Home / Blogs

Facebook Apps on Any Website: A Clever Move? Or a Security Nightmare?

Fergie

Well, given the amount of malicious JavaScript, malware, and other possibilities to use Facebook (and other similar social networking platforms) for abuse, I certainly wouldn't categorize this news as a "clever move".

The announcement says, in part, that:

...JavaScript client library allows you to make Facebook API calls from any web site and makes it easy to create Ajax Facebook applications. Since the library does not require any server-side code on your server, you can now create a Facebook application that can be hosted on any web site that serves static HTML. An application that uses this client library should be registered as an iframe type. This applies to either iframe Facebook apps that users access through the Facebook web site or apps that users access directly on the app's own web sites. Almost all Facebook APIs are supported.

In fact, I foresee this as an extraordinarily short-sighted move with far-reaching security implications — which will allow the levels of malicious abuse to reach new heights.

In fact, minor annoyances such as this may become fond memories, as this new "feature" will allow miscreants to create much more malicious functionality.

So, this is a forecast placeholder for me — we'll have to look back on my prediction at some point in the future to see if I'm right, or not.

By Fergie, Advanced Threats Researcher, Emerging Threats & Operational Intelligence. Visit the blog maintained by Fergie here.

Related topics: Malware, Security, Web

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

To post comments, please login or create an account.

Related Blogs

The Antivirus Uncertainty Principle

Facebook Size Estimates

So/Lo/Mo for Business

Rethinking Protection Technologies: A Change Has Occurred

Cel-e-brate v6, Come On!

Related News

Topics

Industry Updates – Sponsored Posts

Nominum Launches 1st Comprehensive Mobile Security Solution That Protects Both Network and End User

Frontline and Nominum Deliver Integrated DNS-Based Platform to Enhance Enterprise Security

Nominum Launches Comprehensive Suite of DNS-Based Security Solutions for Russian Service Providers

Nominum Sets New Record for Network Speed and Efficiency

Implementing a Cyber-Security Code of Conduct: Real-Life Lessons From Australia (Webinar)

Google Mobile Website Initiative for German-Speaking Market Launches With goMobi Website Builder

DDoS Attacks: Top 10 Trends and Truths (Video)

DDoS Attacks: Top Trends and Truths (Webinar)

goMobi and Google to Help UK Companies Get on the Mobile Web

Internet Grows to More Than 225 Million Domain Names in the Fourth Quarter of 2011

Neustar UltraDNS Basic Launches Add-On Services for Website Monitoring and DNS Server Failover

Neustar And Arbor Networks Cloud Signaling Coalition to Stop Evolving DDoS Threat to Data Centers

Usablenet Partners With dotMobi for Mobile Device Detection

Nominum Launches World's First Purpose-Built Suite of DNS‐Based Solutions for Mobile Operators

Neustar Announces Partnership with the National Small Business Association

MarkMonitor Fraud Intelligence Report, Q4 2011

dotMobi And LuxCloud Collaborate on Integration of goMobi Onto LuxCloud SaaS Platform

2011 Half a Billion Handset and Smartphone Sales: The Big Picture

MarkMonitor to Exhibit at Internet Tech Policy Exhibition and Reception to be Held on Capitol Hill

Verisign to Award New Infrastructure Research Grants

Hot Topics

Nominum

IPv6

Sponsored by
Nominum
Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines
Neustar UltraDNS

DNS

Sponsored by
Neustar UltraDNS
Verisign

Security

Sponsored by
Verisign
Afilias

DNS Security

Sponsored by
Afilias
dotMobi

Mobile

Sponsored by
dotMobi