February 26, 2008   Sign In |  About ebizQ |  Contact Us |  Join ebizQ Gold Club
Elizabeth Kratz
Elizabeth Kratz's Business Agility Watch
ebizQ editor-in-chief Elizabeth Kratz gives a daily dose of Web happenings for the business technology industry; the industry that builds, powers and ensures business success.

« New ebizQ Blogs: 'Open Source Unleashed' and 'SaaS Week' | Main | Is ITtoolbox Really Worth $58.9 million? »

August 14, 2007
Facebook's Source Code Leaked

Stuff just hasn't been right the last few days with my very favorite social networking tool, Facebook. The recent growth of Facebook's application tools combined with talk of either an IPO or takeover bid from one of the 800-pound Internet gorillas have put pressure on the Facebook team and there is a palpable air of unease. Not to mention that two of my applications, including Trakzor and Scrabulous, have not been displaying notifications properly! P.S. Hey, Facebook, I love what you've done with Scrabulous! It's, well... Scrabulous!

But I doubt my personal solipsistic concern with notifications has anything to do with the top Facebook issue this week, though, which is that, reportedly, portions of the site’s code were leaked via a blog, and it is unknown whether these exposed codes could have compromised personal user information. It has raised an alarm around the web-savvy world about the security of social networking sites.

Joshua Block, VP of North American Operations for Cyberoam, "the leading provider of identity-based UTM solutions," recently sent around some commentary addressing where additional security concerns may lie:

“The issues surrounding consumer privacy raise the need for education on safe practices when it comes to Web 2.0 and social networking applications. But what’s more is that cross-scripting attacks and cross-site request forgeries are raising new vulnerabilities. Since Web 2.0 enables users to upload content, these sites can be left open to malicious content upload, leaving innocent visitors vulnerable to targeted attacks.”

However, this may all be a tempest in a teapot. Brandee Barker from Facebook has left a comment on a TechCrunch article about this:

“A small fraction of the code that displays Facebook web pages was exposed to a small number of users due to a single misconfigured web server that was fixed immediately. It was not a security breach and did not compromise user data in any way. Because the code that was released only powers the Facebook user interface, it offers no useful insight into the inner workings of Facebook. The reprinting of this code violates several laws and we ask that people not distribute it further.”

Hopefully, all will be better soon. Facebook is not something anyone wants compromised, as almost everyone I know has become somewhat dependent on it to a certain extent.

Posted by elizabeth in |Digg This|Add to del.icio.us

Trackback Pings

TrackBack URL for this entry:
http://www.ebizq.net/mt/mt-tb.cgi/2225

Comments Post a comment




Remember Me?

(you may use HTML tags for style)

We ask that you type your code (displayed below) in the text box.This code is an image that cannot be read by a machine. It prevents automated programs from submitting comments.


Code:



Most Recent ebizQ Blog Entries
ADVERTISEMENT
ebizQ Blogs
Subscribe

Podcast Feed
Elizabeth Book's Articles
Subscribe to our Newsletters
ebizQ Weekly Gold Club Update
Live Webinar Updates
Updates from ebizQ Partners
ebizQ SOA Update
ebizQ BPM Update
ebizQ Security Update
ebizQ BI Update
ebizQ Open Source Software Update
Virtual Show Newsletter
ebizQ Web 2.0 and the Enterprise
Your E-mail Address:
Roundtable: SOA Security - The Real Deal, or Much Ado About Nothing?
Date: Feb 27, 2008
Time: 12:00 PM ET
(17:00 GMT)

I WANT TO ATTEND
The Business Process Expert and the Future of BPM: A New Role, Matched to New BPM Tools
Date: Feb 28, 2008
Time: 14:00 PM ET
(19:00 GMT)

I WANT TO ATTEND
Archived Webinars | Upcoming Webinars

Marketing Solutions | Feedback | About ebizQ | Unsubscribe | Privacy Policy | Site Map