Existing users, log in.  New users, create a free account.  Lost password?

Mac OS X  |  Widgets  |  Other Widgets  |  Facebook Watch  |  sends password + email in cleartext to a third-party server

Facebook Watch

Facebook Watch

widget shows user data from Facebook

Version:  2.1

   [ Views: 926 ]

sends password + email in cleartext to a third-party server

Feedback Type:  Review

Contributed by: lensovet Thursday, July 05 2007 @ 03:09 AM PDT

Product Platform: MacOSX

Used Product For: Less than a month

Recommend Product: NO

wow this guy is clever...the application will send your email address and Facebook login password in clear text to the developer's server!

i'm amazed at how many people are using this app without any concern about this, as well as the fact that it's even listed on Apple's Downloads section.   
Overall Rating:

Quality / Stability:

5 of 5 users found this helpful.

Rate this Review

Was this Review helpful? Yes | No

Comments

3 comments |

re: sends password + email in cleartext to a third-party server - cjbeauchamp

Yes, and I am changing statuses across the globe.

I would like to say that this information is never recorded or seen by anyone. Here is why it is done: the code to parse all the facebook data lies on my servers - true. It is hosted on my servers and not your local machine because facebook is always changing, as is the code. To avoid having to download an update every week, I can update the code, on my servers, to accommodate the facebook changes. This widget is safe, along with your information, and I apologize for not clearing this up sooner.

Reply to This

Monday, July 16 2007 @ 10:57 AM PDT


re: sends password + email in cleartext to a third-party server - johnjacobjingleheimerschmidt

Given that facebook does sometimes ask for credit card information or cell phone numbers, I would regard cleartext passwords over the wire an inexcusable security hole. There is no shortage of easy-to-use openssl implementations.

I haven't downloaded the client myself, but if the installer doesn't specifically state in a terms of service document that user logins and passwords will be stored on a third-party server, might there a violation of privacy acts in certain parts of the globe, including the US and the EU? I wonder what kind of evidence is used to file search warrants and seizure of computer equipment when someone chooses to sniff passwords off the wire, "just for fun"?

--not that Mac users have a history of excessive ligitations filed or anything.

Cheers.

Reply to This

Sunday, July 22 2007 @ 11:06 PM PDT


re: sends password + email in cleartext to a third-party server - lensovet

The problem, however, is that this information is not disclosed anywhere and violates both the website Terms of Use and the developers platform Terms of Service.

Apart from that, you can tell me as much as you want that the data is "safe".

Reply to This

Wednesday, August 08 2007 @ 01:19 AM PDT