Monday, June 08, 2009

Facebook Privacy Flaw - Disable CSS to view Private Accounts.

I was playing around with some new web developer addons in my Firefox while on Facebook and I pressed a key combination which disabled the CSS styles for currently opened tab of Facebook. I was on a profile page of someone who has set their details not to appear if the viewer is not her friend. I just scrolled down and saw the profile picture of that person which really amazed me to see something that wasn't there before (in normal layout).

I tried this on a few other private profiles and everytime I was able see the profile pictures of those who were not my friends. Apparently, facebook hides the information (display pictures) using CSS! How ridiculas can it be! I think of it as a serious privacy flaw.

0 comments: