Logo

dev-resources.site

for different kinds of informations.

Facebook Lied : A Facebook Feature Which Kills Another Feature

Published at
12/19/2018
Categories
security
awareness
facebook
india
Author
bauripalash
Categories
4 categories in total
security
open
awareness
open
facebook
open
india
open
Author
11 person written this
bauripalash
open
Facebook Lied : A Facebook Feature Which Kills Another Feature

Facebook, Facebook , Facebook.... 2018 was not quite a Happy Year for Facebook.. Though I'm not here talk about those.

Today I'll talk about a facebook features which is totally killing another feature. So without further talking let's jump into the main content..

I'll keep it short and simple...

Back in 2017 , Facebook introduced Profile Picture Guard for indian users to secure their photos from misuse.
[Source]

When Profile Picture Guard Turned on a Profile , other users will not be able to download images from that profile and blue border appears on the profile picture :

And on the bottom you'll not see any View Full Size Option

No Download Options

Wait...!! I forgot One Thing, According The Claim , Facebook should be preventing users from taking screenshot, But where is the feature?πŸ˜‘

Now , Leave that for now, there's already a Facebook Feature which we can use to download anybody's profile picture bypassing the so-called Profile Picture Guard

So , Let's take a Look at How We Can Download a Profile Picture with Profile Picture Guard turned on.

First Thing We'll need is Victim's , I mean target's Numerical Profile ID (or whatever it's called)
We can extract target's Numerical Profile ID with https://findmyfbid.in/ if profile id isn't visible and has username such as bauripalash , abcd etc..

Now visit
https://graph.facebook.com/USERNAME/picture?width=800 and replace USERNAME with target's Numerical Profile ID

Now You'll See The Profile Picture of The Target User Will Be Shown and Also available for Download

Now! My Question is, Is Facebook Fooling Us , Indians? 😑

They Day when I found this, I reported that to Facebook Whitehat Program. At first I thought, There must be some authentication or api key system and maybe it's broken somehow!
After few days , I got reply from a staff , In Summary , he said

Thanks for your report, but we do not consider capturing a public image from the web to be eligible for a bounty under our program.
...
It’s important to remember the profile picture is always public. The feature you mentioned is a pilot test to see how these tools can help people have better control over how other people engage with their profile picture on Facebook.
...

I mean πŸ˜‘ anybody can download a so-called Guarded Profile Picture. Then what's the use of Profile Picture Guard? Just A Fancy Blue Border! πŸ˜“

Disclaimer : I , Palash Bauri or Dev.to is not Responsible for any damage done with the methods mentioned here. This article is only for educational and awareness purposes


If You Like My Work (My Articles, Stories, Softwares, Researches and many more) Consider Buying Me A Coffee β˜• πŸ€—

Featured ones: