<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Your Facebook Profile is Already Public</title>
	<atom:link href="http://theharmonyguy.com/2009/08/13/your-facebook-profile-is-already-public/feed/" rel="self" type="application/rss+xml" />
	<link>http://theharmonyguy.com/2009/08/13/your-facebook-profile-is-already-public/</link>
	<description>Investigating privacy and security issues in online social networking</description>
	<lastBuildDate>Thu, 09 Feb 2012 10:47:20 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Social Media Security &#187; With Facebook Privacy, Everyone Means Everyone</title>
		<link>http://theharmonyguy.com/2009/08/13/your-facebook-profile-is-already-public/comment-page-1/#comment-8257</link>
		<dc:creator>Social Media Security &#187; With Facebook Privacy, Everyone Means Everyone</dc:creator>
		<pubDate>Wed, 06 Jan 2010 15:55:46 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=296#comment-8257</guid>
		<description>[...] don&#8217;t want the entire Internet to see, since despite Facebook&#8217;s many privacy settings, much of your content has long been accessible via Facebook applications &#8211; and security issues with applications are [...]</description>
		<content:encoded><![CDATA[<p>[...] don&#8217;t want the entire Internet to see, since despite Facebook&#8217;s many privacy settings, much of your content has long been accessible via Facebook applications &#8211; and security issues with applications are [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: With Facebook Privacy, Everyone Means Everyone &#124; Social Hacking</title>
		<link>http://theharmonyguy.com/2009/08/13/your-facebook-profile-is-already-public/comment-page-1/#comment-7510</link>
		<dc:creator>With Facebook Privacy, Everyone Means Everyone &#124; Social Hacking</dc:creator>
		<pubDate>Fri, 11 Dec 2009 18:15:09 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=296#comment-7510</guid>
		<description>[...] don&#8217;t want the entire Internet to see, since despite Facebook&#8217;s many privacy settings, much of your content has long been accessible via Facebook applications &#8211; and security issues with applications are [...]</description>
		<content:encoded><![CDATA[<p>[...] don&#8217;t want the entire Internet to see, since despite Facebook&#8217;s many privacy settings, much of your content has long been accessible via Facebook applications &#8211; and security issues with applications are [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Facebook Hacked &#124; Social Hacking</title>
		<link>http://theharmonyguy.com/2009/08/13/your-facebook-profile-is-already-public/comment-page-1/#comment-5654</link>
		<dc:creator>Facebook Hacked &#124; Social Hacking</dc:creator>
		<pubDate>Thu, 27 Aug 2009 21:35:36 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=296#comment-5654</guid>
		<description>[...] the last few months, I have uncovered such holes in seven applications, three of which currently have monthly active users numbering in the tens of [...]</description>
		<content:encoded><![CDATA[<p>[...] the last few months, I have uncovered such holes in seven applications, three of which currently have monthly active users numbering in the tens of [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: meh</title>
		<link>http://theharmonyguy.com/2009/08/13/your-facebook-profile-is-already-public/comment-page-1/#comment-5525</link>
		<dc:creator>meh</dc:creator>
		<pubDate>Fri, 14 Aug 2009 16:32:18 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=296#comment-5525</guid>
		<description>Code or it never happened :)</description>
		<content:encoded><![CDATA[<p>Code or it never happened :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: theharmonyguy</title>
		<link>http://theharmonyguy.com/2009/08/13/your-facebook-profile-is-already-public/comment-page-1/#comment-5515</link>
		<dc:creator>theharmonyguy</dc:creator>
		<pubDate>Fri, 14 Aug 2009 05:20:21 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=296#comment-5515</guid>
		<description>@chris: An application has the same amound of access if either (a) you have also installed the application, or (b) you have not specifically limited the amount of access by uninstalled applications in your Facebook privacy settings.  Based on the scientific guess that most users have never changed the default privacy settings in this regard, I said that the same amount of access was likely.  But since one could limit access for apps they&#039;ve not also installed, I could not say it was true 100% of the time.</description>
		<content:encoded><![CDATA[<p>@chris: An application has the same amound of access if either (a) you have also installed the application, or (b) you have not specifically limited the amount of access by uninstalled applications in your Facebook privacy settings.  Based on the scientific guess that most users have never changed the default privacy settings in this regard, I said that the same amount of access was likely.  But since one could limit access for apps they&#8217;ve not also installed, I could not say it was true 100% of the time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: chris</title>
		<link>http://theharmonyguy.com/2009/08/13/your-facebook-profile-is-already-public/comment-page-1/#comment-5512</link>
		<dc:creator>chris</dc:creator>
		<pubDate>Fri, 14 Aug 2009 04:07:21 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=296#comment-5512</guid>
		<description>&quot;Second, if a friend authorizes an application, that application likely has the same amount of access to your profile via your friends’ sessions.&quot;

This is your speculation. On what factual basis does your claim rest?  Are you speculating that authorized apps can do this using the official API the way it was intended to be used, or are you speculating that authorized apps can do this by abusing the API and running XSS or other exploits?</description>
		<content:encoded><![CDATA[<p>&#8220;Second, if a friend authorizes an application, that application likely has the same amount of access to your profile via your friends’ sessions.&#8221;</p>
<p>This is your speculation. On what factual basis does your claim rest?  Are you speculating that authorized apps can do this using the official API the way it was intended to be used, or are you speculating that authorized apps can do this by abusing the API and running XSS or other exploits?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Twitted by theharmonyguy</title>
		<link>http://theharmonyguy.com/2009/08/13/your-facebook-profile-is-already-public/comment-page-1/#comment-5508</link>
		<dc:creator>Twitted by theharmonyguy</dc:creator>
		<pubDate>Fri, 14 Aug 2009 02:37:43 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=296#comment-5508</guid>
		<description>[...] This post was Twitted by theharmonyguy [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was Twitted by theharmonyguy [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

