Earlier quoted context omitted.
I disagree. See: Airport Security.
Yup, there you're trading off security for theater.
Deceiving Users with the Facebook Like Button
11–20 of 21 posts
Re: Deceiving Users with the Facebook Like Button
#12not a terrible confusion or potentially too sinister, but a bit more attention than usual is required than the simple share.
Re: Deceiving Users with the Facebook Like Button
#13As the author points out, the easy fix is to let users know what they just liked, or ask them to confirm. Also I suspect this service is fairly self-regulating. Facebook users are generally careful about what they broadcast. The author gives the captcha trick used by porn sites as an example...how many people are going to broadcast their taste in porn?
there are already lots of spam websites and fb apps, that trick into being a fan... i mean, "like" pages using js. this iframe only makes it easier.
i can even imagine spam js links altering a legit iframe, hoping a user clicks it afterwards.
Re: Deceiving Users with the Facebook Like Button
#14As the author points out, the easy fix is to let users know what they just liked, or ask them to confirm. Also I suspect this service is fairly self-regulating. Facebook users are generally careful about what they broadcast. The author gives the captcha trick used by porn sites as an example...how many people are going to broadcast their taste in porn?
I see this story come up a lot, but according to reCAPTCHA, it's an urban legend. There is not really any evidence that spammers actually do this at all, let alone do it on a meaningful scale.
Re: Deceiving Users with the Facebook Like Button
#15As the author points out, the easy fix is to let users know what they just liked, or ask them to confirm. Also I suspect this service is fairly self-regulating. Facebook users are generally careful about what they broadcast. The author gives the captcha trick used by porn sites as an example...how many people are going to broadcast their taste in porn?
Seriously? Maybe among your tech-savvy friends, but the majority of Facebook users have no idea what they're doing when they type something into the box and click "Share."
A few minutes over at http://failbook.com/ is enough to point that out, and those are just the egregiously bad / hilarious cases.
Re: Deceiving Users with the Facebook Like Button
#16Re: Deceiving Users with the Facebook Like Button
#17Re: Deceiving Users with the Facebook Like Button
#18Sure, the referrer can be spoofed if you can set arbitrary headers, but you can't set headers on iframe requests anyway (and even XHR explicitly disallows setting Referer)
Re: Deceiving Users with the Facebook Like Button
#19Re: Deceiving Users with the Facebook Like Button
#20A related side-note: my organization blocks access to Facebook, the iframe with his like button was also blocked by the filter.