Уровень 0 · материалов: 8
В кластер включаются документы о программных уязвимостях, сбоях настроек приватности и утечках данных в VKontakte, но не включаются сообщения о физическом проникновении в офис компании.
Общие признаки: бреши в безопасности VK, утечки персональных данных, нарушение приватности пользователей, проблемы сторонних виджетов, критика политики конфиденциальности соцсети
Группа выше: Приватность и данные во ВКонтакте
Смысл: The text highlights a critical security flaw in VKontakte where default settings made users' uploaded documents publicly searchable, exposing sensitive data like passports, and criticizes the company for blaming users instead of fixing the system.
VKontakte exposed users' sensitive documents, including passports, through a default public search feature and refused to take corporate responsibility for the flaw.
Смысл: The main idea is to expose a massive security breach on VKontakte where a third-party widget application was used to distribute malware to millions of users via drive-by downloads, highlighting the dangers of third-party integrations and the administration's lack of transparency.
A third-party widget app on VKontakte was found delivering Java exploits to millions of visitors, potentially creating a massive botnet while the platform administration remained silent.
Смысл: The main idea is to alert users and developers about a privacy vulnerability in VKontakte that allowed unauthorized viewing of private photos through a specific site feature.
A discovered bug in VKontakte's accelerated viewing mode allowed users to see private photos, though it was quickly patched.
Смысл: The text demonstrates a clickjacking vulnerability in the VKontakte authorization widget that allows attackers to steal user profile data, and criticizes the platform's support for refusing to acknowledge it as a security flaw.
The author reveals a way to use a transparent VK authorization widget to trick users into giving away their profile data, which VK support refuses to treat as a vulnerability.
Смысл: The main idea is to debunk the myth that VKontakte 'canceled' privacy, explaining that the perceived leak of photos was actually a result of existing default settings becoming more visible, and urging users to read official documentation before panicking.
The author clarifies that VKontakte's photo privacy hasn't changed, but rather the visibility of default-public albums has become more transparent, urging users to stop sensationalizing the issue.
Смысл: The text describes a major security vulnerability in VKontakte where users briefly gained moderator rights, illustrating the inherent privacy risks and the powerful surveillance tools available to social media administrators.
A temporary bug in VKontakte granted regular users administrator privileges, exposing the platform's internal moderation tools and sparking privacy concerns.
Смысл: The main idea is a critical protest against the erosion of user privacy on the VKontakte social network, specifically regarding the shift toward public friend lists and the lack of transparent data deletion options.
The author criticizes VKontakte for making friend lists public by default and expresses frustration over the lack of an easy account deletion process.
Смысл: The text warns about a privacy vulnerability where third-party websites can deanonymize visitors by linking their session to a VK profile using hidden widgets, raising ethical and legal questions about personal data consent.
A JavaScript service allows websites to silently identify VK profiles of visitors without their consent, creating serious privacy and security risks.