<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Easily View Hidden Facebook Friend Lists</title>
	<atom:link href="http://theharmonyguy.com/2009/12/24/easily-view-hidden-facebook-friend-lists/feed/" rel="self" type="application/rss+xml" />
	<link>http://theharmonyguy.com/2009/12/24/easily-view-hidden-facebook-friend-lists/</link>
	<description>Investigating privacy and security issues in online social networking</description>
	<lastBuildDate>Wed, 28 Jul 2010 21:02:56 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
	<item>
		<title>By: :(</title>
		<link>http://theharmonyguy.com/2009/12/24/easily-view-hidden-facebook-friend-lists/comment-page-1/#comment-9647</link>
		<dc:creator>:(</dc:creator>
		<pubDate>Sat, 13 Mar 2010 13:52:15 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=613#comment-9647</guid>
		<description>IT doesnt work</description>
		<content:encoded><![CDATA[<p>IT doesnt work</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Social Media Security &#187; Facebook’s Fluid Definition of Publicly Available Information</title>
		<link>http://theharmonyguy.com/2009/12/24/easily-view-hidden-facebook-friend-lists/comment-page-1/#comment-9184</link>
		<dc:creator>Social Media Security &#187; Facebook’s Fluid Definition of Publicly Available Information</dc:creator>
		<pubDate>Thu, 11 Feb 2010 14:27:57 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=613#comment-9184</guid>
		<description>[...] course, it wasn’t long before someone discovered a “means to do so.” In December, I posted a simple trick that would reveal the names and profile pages of any user’s friends, regardless of whether they [...]</description>
		<content:encoded><![CDATA[<p>[...] course, it wasn’t long before someone discovered a “means to do so.” In December, I posted a simple trick that would reveal the names and profile pages of any user’s friends, regardless of whether they [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Facebook&#8217;s Fluid Definition of Publicly Available Information &#124; Social Hacking</title>
		<link>http://theharmonyguy.com/2009/12/24/easily-view-hidden-facebook-friend-lists/comment-page-1/#comment-9147</link>
		<dc:creator>Facebook&#8217;s Fluid Definition of Publicly Available Information &#124; Social Hacking</dc:creator>
		<pubDate>Wed, 10 Feb 2010 00:26:55 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=613#comment-9147</guid>
		<description>[...] wasn&#8217;t long before someone discovered a &#8220;means to do so.&#8221; In December, I posted a simple trick that would reveal the names and profile pages of any user&#8217;s friends, regardless of whether [...]</description>
		<content:encoded><![CDATA[<p>[...] wasn&#8217;t long before someone discovered a &#8220;means to do so.&#8221; In December, I posted a simple trick that would reveal the names and profile pages of any user&#8217;s friends, regardless of whether [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vas</title>
		<link>http://theharmonyguy.com/2009/12/24/easily-view-hidden-facebook-friend-lists/comment-page-1/#comment-8446</link>
		<dc:creator>Vas</dc:creator>
		<pubDate>Thu, 14 Jan 2010 09:36:36 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=613#comment-8446</guid>
		<description>how do you find a Facebook user;s ID number?</description>
		<content:encoded><![CDATA[<p>how do you find a Facebook user;s ID number?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: theharmonyguy</title>
		<link>http://theharmonyguy.com/2009/12/24/easily-view-hidden-facebook-friend-lists/comment-page-1/#comment-7972</link>
		<dc:creator>theharmonyguy</dc:creator>
		<pubDate>Mon, 28 Dec 2009 21:07:06 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=613#comment-7972</guid>
		<description>@Pascal: Thanks for the further testing. I operated off the assumption that all users will eventually migrate, so I didn&#039;t take migration into account.

Also, I mentioned in my post that the trick works even when not logged in. From what I&#039;ve found in further testing, it appears that whether the trick works for an unauthenticated session depends on whether the user has a public profile, not the privacy of their friend list. For instance, http://www.facebook.com/ajax/typeahead_friends.php?u=4&amp;__a=1 brings up Mark Zuckerberg&#039;s friend list regardless of whether you&#039;re logged in, but http://www.facebook.com/ajax/typeahead_friends.php?u=4617&amp;__a=1 only brings up Randi Zuckerberg&#039;s friend list if you&#039;re logged in. Both have their friend lists hidden on their profile, but Randi has her public profile disabled.</description>
		<content:encoded><![CDATA[<p>@Pascal: Thanks for the further testing. I operated off the assumption that all users will eventually migrate, so I didn&#8217;t take migration into account.</p>
<p>Also, I mentioned in my post that the trick works even when not logged in. From what I&#8217;ve found in further testing, it appears that whether the trick works for an unauthenticated session depends on whether the user has a public profile, not the privacy of their friend list. For instance, <a href="http://www.facebook.com/ajax/typeahead_friends.php?u=4&#038;__a=1" rel="nofollow">http://www.facebook.com/ajax/typeahead_friends.php?u=4&#038;__a=1</a> brings up Mark Zuckerberg&#8217;s friend list regardless of whether you&#8217;re logged in, but <a href="http://www.facebook.com/ajax/typeahead_friends.php?u=4617&#038;__a=1" rel="nofollow">http://www.facebook.com/ajax/typeahead_friends.php?u=4617&#038;__a=1</a> only brings up Randi Zuckerberg&#8217;s friend list if you&#8217;re logged in. Both have their friend lists hidden on their profile, but Randi has her public profile disabled.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pascal Van Hecke</title>
		<link>http://theharmonyguy.com/2009/12/24/easily-view-hidden-facebook-friend-lists/comment-page-1/#comment-7936</link>
		<dc:creator>Pascal Van Hecke</dc:creator>
		<pubDate>Sun, 27 Dec 2009 01:37:38 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=613#comment-7936</guid>
		<description>Hi,

Here&#039;s what my little tests showed when I try http://www.facebook.com/ajax/typeahead_friends.php?u=[USERID]&amp;__a=0 

unauthenticated session: the resultset is empty for users that have hidden their friend list and users that have not migrated yet, but is accessible for users that haven&#039;t done so.

authenticated session: resultset is empty for users that have not migrated yet, but is accessible for all users that have done so, regardless whether they have hidden their friend list or not.

So even after you have migrated, hiding your friend list does give you some protection against unauthenticated scraping.
You would have protection against authenticated scraping on the condition that Facebook monitors for an excessive number of requests coming from one userID.</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Here&#8217;s what my little tests showed when I try <a href="http://www.facebook.com/ajax/typeahead_friends.php?u=USERID&amp;__a=0" rel="nofollow">http://www.facebook.com/ajax/typeahead_friends.php?u=USERID&amp;__a=0</a> </p>
<p>unauthenticated session: the resultset is empty for users that have hidden their friend list and users that have not migrated yet, but is accessible for users that haven&#8217;t done so.</p>
<p>authenticated session: resultset is empty for users that have not migrated yet, but is accessible for all users that have done so, regardless whether they have hidden their friend list or not.</p>
<p>So even after you have migrated, hiding your friend list does give you some protection against unauthenticated scraping.<br />
You would have protection against authenticated scraping on the condition that Facebook monitors for an excessive number of requests coming from one userID.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: OzzyGreene</title>
		<link>http://theharmonyguy.com/2009/12/24/easily-view-hidden-facebook-friend-lists/comment-page-1/#comment-7899</link>
		<dc:creator>OzzyGreene</dc:creator>
		<pubDate>Fri, 25 Dec 2009 14:01:27 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=613#comment-7899</guid>
		<description>dude u&#039;ve inspired me and guess what?
i&#039;m in this...and i just knew this &quot;there&#039;s NO privacy With Netlog.com&quot;
i knew this u harmony guy will drag us  to the jail
adios amigo
ozzy Greene</description>
		<content:encoded><![CDATA[<p>dude u&#8217;ve inspired me and guess what?<br />
i&#8217;m in this&#8230;and i just knew this &#8220;there&#8217;s NO privacy With Netlog.com&#8221;<br />
i knew this u harmony guy will drag us  to the jail<br />
adios amigo<br />
ozzy Greene</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: uberVU - social comments</title>
		<link>http://theharmonyguy.com/2009/12/24/easily-view-hidden-facebook-friend-lists/comment-page-1/#comment-7892</link>
		<dc:creator>uberVU - social comments</dc:creator>
		<pubDate>Fri, 25 Dec 2009 07:00:47 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=613#comment-7892</guid>
		<description>&lt;strong&gt;Social comments and analytics for this post...&lt;/strong&gt;

This post was mentioned on Twitter by theharmonyguy: New Post: Easily View Hidden Facebook Friend Lists http://bit.ly/5hHO7V...</description>
		<content:encoded><![CDATA[<p><strong>Social comments and analytics for this post&#8230;</strong></p>
<p>This post was mentioned on Twitter by theharmonyguy: New Post: Easily View Hidden Facebook Friend Lists <a href="http://bit.ly/5hHO7V.." rel="nofollow">http://bit.ly/5hHO7V..</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tweets that mention Easily View Hidden Facebook Friend Lists &#124; Social Hacking -- Topsy.com</title>
		<link>http://theharmonyguy.com/2009/12/24/easily-view-hidden-facebook-friend-lists/comment-page-1/#comment-7890</link>
		<dc:creator>Tweets that mention Easily View Hidden Facebook Friend Lists &#124; Social Hacking -- Topsy.com</dc:creator>
		<pubDate>Fri, 25 Dec 2009 04:39:35 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=613#comment-7890</guid>
		<description>[...] This post was mentioned on Twitter by Melissa and theharmonyguy, topsy_top20k. topsy_top20k said: New Post: Easily View Hidden Facebook Friend Lists http://bit.ly/5hHO7V [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Melissa and theharmonyguy, topsy_top20k. topsy_top20k said: New Post: Easily View Hidden Facebook Friend Lists <a href="http://bit.ly/5hHO7V" rel="nofollow">http://bit.ly/5hHO7V</a> [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
