<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Social Me Still Too Social</title>
	<atom:link href="http://theharmonyguy.com/2008/07/16/social-me-still-too-social/feed/" rel="self" type="application/rss+xml" />
	<link>http://theharmonyguy.com/2008/07/16/social-me-still-too-social/</link>
	<description>Investigating privacy and security issues in online social networking</description>
	<lastBuildDate>Thu, 09 Feb 2012 10:47:20 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Social Me is Back, Privacy Still Vulnerable&#160;&#124;&#160;FaceBook News</title>
		<link>http://theharmonyguy.com/2008/07/16/social-me-still-too-social/comment-page-1/#comment-31972</link>
		<dc:creator>Social Me is Back, Privacy Still Vulnerable&#160;&#124;&#160;FaceBook News</dc:creator>
		<pubDate>Sat, 09 Jul 2011 04:25:13 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=27#comment-31972</guid>
		<description>[...] resurrected but it appears that there are still some substantial privacy loopholes. According to theharmonyguy, there is still a substantial privacy flaw which enabled him &#8220;to send a message to anyone and [...]</description>
		<content:encoded><![CDATA[<p>[...] resurrected but it appears that there are still some substantial privacy loopholes. According to theharmonyguy, there is still a substantial privacy flaw which enabled him &#8220;to send a message to anyone and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Waks</title>
		<link>http://theharmonyguy.com/2008/07/16/social-me-still-too-social/comment-page-1/#comment-316</link>
		<dc:creator>Mark Waks</dc:creator>
		<pubDate>Thu, 17 Jul 2008 17:01:00 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=27#comment-316</guid>
		<description>Nice job of finding that, and good on them for fixing it.

Formal invitation: if you find the time and inclination to poke at an app that&#039;s still in the construction phase, I&#039;d love to have some outside eyes take a look at &lt;a href=&quot;http://www.facebook.com/apps/application.php?id=6825710207&quot; rel=&quot;nofollow&quot;&gt;CommYou&lt;/a&gt;, the conversation system I&#039;m building.  

That&#039;s not even at alpha yet, but I&#039;d rather find and fix the security holes *before* I have thousands of people using the thing.  I know it&#039;s not perfect yet -- it&#039;s subject to a man-in-the-middle attack during login, which is going to be a pain in the ass to fix -- but I believe it&#039;s pretty good otherwise.  I&#039;d be interested to see if you notice other holes in the security...</description>
		<content:encoded><![CDATA[<p>Nice job of finding that, and good on them for fixing it.</p>
<p>Formal invitation: if you find the time and inclination to poke at an app that&#8217;s still in the construction phase, I&#8217;d love to have some outside eyes take a look at <a href="http://www.facebook.com/apps/application.php?id=6825710207" rel="nofollow">CommYou</a>, the conversation system I&#8217;m building.  </p>
<p>That&#8217;s not even at alpha yet, but I&#8217;d rather find and fix the security holes *before* I have thousands of people using the thing.  I know it&#8217;s not perfect yet &#8212; it&#8217;s subject to a man-in-the-middle attack during login, which is going to be a pain in the ass to fix &#8212; but I believe it&#8217;s pretty good otherwise.  I&#8217;d be interested to see if you notice other holes in the security&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://theharmonyguy.com/2008/07/16/social-me-still-too-social/comment-page-1/#comment-315</link>
		<dc:creator>John</dc:creator>
		<pubDate>Thu, 17 Jul 2008 06:43:31 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=27#comment-315</guid>
		<description>Have you contacted SocialMe or Facebook about this, seems like something they would care about.

Also I tried doing this but couldn&#039;t figure it out (wanted to make sure my apps aren&#039;t susceptible to this)

Could you demonstrate on these two accounts:
1017467310, 835962318 (you can do whatever message you want)</description>
		<content:encoded><![CDATA[<p>Have you contacted SocialMe or Facebook about this, seems like something they would care about.</p>
<p>Also I tried doing this but couldn&#8217;t figure it out (wanted to make sure my apps aren&#8217;t susceptible to this)</p>
<p>Could you demonstrate on these two accounts:<br />
1017467310, 835962318 (you can do whatever message you want)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: T</title>
		<link>http://theharmonyguy.com/2008/07/16/social-me-still-too-social/comment-page-1/#comment-312</link>
		<dc:creator>T</dc:creator>
		<pubDate>Wed, 16 Jul 2008 21:38:01 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=27#comment-312</guid>
		<description>I didn&#039;t find an e-mail address on your site to contact you, so I guess I&#039;ll just leave a comment here. Recently Facebook removed the ability to see what friends are currently online (without appearing online yourself, using Facebook Chat). With the new profile beta, I found that the functionality is still there, just hidden. If you click on &quot;Friends&quot; at the top of your profile redesign page (new.facebook.com), you can replace a string in the url with &quot;online&quot;. You end up with this url: &quot;http://www.new.facebook.com/friends/?view=online&quot;.

Not really a vulnerability or anything, just thought it would interest you</description>
		<content:encoded><![CDATA[<p>I didn&#8217;t find an e-mail address on your site to contact you, so I guess I&#8217;ll just leave a comment here. Recently Facebook removed the ability to see what friends are currently online (without appearing online yourself, using Facebook Chat). With the new profile beta, I found that the functionality is still there, just hidden. If you click on &#8220;Friends&#8221; at the top of your profile redesign page (new.facebook.com), you can replace a string in the url with &#8220;online&#8221;. You end up with this url: &#8220;http://www.new.facebook.com/friends/?view=online&#8221;.</p>
<p>Not really a vulnerability or anything, just thought it would interest you</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Social Me is Back, Privacy Still Vulnerable</title>
		<link>http://theharmonyguy.com/2008/07/16/social-me-still-too-social/comment-page-1/#comment-311</link>
		<dc:creator>Social Me is Back, Privacy Still Vulnerable</dc:creator>
		<pubDate>Wed, 16 Jul 2008 20:34:06 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=27#comment-311</guid>
		<description>[...] resurrected but it appears that there are still some substantial privacy loopholes. According to theharmonyguy, there is still a substantial privacy flaw which enabled him &#8220;to send a message to anyone and [...]</description>
		<content:encoded><![CDATA[<p>[...] resurrected but it appears that there are still some substantial privacy loopholes. According to theharmonyguy, there is still a substantial privacy flaw which enabled him &#8220;to send a message to anyone and [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

