Archive for May 2008

New Facebook "Loophole" Found

Posted by: Tom

Saw this on Liquidmatrix today....

Some programmers in the UK created a Facebook application that could be downloaded by a Facebook user which would allow the programmers to view personal information even with the privacy settings changed. From the UK article:

"Details such as the date of birth, address and contact numbers of the user, and that of all their friends, can be seen by the creators and could potentially be stolen."

This shouldn't be a surprise to anyone. Facebook has very limited control over what third-party applications or widgets a user can install. Sure they have "terms and conditions" that must be followed...but as we all know those can be circumvented quite easily.

I recently created a Facebook profile to test the security for myself and I have found that the default security/privacy settings for your Facebook profile are pretty much wide open. This include having your profile hit by search engine spiders. The average user of Facebook will most likely ignore these settings and download those cool Facebook applications that their friends are using as well. :)