you know that?

    • 2 votes
    #11.2 - Wed Dec 7, 2011 3:42 PM EST

    What I know is any person or entity with ethics, morals, standards, or simply common courtesy and care wouldn't have done it. But yes, they do it all the time.

    • 3 votes
    #11.3 - Wed Dec 7, 2011 7:54 PM EST

    Oh, who cares? The pics are of some goofball wearing an apron and making sushi. That's hardly tantalizing material there.

    • 2 votes
    #11.4 - Wed Dec 7, 2011 10:38 PM EST

    He probably does (since he had them marked as private), and probably some of the other people in the photos weren't planning on this. Agreed, nothing tantalizing here. But many in the public, apparently not including you, would feel violated if their personal photos were acquired by mistake and shown to millions without their permission. I comes down to ethics and courtesy. Who cares???

    • 3 votes
    #11.5 - Thu Dec 8, 2011 6:42 PM EST

    Greg Beard writes:

    "What I know is any person or entity with ethics, morals, standards, or simply common courtesy and care wouldn't have done it." I can agree with that statement.

    Unfortunately there are also those who are greedy and have no or very limited morals. Zuckerberg comes to mind since he is getting filthy rich selling the info he has free access to on FB.

    • 1 vote
    #11.6 - Sat Dec 31, 2011 2:25 PM EST
    Reply

    What an idiot. If you don't want the whole world to see your private stock of photos then don't put them on Facebook or anywhere on the Internet for that matter. He's definitely as dumb as I though he was.

    • 2 votes
    Reply#12 - Wed Dec 7, 2011 4:48 PM EST

    I refuse to believe this was an accident. It might have been a Facebook ploy to show that "even Mark's picture's can get hacked." Looks like the pictures were all selected for release. It makes a good story but I'm not buying it.

    • 3 votes
    Reply#13 - Wed Dec 7, 2011 5:07 PM EST

    When will people understand. If you post something on the internet it is not private. Anything can be hacked. This is good for Mark so that he can see that his own site has issues.

    • 1 vote
    Reply#14 - Wed Dec 7, 2011 6:26 PM EST

    Stay off of Facebook and Twitter. I cannot understand what is the fascination with Facebook and Twitter. Get a life, people.

    • 4 votes
    Reply#15 - Thu Dec 8, 2011 8:05 AM EST

    Totally agree. Such dribble.

    • 2 votes
    #15.1 - Thu Dec 8, 2011 8:43 AM EST

    Facebook I can understand, it helps keep in contact with friends / family.

    Twitter I do not, who the hell cares if you ate a taco for lunch?

    • 4 votes
    #15.2 - Thu Dec 8, 2011 10:58 AM EST
    Reply

    This film is set to release next year and is based on exactly these same Glitch based issues.

    It was just posted a few days ago and seems to be very interesting... and creepy...

    Search: "(AmI) Live" on Facebook

    • 1 vote
    Reply#16 - Fri Dec 9, 2011 11:34 PM EST
    You're in Easy Mode. If you prefer, you can use XHTML Mode instead.
    As a new user, you may notice a few temporary content restrictions. Click here for more info.