Hi Matt. First off, thank you for coming forth to make a statement about this vulnerability. It's nice to see that fb is responding to these incidents, and since you care, I'll work with you to solve the problem.
But first, let me express how disconcerting I find it for facebook to "pass the buck" on the blame of this vulnerability. It's not a browser vulnerability to have personal information be shared by implementing a "1 click publishing" button via a cross-domain iframe that (often times unknowingly) has a user logged into another site -- it's a privacy vulnerability that you need to take care of. As of late, I see no way that I can disable "liking" stuff, and I'm aware of the vulnerability, so I stay logged out of Facebook as often as I can.
It's facebook's decision to use an iframe, to publish content to user's news streams in 1 click, and to allow any website to implement the like button. It's your decision in spite of knowing that the means of doing so are open to "vulnerabilities" such as linkjacking. I put "vulnerability" in quotes because it's not really a vulnerability, now is it? It's a fundamental possibility based on how HTML works -- links can be invisible! Calling "linkjacking" a vulnerability is like calling tracking pixels, sessions in URLs, or anything that can be used for ill purposes, a "vulnerability" that browsers need to take care of. I'm not buying it. It's part of the design of HTML and you need to work with it.
You could easily remedy the situation by ensuring the user really means to publish something. However, I realize you aren't going to change anything about the "liking" process because it will disincentivize publishers from including it if it's not as effective. Business first, I understand.
Luckily, I will share with you, for free, how to fix this issue.
You can detect whether or not an iframe is being invisibly dragged by polling the cursorX and cursorY (which are relative to the browser window itself, not just the iframe) in conjunction with whether or not the user's mouse is over the "like" button (simple onmouseover/onmouseout).
If the user's mouse is over the "like" button even as X and Y dramatically change (optionally, over some unit of time) then the iframe is being positioned according to the mouse movements. A click on the "like" button should be disabled, and you should discretely notify your server that the URL/domain is suspect.
If the attackers were smarter, they'd position the "like" button below the mouse only on an onmousedown event so that your detection script wouldn't catch on to the one sudden movement of the "like" button in time for when the user lifts the button of their mouse.
But, luckily, you'd have me to tell you to ensure that both onmousedown and onmouseup are fired before actually having the "like" button signal a click.
So, there you have it. A free solution to your problem. That worked out much easier than posting a puzzle on your jobs page and waiting for people to solve your problems that way.
PS: For some reason as I read my post I realize that I come off as quite arrogant and perhaps a bit angsty. I apologize for that... it's almost embarrassing. I think it's just really late and I felt like being really frank about the issue. At any rate, you guys should hire me.