It's surprisingly simple to click jack using CSS4
jsfiddle.net
jsfiddle.net
Clicking the div will click the underlying link, which will (if you're logged into facebook) "like" the Facebook Developer group.
Is this an issue with HTML5, or is it really an issue with how easy sites can manipulate your Facebook account?
A lot of web Javascript would be useless if events didn't bubble, and being able to define invisible click areas is useful in a variety of contexts.
Sucks that a few people are going to be malicious about it but I think the benefits outweigh the drawbacks.
Invisible click areas as you called it are not the same as multi-layered click targets imho.
I hope this doesn't mean the end of niche browsers, or at least not those built on well-known rendering engines like WebKit.
Unfortunately it simply isn't possible to provide something like the Like button without being vulnerable to click jacking. I assume Facebook decided that the benefits outweighed the drawbacks. There's probably something clever they can do on the server side to statistically detect and penalize likely clickjacking attempts.
It's like arguing that something is safer because it requires 10 lines of code instead of one to do the exploit. That's security by obscurity.
Still, I can not think of a possible use case this can be useful. Maybe other options will make it worth knowing about.
http://shiflett.org/blog/2009/feb/twitter-dont-click-exploit
Maybe our privacy settings are different and that's why you saw a prompt even though you were logged in.