How to Hijack a Digital Identity: The Lethal Simplicity of Expired Emails
How to hack into Facebook without being a hacker
The paper "How to Hack into Facebook without being a Hacker" uncovers a critical security vulnerability involving the reuse of expired email addresses. By reactivating defunct Hotmail accounts used for registration, the authors demonstrate a "no-skill" method to bypass Facebook’s security and seize full account control via standard password recovery mechanisms.
TL;DR
Researchers from Rutgers University demonstrated a startlingly simple way to take over Facebook accounts without writing a single line of malicious code or using "traditional" hacking tools. By simply re-registering expired Hotmail accounts that were linked to Facebook profiles, they exploited the "Forgotten Password" mechanism to gain full control of 15 accounts across six levels of social connections.
Positioning: This work is a seminal "Red Teaming" exercise that shifted the focus from technical software bugs to systemic policy failures between interconnected web services.
Problem & Motivation: The Weakest Link in the Chain
Most users view their email as a permanent digital vault. However, certain providers (notably Hotmail/Outlook in the early 2010s) had policies where accounts were deleted after periods of inactivity. The critical failure was that these deleted addresses were then returned to the public pool for anyone to register.
The authors realized that if a user signed up for Facebook with a "secondary" email and forgot about it, that email might expire. If an attacker re-registers that exact address, they don't just get a new email—they get the "keys to the kingdom" for every service linked to that address.
Methodology: The "Tree" of Vulnerability
The beauty (and terror) of this attack lies in its simplicity. The researchers used a three-step process:
- Identification: They used Windows Live Messenger to import Facebook friend lists. The system clearly flagged which contacts did not have active Windows Live accounts—if those contacts had Hotmail addresses, it was a high-probability signal that the email had expired.
- Reactivation: The researchers simply signed up for the "available" expired email address.
- Takeover: They triggered Facebook’s password recovery. The reset code was sent to the "new" (reactivated) email, allowing the authors to change the Facebook password and lock out the original owner.
The Propagation Chain
The attack is recursive. Once one account is compromised, the attacker can view that person's friends list and repeat the process. This creates a branching tree of compromised identities.
Figure 1: The researchers visualized the attack as a tree, where each internal node represents a hijacked account that led to further victims.
Experimental Analysis: Global Reach
The experiment started with a single user who had 760 friends. Within just six levels of depth, the researchers could have accessed a massive network. Even after stopping early for ethical reasons, they found that:
- Susceptibility: 1% to 2% of any given friend list is vulnerable.
- Geographic Spread: Hijacking just 15 accounts allowed them to "teleport" across the globe, accessing users in different continents.
Figure 2: The pins represent the physical locations of the 15 compromised accounts, demonstrating how social networking bypasses physical borders.
Critical Insight & Conclusion
The core takeaway is that identity is transitive. If a platform (Facebook) trusts a third party (Email Provider) for authentication, the platform's security is only as good as the third party's retention policy.
Future Outlook & Defense
To stop this, the authors suggested several mechanisms that are now industry standards:
- Multi-Factor Authentication (MFA): Requiring an SMS or an app-based code.
- Social Recovery: Identifying friends in photos (a method Facebook actually implemented for a time).
- Security Questions: Adding a layer of personal knowledge that isn't stored in the email inbox.
Final Thought: This paper serves as a reminder that the most "elegant" hacks aren't found in complex math or zero-day exploits, but in understanding the simple logic of how different systems talk to—and trust—each other.
