<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/facebook_security_weeks_old.php" />
  <link rel="self" type="application/atom+xml" href="http://www.readwriteweb.com/atom.xml" />
  <id>tag:,2009:/1/tag:www.readwriteweb.com,2008://1.5961-</id>
  <updated>2009-11-23T19:21:03Z</updated>
  <title>Comments for Comment of the Day: Facebook Security Lapse is Weeks Old</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.23-en</generator>
  <entry>
    <id>tag:www.readwriteweb.com,2008://1.5961</id>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/facebook_security_weeks_old.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.readwriteweb.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=5961" title="Comment of the Day: Facebook Security Lapse is Weeks Old" />
    <published>2008-03-25T07:00:40Z</published>
    <updated>2008-03-25T07:44:56Z</updated>
    <title>Comment of the Day: Facebook Security Lapse is Weeks Old</title>
    <summary>Today&apos;s winning comment comes from our post about a Facebook security flaw that allowed people to access private photos - including some from Paris Hilton at the Emmys and others from Facebook founding CEO Mark Zuckerberg&apos;s vacation in November of 2005. In an excellent example of crowdsourced fact checking and research, Mark Jaquith noted that...</summary>
    <author>
      <name>Richard MacManus</name>
      <uri>http://www.readwriteweb.com</uri>
    </author>
    
    <category term="Comments Competition" />
    
    <content type="html" xml:lang="en" xml:base="http://www.readwriteweb.com/">
      <![CDATA[<p><img src="http://www.readwriteweb.com/images/facebook-logo.jpg" />Today's winning comment comes from our post about <a href="http://www.readwriteweb.com/archives/facebook_security_lapse_private_photos.php">a Facebook security flaw</a> that allowed people to access private photos - including some from Paris Hilton at the Emmys and others from Facebook founding CEO Mark Zuckerberg's vacation in November of 2005. In an excellent example of crowdsourced fact checking and research, <a href="http://markjaquith.com/">Mark Jaquith</a> noted that "this flaw has been publicly known for weeks". Wrote Mark: "<a href="http://lenky.net/blog/2008/02/28/view-facebook-private-photos/">Here is a tutorial</a>, from late February (AP is reporting that the flaw was fixed, so hopefully this doesn't still work.)"</p>]]>
      <![CDATA[<p>Congratulations Mark, you've won a $30 Amazon voucher - courtesy of our competition sponsors AdaptiveBlue and their <a href="http://www.adaptiveblue.com/widgets_auto.html?section=nfx&name=Personalized%20Feed" rel="nofollow">Netflix Queue Widget</a>.</p>
<p>Here is Mark's full comment, followed by an extra comment he left verifying that Facebook has now fixed the error:</p>
<blockquote><p>"This flaw has been publicly known for weeks (which I report as an example of how poorly Facebook takes user privacy, not as a correction to your story).  Really crazy.  They weren't checking user permissions for photo pages.  If you could guess the ID of a photo, you could view that photo.  Worse, they gave you ways to determine the ID of a recent photo.  And once you viewed a private photo in the album, <strong>the previous/next links worked, showing you the rest of the private photos in that album!</strong></p>

<p><a href="http://lenky.net/blog/2008/02/28/view-facebook-private-photos/">Here is a tutorial</a>, from late February (AP is reporting that the flaw was fixed, so hopefully this doesn't still work.)"</p></blockquote>
<p>Comment 2 by Mark:</p>
<blockquote><p>"Verified that they fixed it:</p>

<p><em>"The page you requested can not be displayed right now. It may be temporarily unavailable, the link you clicked on may have expired, or you may not have permission to view this page."</em></p>

<p><strong>BUT</strong> you can still see private photos in which you are tagged, even if you were omitted from the permissions list.  I created a new album on my wife's account, and blocked all her networks, and all her friends except one (not me).  I added one picture of me, then tagged myself in it.  On my account, it announced the photo to me with a thumbnail and I was able to view it.  At no time did it warn me (on her account) that by tagging the photo I was expanding the permissions on that photo.  Not a huge flaw, but still -- if people are going to trust these privacy settings, they need to be bulletproof."</p></blockquote>

]]>
    </content>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.5961-comment:50135</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.5961" type="text/html" href="http://www.readwriteweb.com/archives/facebook_security_weeks_old.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/facebook_security_weeks_old.php#c50135" />
    <title>Comment from Ginnungagap on 2008-03-25</title>
    <author>
        <name>Ginnungagap</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>I don't really know what is fixed and what isn't... Right now my news feed contains two items of the type 'X commented on Y's photo' and both Ys are not my friends, yet I can see their photos and (clicking on Previous/Next) the rest of their albums, which are meant to be private!</p>]]>
    </content>
    <published>2008-03-25T13:45:47Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.5961-comment:52489</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.5961" type="text/html" href="http://www.readwriteweb.com/archives/facebook_security_weeks_old.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/facebook_security_weeks_old.php#c52489" />
    <title>Comment from tazar M18L on 2008-04-18</title>
    <author>
        <name>tazar M18L</name>
        <uri>http://www.planetmace.com/airtasers.html</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.planetmace.com/airtasers.html">
        <![CDATA[<p>Your trusted source for personal security products. We strive to provide our customers with a comprehensive online resource for finding dependable personal, home and auto products at the best prices available anywhere.<a href="http://www.planetmace.com/airtasers.html" rel="nofollow">tazar M18L</a></p>]]>
    </content>
    <published>2008-04-18T13:12:09Z</published>
  </entry>

</feed>