13 May 2019Murat Volkan DülgerCommentary

Introduction

This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.

The subject of this article is the Board’s “Facebook decision” of 11 April 2019, No. 2019/104, which was published on 10 May 2019. The data breach at issue in the Board’s decision rests on the allegation, which was reported publicly and is referred to as the “Photo API” incident, that between 13 September and 25 September 2018 some third-party applications may have had access to photos on Facebook, for twelve days, beyond the scope of their authorisation. Facebook’s Engineering Director Tomer Bar confirmed this allegation in a statement published on 14 December 2018 at https://developers.facebook.com/blog/post/2018/12/14/notifying-our-developer-ecosystem-about-a-photo-api-bug/ under the title “Notifying our developer ecosystem about a photo API bug”.

The statement said that a photo API bug had been discovered which allowed third-party applications to access Facebook users’ photos and that the problem had been fixed, but that because of this flaw some third-party applications may have had access to photos beyond the scope of their authorisation for 12 days between 13 September and 25 September 2018. In addition, it emerged that, whereas a third-party application given permission by a Facebook user through the Facebook platform to access his or her photos should have had access only to the photos the user had shared on the timeline, during those 12 days third-party applications also gained access, as a result of the flaw described, to other photos shared on Marketplace or Facebook Stories.

Related publications