wow this guy is clever...the application will send your email address and Facebook login password in clear text to the developer's server!
i'm amazed at how many people are using this app without any concern about this, as well as the fact that it's even listed on Apple's Downloads section.
Facebook Watch
widget shows user data from Facebook
Version: 2.1
sends password + email in cleartext to a third-party server
Feedback Type: Review
Contributed by: lensovet Thursday, July 05 2007 @ 03:09 AM PDT
Product Platform: MacOSX
Used Product For: Less than a month
Recommend Product: NO
Overall Rating:
Quality / Stability:
Comments
re: sends password + email in cleartext to a third-party server - johnjacobjingleheimerschmidt
Given that facebook does sometimes ask for credit card information or cell phone numbers, I would regard cleartext passwords over the wire an inexcusable security hole. There is no shortage of easy-to-use openssl implementations.I haven't downloaded the client myself, but if the installer doesn't specifically state in a terms of service document that user logins and passwords will be stored on a third-party server, might there a violation of privacy acts in certain parts of the globe, including the US and the EU? I wonder what kind of evidence is used to file search warrants and seizure of computer equipment when someone chooses to sniff passwords off the wire, "just for fun"?
--not that Mac users have a history of excessive ligitations filed or anything.
Cheers.
Sunday, July 22 2007 @ 11:06 PM PDT
re: sends password + email in cleartext to a third-party server - lensovet
The problem, however, is that this information is not disclosed anywhere and violates both the website Terms of Use and the developers platform Terms of Service.Apart from that, you can tell me as much as you want that the data is "safe".
Wednesday, August 08 2007 @ 01:19 AM PDT
re: sends password + email in cleartext to a third-party server - cjbeauchamp
Yes, and I am changing statuses across the globe.I would like to say that this information is never recorded or seen by anyone. Here is why it is done: the code to parse all the facebook data lies on my servers - true. It is hosted on my servers and not your local machine because facebook is always changing, as is the code. To avoid having to download an update every week, I can update the code, on my servers, to accommodate the facebook changes. This widget is safe, along with your information, and I apologize for not clearing this up sooner.
Reply to This
Monday, July 16 2007 @ 10:57 AM PDT