Beware of "Facebook Social Plugins"

I discovered today that Facebook allows third party sites to make use of something called "Facebook Social Plugins" which can make it appear as if you are logged into other sites through Facebook.  You are not able to opt out of this.

For my non-tech friends who wander by here, this uses what's called an "iframe."  There are some protections built in because of your web browser's security policies, but this is open to abuse easily.  Facebook could snoop on what sites you visit that use these plugins.  Facebook could list what you've visited on your profile.  The only thing preventing abuse is trust.  You have no way to turn this off in Facebook settings currently.  Please see FAQ items linked above to confirm this.

You should log out of Facebook after every use or use a browser plugin that does this for you to prevent abuse until Facebook changes its policy on this.  I have to admit this is so shady and open to abuse and coupled with the fact that it was not announced widly that I am now seriously considering abandoning Facebook altogether, despite the great personal value I get from connections with people on the site.

Posted by deryck on May 19, 2010

Post a comment