Facebook blames Zuckerberg embarrassment on API 'bug'
networkworld.com
networkworld.com
Or if his personal account is not an admin on the page, but again I find that unlikely.
Still, I believe them when they say it was an API bug. I don't see why they would lie and claim it was something else on the day they roll out a fix for the problem.
Stealing passwords is of course also trivial, but to do that you need to force a situation where the user has to actually log in again (see Moxie Marlinspike's sslstrip..., which will nail the majority of people even if the site normally does use https for everything. Really bloody effective.)
Wonder what really happened? Must've been much more embarrassing for them to admit they had an "API Bug".
(I haven't heard of any other accounts being borked via API calls, and developers mess with these thousands of times a day, you're telling me nobody picked up on this...? Except the dude who did a harmless prank on Zuckerbergs page...)
Fun poem to memorize
Of course, we have to keep in mind that Facebook has an incentive to downplay the severity and the author has an incentive to hype the severity; the truth is probably somewhere in the middle. There's no reason to believe that there was mass-abuse of this issue unless someone has evidence to the contrary. At the same time, Zuckerberg's wasn't the only high profile page to have a strange status posted on it recently.