Facebook's Canvas Encryption Proposal
developers.facebook.com
developers.facebook.com
I think that the perception is that if a business gets my Facebook UID, they have access to my information - which is not true, they can't retrieve any more information than you publicly make available.
Maybe I'm just misunderstanding what the big issue is all about though.
The current ids have completely permeated every part of their public APIs and likely every part of their internal systems...
Also, anyone who's worked with their APIs before knows not to underestimate Facebook's commitment to the "move fast, break things" mantra.
I think it is a clever idea, but it ends up breaking down in a lot of ways, and it has the bad quality that it is not backwards compatible with existing applications.
That way, you would normally only be able to see what the world would see; but if you try to view your or your friend's profile, it's fluid?
Create the iframe with some JS that POSTs a form containing the data to the canvas app. The resulting iframe url is the same but without any query parameters.
I am not sure if fb has rules for not pushing uid's with 3rd party services - other than that, I don't see how this solution avoids the problem.
However, if an ad network wanted to get the UIDs they can still easily get them. Just about all Facebook iframe applications use the Facebook Javascript SDK, which provides methods that can easily be used to collect the user's current ID or other information. Most ad networks require developers to load a remote javascript file on their site, and this javascript file can simply make calls through the SDK to fetch whichever information it wants.
Actually the problem is how Facebook is working its way into all parts of the internet with its widgets and Facebook logins.
It's hardly a proposal when they already seem intent on following through with this plan. It's not exactly an RFC.
Not to mention the flaws present pointed out by the other commenters...