PogoWasRight.org

Menu
  • About
  • Privacy
Menu

The Inside Story of How Facebook Responded to Tunisian Hacks

Posted on January 25, 2011July 3, 2025 by Dissent

It was on Christmas Day that Facebook’s Chief Security Officer Joe Sullivan first noticed strange things going on in Tunisia. Reports started to trickle in that political-protest pages were being hacked. “We were getting anecdotal reports saying, ‘It looks like someone logged into my account and deleted it,'” Sullivan said.

For Tunisians, it was another run-in with Ammar, the nickname they’ve given to the authorities that censor the country’s Internet. They’d come to expect it.

In the days after the holiday, Sullivan’s security team started to take a closer look at the data, but it wasn’t entirely clear what was happening. In the US, they could look to see if different IP addresses, which identify particular nodes on the network, were accessing the same account. But in Tunisia, the addresses are commonly reassigned. The evidence that accounts were being hacked remained anecdotal. Facebook’s security team couldn’t prove something was wrong in the data. It wasn’t until after the new year that the shocking truth emerged:

Ammar was in the process of stealing an entire country’s worth of passwords.

Read more in The Atlantic.

Facebook did an important – and terrific – thing here and they deserve tremendous credit for this.

The high praise they’ve been earning is not totally uncritical, however. Security researcher Chris Soghoian, noted:

Facebook deployed https by default for users in tunisia. Waiting for US users to get similar security protection.

No related posts.

Category: Featured NewsNon-U.S.OnlineSurveillance

Post navigation

← Can Search Engines Compete on Privacy?
Patriot Act’s Wiretapping & FISA Provisions Up for Renewal this Month →

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • Tool allows stealthy tracking of Signal and WhatsApp users through delivery receipts
  • Oh Great, Smart Glasses That Record Everything You Say
  • CBP Agents Held This U.S. Citizen for Hours Until He Agreed To Let Them Search His Electronic Devices
  • U.S. Plans to Scrutinize Foreign Tourists’ Social Media History
  • ANNOUNCEMENT: EFF Launches Age Verification Hub as Resource Against Misguided Laws
  • FTC Denies Petition from SpyFone App CEO to Vacate 2021 Order
  • Privacy concerns raised as Grok AI found to be a stalker’s best friend

RSS Recent Posts at DataBreaches.net

  • Virginia Urology Silent on Possible Data Breach as Purported Patient Data Begins to Leak
  • Village of Golf Manor considering paying ransom amid cyberattack (1)
  • Teen who allegedly stole millions of personal data records arrested in Spain
  • Akira ransomware: FBI tallies 250 million in payouts
  • IE: HSE confirms second ransomware attack but ‘no evidence’ patient data was stolen
©2025 PogoWasRight.org. All rights reserved.