{"id":23689,"date":"2010-11-09T11:11:00","date_gmt":"2010-11-09T07:11:00","guid":{"rendered":"http:\/\/localhost\/?p=23689"},"modified":"2010-11-09T12:11:27","modified_gmt":"2010-11-09T08:11:27","slug":"facebooks-api-may-expose-private-status-updates","status":"publish","type":"magazine","link":"https:\/\/brainstation.io\/magazine\/facebooks-api-may-expose-private-status-updates","title":{"rendered":"Facebook&#8217;s API May Expose Private Status Updates"},"content":{"rendered":"<p>Facebook users who rely on the social network site&#8217;s ability to make status updates visible only to certain people may find their posts exposed publicly.<\/p>\n<p>Technology expert Tod Maffin discovered the flaw while using a email marketing system that relies on Facebook&#8217;s API.&nbsp;<\/p>\n<p>Maffin says he relies on Facebook&#8217;s &#8220;Make visible to&#8221; feature in the Status Update post box to restrict his status updates &mdash; some of his more personal updates are sent only to those on his &#8220;Close Friends&#8221; and &#8220;Family&#8221; friend lists. However, when using the email marketing system, he discovered that the site pulled all status messages, regardless of any restriction, from Facebook&#8217;s Application Programming Interface (API), a system through which web sites exchange data.<\/p>\n<p>&#8220;I was pretty stunned,&#8221; said Maffin, senior strategiest and COO of tMedia Strategies in Vancouver. &#8220;All this time, I&#8217;d assumed those posts were kept off any sort of public feed.&#8221;<\/p>\n<p>Maffin uses Mailchimp for his email marketing campaigns. The email provider uses codes to pull dynamic content from social media sites like the sender&#8217;s most recent tweets or most recent Facebook posts. Facebook&#8217;s code appears to distribute all status updates, regardless of any restriction setting, to applications using its API. This is not specific to Mailchimp; any web application relying on Facebook&#8217;s API would be able to read this content, provided the application is authorized with Facebook (which is necessary to be able to dynamically link Facebook content).<\/p>\n<p>Maffin has documented the flaw on his website at <a href=\"http:\/\/www.todmaffin.com\/friendsplittingbug\">www.todmaffin.com\/friendsplittingbug<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Facebook users who rely on the social network site&#8217;s ability to make status updates visible only to certain people may find their posts exposed publicly. Technology expert Tod Maffin discovered the flaw while using a email marketing system that relies on Facebook&#8217;s API.&nbsp; Maffin says he relies on Facebook&#8217;s &#8220;Make visible to&#8221; feature in the [&hellip;]<\/p>\n","protected":false},"author":1358,"featured_media":23691,"menu_order":0,"template":"","meta":{"_acf_changed":false,"footnotes":""},"categories":[],"tags":[],"magazine-region":[],"magazine-series":[],"magazine-topic":[],"class_list":["post-23689","magazine","type-magazine","status-publish","has-post-thumbnail","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/brainstation.io\/wp\/api\/wp\/v2\/magazine\/23689","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/brainstation.io\/wp\/api\/wp\/v2\/magazine"}],"about":[{"href":"https:\/\/brainstation.io\/wp\/api\/wp\/v2\/types\/magazine"}],"author":[{"embeddable":true,"href":"https:\/\/brainstation.io\/wp\/api\/wp\/v2\/users\/1358"}],"version-history":[{"count":0,"href":"https:\/\/brainstation.io\/wp\/api\/wp\/v2\/magazine\/23689\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/brainstation.io\/wp\/api\/"}],"wp:attachment":[{"href":"https:\/\/brainstation.io\/wp\/api\/wp\/v2\/media?parent=23689"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/brainstation.io\/wp\/api\/wp\/v2\/categories?post=23689"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/brainstation.io\/wp\/api\/wp\/v2\/tags?post=23689"},{"taxonomy":"magazine-region","embeddable":true,"href":"https:\/\/brainstation.io\/wp\/api\/wp\/v2\/magazine-region?post=23689"},{"taxonomy":"magazine-series","embeddable":true,"href":"https:\/\/brainstation.io\/wp\/api\/wp\/v2\/magazine-series?post=23689"},{"taxonomy":"magazine-topic","embeddable":true,"href":"https:\/\/brainstation.io\/wp\/api\/wp\/v2\/magazine-topic?post=23689"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}