Major Facebook security hole lets you view your friends’ live chats
eu.techcrunch.com
eu.techcrunch.com
I'm pretty sure we'd see them wise up quickly when presented with a taste of their own dogfood.
Missed opportunity!
Obviously that's wrong. And privacy should be respected, bug or no bug.
Think again.
If it would have been me discovering this (not that I'm nearly smart enough to do so, but hypothetically speaking) I would have definitely used it against FB management.
They run roughshod over the rights of their users every chance they get, they really need a wake-up call about why privacy matters and that they ought to be more responsible when it comes to things like this.
I imagine it cuts across whole swathes of code, requiring additional checks about the current user. It would be so easy to leave some of these checks out or mess them up. You would have to be very careful about validating your assumptions with this feature.
I built an internal web application for a large and somewhat paranoid company that required three distinct layers of security. While I'm pretty sure I implemented them correctly, and could explain pretty well how they worked when pressed, I think it was just too much for most users to wrap their heads around the mental model.
In retrospect, I should have pushed back. If I couldn't convince them to with a simpler model, I should have at least advocated for adding the layers of security incrementally, both to let the users understand what the model is and to help the development team understand what the model should be.
Sorry, just ranting a bit. It's been frustrating dealing with a company that doesn't have a telephone helpline, even for paying customers. (We've spent thousands of dollars on Facebook ads, etc.)
Edit: The button from the privacy settings page is working again.
In general, though, cutting chat while trying to fix this is probably a Good Idea. Less room for bad things to happen assuming you can turn chat off more quickly than you can fix the behavior.
Edit: I see someone in the Techcrunch comments section posted what he claims to be Mark Zuckerberg's pending friends requests - Ctrl+F for "Random Jo - May 5th, 2010 at 3:04 pm UTC" ...
But incompetence, especially systemic incompetence, is extraordinarily difficult to change. Facebook appears to have ADD around user privacy and its interface. Designs come and go, defaults change capriciously, and security seems to be an afterthought.
We've seen this movie before, with MSFT in the role of the bumbling centi-billionaire. Hopefully Facebook will steer a different course.
Facebook, like all other software, is bound to have bugs. If you don't want your personal information/conversations to be exposed by a potential bug I'd suggest not using the service.
Release processes and rigorous QA procedures seem more appropriate for client-deployed software like operating systems than for centralized web applications.
What happens to the reviewers that let this thing slip through, btw?
that would be mighty difficult, as software and their potential bugs are present in most every facet of modern life.
Spying on PMs is even worse than live chat, in my opinion.