.

.
Showing posts with label Facebook. Show all posts
Showing posts with label Facebook. Show all posts

Monday, 17 October 2011

Name Change Limit Reached-Facebook Fix

Name Change Limit Reached-Facebook Fix

Name Change Limit Reached
Too bad! You've upgraded your name the most extreme number of
times permitted and your name could not be altered again. To catalogue a different name you go by, for example a last name by birth, satisfy utilize the Alternate Name field underneath.
Having this Message??

want to Fix it up??
Bypass Facebook Name Change Limit

LogIn to your Account & Change your name as Listed & Go to this Link

http://www.facebook.com/deactivate.php

Notwithstanding Select the Reason My Account Was hacked!
There's an Information Dialogue popups Says "You could probably Secure your Account here"
as you could probably see here in Snap Shot...
Select that Link

Thursday, 25 August 2011

A Trillion Pageviews for Facebook

A Trillion Pageviews for Facebook

facebook stats
Google today released an updated list of the most-visited sites on the web and it should not come as any surprise that Facebook takes the top spot with 870 million uniques. YouTube and Yahoo are next with 790 M and 590 M uniques respectively.
Google, maybe for competitive reasons, doesn't share traffic data of its own site, or that of Gmail, in the Ad Planner report. Google+ is growing but the user base is still relatively small for the site to become part of this report.
A Trillion Page Views
Facebook hit a new milestone in June this year - the site touched a trillion page views from the 870 million* people who visited Facebook that month. Check this infographic to get an idea of how big a trillion – or a million million – is.
[*] Officially, Facebook has 750+ million users but the number of unique visitors who flock Facebook every month is much higher because certain section of the site – Facebook Pages and Profiles for example – are open to non-users as well.
Facebook says that people spend over 700 billion minutes per month on the site and now we also know that, on an average, one user visits 1150 pages on Facebook in a month. That's impressive considering that YouTube, with all the entertaining and viral content, manages only 126 views per unique visitor per month.

Sunday, 21 August 2011

A Look at Chromebook After Release: What Real Users are Saying

A Look at Chromebook After Release: What Real Users are Saying


chromebook A Look at Chromebook After Release: What Real Users are Saying
They are mist-registering based machines, and have taken an absolutely unexpected heading to supply mist figuring, when contrasted and the heading that the brand new Windows 8 managing framework vows.
Google suddenly discharged the Chromebook in May 2011, and there was a ton of clamor regarding this late thought in private registering. The Chromebook is the first fully fog working framework. It is the first time we have perceived mist processing in this way. Chromebooks run on the Chrome OS, which is basically an augmented form of the Chrome program. In otherwords, your Chromebook, which looks similar to a laptop will ought to be within the web based world every last trace of the chance to do anything. You could probably consider it as a web browser that has every last trace of the projects and all items else on your machine, aside from, nothing is in reality on your PC. Every little item is archived in your Google record or different within the web based world areas. Windows 8 is taking a fully better go at, it is in addition going fog by permitting the same registering dialect of the web deal with your managing framework freely of your program, and still permitting more universal customizing dialects of requisitions capacity at the same time. With Windows, we get mist and not mist, at the same time. Thus, while just good to go in the US, what have we perceived so far with Chromebooks in a few shortmonths.chromebook A Look at Chromebook After Release: What Real Users are Saying
  • Still More Tablet Like.Real user reviews are showing us that the Chromebook is more like owning a tablet with a keyboard. This means that we cannot really use one for getting all those tough jobs done, like doing design, producing super-cool presentations or maintaining a company network, for example. In other words, at this stage, the Chromebook is for of a casual internet surfer's mini-computer and can supply the needs of a student who needs to get some research and textual work done. That is not to say that we cannot do more than that, but the fact remains, the Chromebook is not for the mobile warrior.
  • Cheap or Expensive.Google is shipping Chromebooks with payment plans that seem very attractive. Business can have them for about 30 dollars a month over 3 years, and students can get them for about 20 dollars a month for the same period of time. This includes all hardware and software updates. In reality, there will be no hardware updates, and software updates do not exist because there is nothing on the machine to be updated. When Chrome OS or applications are updated, they will not be on your computer anyway. While the price seems very cheap, considering what we are getting for our money, we could be buying a cheaper tablet for much less money. Only if Chrome OS and the applications improve greatly in a very short period of time, will we be getting the amazing deal it sounds like. Remember, the Chromebook is still not a replacement of a personal computer and running something like the new Windows 8 upgrade with improved features. As a matter of fact, it is nothing like a personal computer yet. It is like an oversized smartphone with a keyboard. Other operating system upgrades are usually very cheap, and updates and application updates, such as the Windows 8 upgrade, are cheap or already included in the original price.

  • Internet Relative.Google Apps are numerous and if you are used to using the Google system of getting things done like using Gmail, Docs, and all that comes with it, you are probably used to Google Apps. There are applications to allow you to edit photos and movies, for example. At the same time, if your internet connection is not superfast, using these online applications can be a little frustrating for even novice users. Chromebooks come with 100G of online access per month, and this could easily be used up by someone, if they were a heavy user. 3g users know that some applications do not work as well as with other types of applications. VOIP calling applications still do not have the quality over 3g wireless networks like they do with land-based broadband and cable networks.
If you think a Chromebook is a personal computer, as it stands, you are mistaken. It would be great to see the Chromebook provide the same user experience and features of a personal computer, and this is also further dependent on the speed and stability of wireless networks. It is doubtful wireless 3g or 4g networks will improve to match cable stability and speed for some time to come, if ever.

Accompany Facebook Pages Secretly [How To]

Accompany Facebook Pages Secretly [How To]


follow facebook pages secretly Follow Facebook Pages Secretly [How To]
This post would be helpful to those Facebook users who don’t would like to impart what Facebook pages they are emulating to their contacts. It perhaps owed business explanations, or a political stunt, or would be you need to conceal any page taking after from your ma. Your security can be kept up hence following perusing this piece. But also yes, you are just 4 strides at a distance from taking after Facebook pages namelessly.

Tricks to follow Facebook Pages Secretly :

FIRST OF ALL :-
The primary thing to do is to pilot the Facebook page that you have a desire to take after covertly. Recall, the page might as well have a ‘Wall’ so that
the overhauls of it comes your direction. Typically, the vast majority of the conglomerations, either medium or impressive, do have a ‘Wall’ on their Facebook page.SECONDLY :
Parchment down the Facebook page that you yearning to accompany furtively and recognize “Subscribe via RSS”. It should be on the other side sidebar in the middle of
‘Create a Page’ and ‘Report Page’.follow facebook pages secretly Follow Facebook Pages Secretly [How To] 
THIRDLY :
Basically right-click on ‘Subscribe via RSS’ channel. Some program might have order-click as a substitute for right-click. Select there ‘Copy channel address' or its comparable of your browser.
AT LAST :
Now head off to your best RSS book lover for example Google Reader and glue the connection in the ‘Add newfangled subscription’ field. Countless folks don’t have RSS bookworm. Making one is exceptionally straightforward. In the event that you feel a distinct desire to have Google Reader, basically on any Google record page for example Gmail and there you possess the choice of Google Reader.
That would be all. Now you hold the protection to accompany any Facebook page subtly without working toward getting tracked by any of your contacts. Do remark beneath your tips and tricks about Facebook.

Step by step instructions to Keep Facebook Newsfeed Clean

Step by step instructions to Keep Facebook Newsfeed Clean


mr clean facebook How To Keep Facebook Newsfeed Clean
Facebook food could frequently be bothering to you. You would not be able to be needing the sustains according to your wish. What you do then? Here are few tips what to do to keep the Facebook food clean according to your prerequisite.
First and foremost click on the “Most Recent” choice in the News Feed. This will prepare the legit-time review of every last trace of the exercises of your associates. Anyway, Facebook indicates here just exercises presents of those mates with whom you interface the most. Now you could probably update this setting. Head off to the ‘Edit Options' of ‘Most Recent’ and afterward click on ‘Show presents from the sum total of your mates and pages.’ This will empower review every last trace of the exercises of all mates and pages as it happens. Well, this might be small feverish for you. Here is the means by which you are able to refine promote this view.
You are able to conceal your companions from the food. Since you don’t need someones upgrades like Italian pizza is unbelievable! or Lolz m laughing almost too hard, essentially conceal such individual from the food. Basically float your rodent over any overhaul of the individual and click on the Cross symbol. You could probably conceal one exclusive upgrade or the sum total of the overhauls of the individual or page. The contact will never approach have prior experience with it. Isn't this is too much intriguing.mr clean facebook How To Keep Facebook Newsfeed Clean
You can also hide the same way in applications such as FarmVille or Twitter.
Now, filter the feeds or posts by category you choose. Go to ‘Most Recent’ and from the option you just filter the feed as – by photos, by links, by status updates, and more.
Suppose you want to have the feeds of limited people and not all such as only the activities of your family members or school buddies. Just go to Account at right top corner and click on Edit Friends. There you have an option ‘Create a List’. Submit title list there and select the contacts whose news feed you want to see on your wall. After doing it, go back to the ‘Most Recent’ and there you will see the friends list. It will be at the bottom of the drop-down. Click on it and you are done.
Here you can play one more trick. You can put all the brands and media pages into a list and then through RSS of the Facebook you can get the updates on your reader such as Google Reader.
Also Read : How to Follow Facebook Pages Secretly
If all these still confusing to you, delete all the friends, pages and apps that you don’t need in your contact or you don’t care about. Simple.
Do comment below about your ways of keeping the newsfeed clean according to your parameters.

To Get Old Version OF Facebook Chat Back

To Get Old Version OF Facebook Chat Back


Get Old Facebook Chat How To Get Old Facebook Chat Back

Get Old Facebook Chat Back …. ?? Yes its possible.

You love Facebook but you may hate few of its features, and probably, as to many, the recent roll-out of video calling feature. With this, Facebook also rolled out a new chat sidebar, and this is sometime annoying to many.
It is no new that Facebook sometimes annoy people with its newer design changes. Last time it annoyed its users with image viewer feature called Facebook Theater mode.
Now, how to get back the old Facebook chat design which were eye-soothing and people were more comfortable to it than the newer one. Here is the answer how you can get back the old Facebook chat.
Get Old Facebook Chat How To Get Old Facebook Chat Back
Image Credit : Proknowliz
1) First login into your Facebook account, and then open a new tab. Open below link in the new tab:
http://www.facebook.com/presence/popout.php
Here you will get back the old Facebook chat where the online and offline contacts are sorted out.
However, this is not the perfect solution to it as everytime you have to open the link in a new tab. Below is a better option:
2) Install Greasemonkey script from the below link and restart your browser:
http://userscripts.org/scripts/show/107159
There is one more way for getting back the old Facebook chat on different browsers. Install the below given addons on your respective browsers:
Google Chrome - https://chrome.google.com/webstore/detail/bfipfkeoidmndggnnpobeenlamiclald
Mozilla Firefox - https://addons.mozilla.org/en-US/firefox/addon/fb-chat-sidebar-disabler/
Opera - https://addons.opera.com/addons/extensions/details/facebook-chat-sidebar-disabler/1.3/?display=en
Why people want to go back to old Facebook chat is a big question if you are not aware of the disadvantages. Below are the details of disadvantages:
Every time you login into your Facebook account you have to manually disable the Sidebar Chat if you are not liking it.
The new chat only shows list of those contacts of yours with whom you interact most. It shows them even if they are offline. This may be annoying to you sometimes.
Online and offline list of contacts are unordered. It needs to be sorted in manner.
Do comment below what you say about the new Facebook chat feature. Are you liking it? If no, then what are the other ways, you might be knowing, to get back to old Facebook chat.

Sunday, 24 July 2011

Facebook Launches Open Compute Project

Facebook Launches Open Compute Project


"Facebook and our development partners have invested tens of millions of dollars over the past two years to build upon industry specifications to create the most efficient computing infrastructure possible," said Jonathan Heiliger, vice president of technical operations at Facebook. "These advancements are good for Facebook, but we think they could benefit all companies. Today we're launching the Open Compute Project, a user-led forum, to share our designs and collaborate with anyone interested in highly efficient server and data center designs. We think it's time to demystify the biggest capital expense of an online business -- the infrastructure."
Inspired by the success of open source software, Facebook is publishing technical specifications and mechanical CAD files for the Prineville data center's servers, power supplies, server racks, battery backup systems and building design. This technology enabled the data center to achieve an initial power usage effectiveness (PUE) ratio of 1.07, compared with 1.5 for our existing facilities, which fall into the "best practice" category as defined by the U.S. Environmental Protection Agency*. Established by the Green Grid in 2007, PUE is an indicator of data center energy efficiency, and the lower the number, the better.
Facebook is releasing these designs as open hardware, aiming to encourage industry-wide collaboration around best practices for data center and server technology.
Advanced Micro Devices, Dell, HP and Intel are among the companies that co-developed technology with Facebook. In addition, Dell's Data Center Solutions business will design and build servers based on the Open Compute Project specification. Synnex Corporation will also serve as a vendor for Open Compute Project servers, offering fully integrated and tested solutions based on customers' specifications.
For Facebook's data center in Prineville, Open Compute Project hardware delivered:
Energy savings—The data center uses 38 percent less energy to do the same work as Facebook's exiting facilities. If a quarter of the data center capacity in the U.S. were built on Open Compute Project specifications, it would save enough energy to power more than 160,000 homes.
Cost savings—In addition to the energy savings, Open Compute Project hardware means data center infrastructure costs 24 percent less to build out than Facebook's existing data centers.
Materials savings—Servers use a vanity-free design with no paint, logos, stickers, or front panel – and are free of all non-essential parts. This saves more than 6 pounds of materials per server. In a typical data center**, this would save more than 120 tons of material from being manufactured, transported, and, ultimately, discarded.
Facebook is publishing specifications and mechanical designs for Open Compute Project hardware, including motherboards, power supply, server chassis, and server and battery cabinets. In addition, Facebook is making available its data center electrical and mechanical construction specifications.
Additional materials: More information about the project, specifications and CAD files are available at http://opencompute.org/ Facebook Engineering page at http://www.facebook.com/Engineering
Industry Support:
"Our long-standing, productive relationship with Facebook is a point of pride for AMD, and we are equally proud to participate in the Open Compute Project. We applaud Facebook for bringing all of these companies together towards further collaboration and development of the future of computing." Patrick Patla, General Manager and Corporate Vice President of server and embedded solutions, AMD
"Facebook has been a great customer of Dell and one of our closest collaborators in pushing the limits of server design and architecture, while pushing the envelope for data center management and energy efficiency. Dell's Data Center Solutions (DCS) business has designed and built servers based on Facebook's Open Compute specification." Forrest Norrod, Vice President and General Manager for Worldwide Server Platforms, Dell
"Data centers provide the foundation for the efficient, high quality services our customers have come to expect. Facebook has contributed advanced reference designs for ongoing data center and hardware innovation. We look forward to collaborating with like-minded technology providers and partners as we seek ways to learn from and further advance these designs." George Brady, Executive Vice President, Technology Infrastructure, Fidelity Investments
"Goldman Sachs is pleased to be working with Facebook on the Open Compute Project," said Don Duet. "Our team has already visited Facebook's hardware design lab in Palo Alto and we look forward to working together to significantly increase the efficiency of servers and hardware in data centers." Don Duet, Global Head of Technology Infrastructure, Compliance, and Market Risk Technology, Goldman Sachs
"Companies with extreme computing needs continue to seek innovative technology that extends the boundaries of what is possible today while challenging their partners to reach new lows in energy usage. HP is looking forward to working with Facebook on the Open Compute Project to increase power efficiency in the most intense computing environments where performance is critical." Greg Huff, Chief Technology Officer, Industry Standard Servers and Software, HP
"Intel is a proud supporter and technology enabler of Facebook's mission to connect the world. We've worked with Facebook for the past 18 months to optimize performance per watt and develop a highly efficient board design. The combination of performance gains through Intel Xeon processors combined with Facebook's aggressive power optimization has resulted in a 60 percent reduction in power consumption per user. The collaborative effort pushed Intel to deliver technology for greater efficiency, which will ultimately benefit a broad base of data centers across the globe." Jason Waxman, General Manager, High Density Computing, Data Center Group, Intel
"Open technology standards and industry collaboration accelerate innovation and better serve our customers. We enthusiastically support the Open Compute Project, for the same reasons that we launched OpenStack, the industry's fastest-growing open source cloud project. The Rackspace team has visited and studied Facebook's next-generation data center, our engineers continue to collaborate, and we look forward to optimizing OpenStack for Open Compute." Lanham Napier, Chief Executive Officer, Rackspace Hosting
"We at Synnex Corporation are very excited to be a part of Facebook's ground breaking effort to improve data center efficiency. We will use our design and integration services and logistics infrastructure to make this technology advancement available to a wide user base." Steve Ichinaga, Senior Vice President and General Manager of System Integration, Synnex Corporation
"We are focused on building a flexible, scalable and efficient infrastructure which enables us to deliver the best experience to over 250 million people who play Zynga games. We look forward to working with the Open Compute Project to exchange best practices and help the entire industry advance in the areas of power efficiency, design and manageability." Cadir Lee, Chief Technology Officer, Zynga
Environmental support:
"We at the Alliance to Save Energy are honored to partner with Facebook to increase awareness and the adoption of technologies and practices to encourage millions of people to become more energy efficient. We applaud Facebook and their industry partners for this terrific effort to transform the energy efficiency of global data centers through their Open Compute Project. This initiative is critically important because it will dramatically increase energy efficiency, lower costs and -- best of all – offers the design of this technology for free via the web to anyone who wants it." Kateri Callahan, President, Alliance to Save Energy
"Computer systems today are about 3,000,000 percent more energy efficient than they were 30 years ago. Facebook and other DESC members are bringing this same innovation capability now to data center resource efficiency. We applaud them for this important work to make our data centers more efficient, which delivers environmental benefits and cost savings for everyone." Chris Hankin, Executive Director, Digital Energy Solutions Campaign
"The Green Grid has championed PUE as a consistent data center energy efficiency metric, and we applaud Facebook's efforts to drive data centers globally towards a marked increase in resource efficiency. The entire industry benefits from The Green Grid's tools, training, and global collaboration, as organizations such as Facebook apply these methods to transform data centers from an operational burden to a source of economic prosperity and ecologic sustainability." Mukesh Khattar, Oracle representative and Board member of The Green Grid * Source: Report to Congress on Server and Data Center Energy Efficiency Public Law 109-431, U.S. Environmental Protection Agency ENERGY STAR Program ** Assuming a data center size of 40,000 servers

Saturday, 11 June 2011

Facebook's New Messaging Service (Please Don't Call It E-Mail)

http://static.guim.co.uk/sys-images/Guardian/Pix/pictures/2010/7/9/1278696340813/Mark-Zuckerberg-Facebook-006.jpg
For months, there have been rumors that Facebook was working on turning the inboxes of its 500 million-plus users into a full-blown e-mail service.
Today, Facebook founder/CEO Mark Zuckerberg formally unveiled the subject of the rumors--code-named "Titan" and officially named simply "Facebook Messages"--at an event in San Francisco. And he spent much of his time stressing that whatever this new thing is, it's not e-mail.

Instead, it's a massive update to Facebook's current messaging system, chat feature, text-messaging integration, and smartphone applications that mashes up all sorts of communications (including e-mail) into one unified stream. Zuckerberg and Facebook engineering honcho Andrew Bosworth mostly talked about the service rather than demoing it, but they said that it'll include features such as these:
  • Every Facebook user will get an e-mail address: If your Facebook profile is located at facebook.com/yournamehere, your e-mail address will be yournamehere@facebook.com.
  • If you're logged into Facebook, incoming e-mail will show up in the service's chat service; reply to a message, and it'll be sent as an e-mail.
  • Similarly, the Facebook iPhone app will notify you of e-mail and let you receive and send messages. (An Android version will come along later.)
  • In a feature that sounds a little like Google's Priority Inbox, you can organize the people you receive messages from into important folks (friends and family), others who aren't so vital (your credit card company, say), and Junk. The goal is let you see stuff you really want to see immediately, allow you to check in on less urgent messages once a day, and ignore spam.
  • You can also choose to have messages from people not on your Facebook friends list bounced, period.
  • Like e-mail, Facebook messages will be able to include file attachments; a deal with Microsoft will let you edit documents using the Office Web Apps online suite.
  • The service will go beyond threaded-message interfaces such as Gmail's Conversations by letting you scroll back through all the communications you've had with a particular person via Facebook, all in one place. (You'll be able to opt out of this--or skip all the new features, period--but that presumably won't be enough to satisfy every privacy watchdog out there. In fact, I can hear them growling from here.)
Zuck and Bosworth explained that all this is in part a reaction to the needs of folks younger than themselves--Facebook-and-text-message-loving high schoolers who find e-mail too slow and too isolated from the rest of their communications. They seemed awfully confident that they've come up with something better than e-mail, in a way that left me flashing back to last year's launch of Google's spectacularly unsuccessful Wave. But while Wave suffered from having far too many features, Zuck says part of the goal with this new messaging service is to have fewer features than e-mail. And from what we saw this morning, it does indeed seem to have a minimalist, IM-like feel.

Three hundred and fifty million of Facebook's half-a-billion-plus members are active users of its messaging tools in their current form, and the service delivers four billion private messages a day. The company isn't going to spring all these new features on everybody all at once: Instead, it'll roll them out gradually over the next few months. Only a few folks will get them starting today.
In the end, all this sounds like...well, like another attempt to improve e-mail. And even though e-mail is rife with weaknesses, it keeps on keeping on even while supposedly better alternatives crash and burn.
The good news is every aspect of Facebook is subject to continuous revision; if you don't like this service in its initial form, just wait. Unlike Wave, which was an all-new effort, this is an upgrade to Facebook's existing messaging features, so it'll surely be around for the long haul.

Tuesday, 8 February 2011

What To Do If Someone Else is Using Your Facebook Account?


http://www.techlivez.com/wp-content/uploads/2011/02/Facebook-logo.jpg
What if someone else sneaks into your Facebook account? Well, this could be a quite serious situation. In this article we will cover some simple steps you should follow in such situation.
But before that let’s see how to find out if someone else is using your Facebook Account.
  • Login to your Facebook account.
  • Click Account >> Account Settings >> Security.
  • Watch carefully and compare the devices, browsers, locations, and timings of your previous logins , if they mismatch then someone else has sneaked into your account.
Facebook-Account-security-features
If such a situation arrives then here are some immediate-basic steps you should take:
  • Change the password of your account.
  • Go to Account >> Account Settings >> Security.
  • Click on “end activity”, in case you see other suspicious active accounts.
  • Check “Send me an email” and “Send me a text message”, and click “Save”.
Now you will get an email and SMS alert every single time anyone login to your Facebook account.
Here is a video tutorial for some advanced Facebook security features:

Note: At the moment one time password and secure browsing features are only available in US.

Saturday, 5 February 2011

Informatics students discover, alert Facebook to threat allowing access to private data, bogus messaging

http://cdn.physorg.com/newman/gfx/news/informaticss.jpg
A Facebook security vulnerability discovered by a pair of doctoral students at Indiana University Bloomington's School of Informatics and Computing that allowed malicious websites to uncover a visitor's real name, access their private data and post bogus content on their behalf has been repaired, Facebook has confirmed.
The vulnerability discovered by Rui Wang and Zhou Li enabled malicious websites to impersonate legitimate websites, and then obtain the same data access permissions on Facebook that those legitimate websites had received.
Wang and Li said the vulnerability occurred when a user informed Facebook of his or her willingness to share information with popular websites like ESPN.com or YouTube. Whenever a website makes such a request to Facebook via the user's browser, Facebook passes a secret random string called an authentication token back to the requestor for identification. Whoever holds that authentication token can convince Facebook that they are, say, ESPN.com and then gain unfettered access to the shared data.
Facebook confirmed the discovery and in a statement said the problem was repaired and that the belief was that no sites had been compromised.
"Researchers at Indiana University reported a vulnerability in our Platform code to us, and we worked quickly with them to resolve it. It was fixed shortly after it was reported. We're not aware of any cases in which it was used maliciously," the statement said. "We thank the researchers at Indiana University for bringing this to our attention, and for demonstrating the value of responsible disclosure."
The researchers identified a flaw in the way the token was transmitted using two Flash objects: one inside Facebook's iframe passes the token to the second, which in this case would be embedded at ESPN.com. The transfer mode can be selected through "transport='flash'" with the security guarantee being that both flash objects are supposed to come from the same domain (i.e., Facebook) before they can talk.
The researchers found, however, that such a same-domain assumption is not always valid because Adobe Flash allows cross-domain communication with an unpredictable domain name that is prepended by an underscore symbol in the connection name. This allows an attacker website to steal an authentication token by choosing the transport='flash,' replacing the receiver flash with its own and then initiating a cross-domain communication with the flash inside the Facebook-controlled iframe to get the token and send it to the attacker's flash.
"This vulnerability has several implications," Wang said. "Basically, any user with a valid Facebook session loses anonymity and privacy to any website, even one with embarrassing or sensitive content."
Facebook allows some websites like bing.com to directly access a user's public data without explicit consent. This enables the malicious website impersonating that site to do the same. Moreover, if the user has ever granted any website, such as The New York Times, YouTube, Farmville or ESPN, the permission to connect to their Facebook account, further damage can be inflicted, including disclosure of private data that the user does not want to share with others, and impersonation of the user to post bogus news or comments on friends' walls. This form of propagation resembles the famous MySpace worm released in 2005, they said.
"Our attack utilized a feature of Adobe Flash called unpredictable communication, and an important distinction between an unpredictable communication and a normal communication is that the former is done through a connection where the name starts with an underscore symbol," Li said. "Therefore, Facebook could check for this symbol to determine if a potentially malicious website tries to do unpredictable communication."
And that is exactly what Facebook started to do once they were alerted to the problem by Wang and Li, who were working under the supervision of School of Informatics and Computing Associate Professor XiaoFeng Wang and Shuo Chen, a researcher in Microsoft Research's Internet Services Research Center.
XiaoFeng Wang, the students' adviser, said Facebook relies on same-domain communications that allow websites to specify Adobe Flash as the communication mechanism.
"In a normal situation, two flash objects can only do same-domain communications, and, in fact, security of Facebook's authentication crucially depends on same-domain restrictions," he explained. "However, Facebook allowed the Adobe Flash communication mechanism but did not disallow the unpredictable domain names. This is how a malicious website could establish a channel to enable two flash objects in different domains to communicate."
To portray the seriousness of the vulnerability, the team made a video demo that can be viewed here.
Facebook officials noted that a contact form at both the Facebook Help Center and from the "Whitehats" tab on the Facebook Security Page are available in the rare instances in which vulnerabilities are found.
"We also recently rewrote our responsible disclosure policy to make it even easier for researchers to let us know when they find a vulnerability, so we can fix it quickly and before it's exploited. Our new policy was praised by the Electronic Frontier Foundation in a recent blog post here," the statement said.