<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Facebook&#8217;s lax security</title>
	<atom:link href="http://cubist.cs.washington.edu/Security/2009/03/08/facebooks-lax-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://cubist.cs.washington.edu/Security/2009/03/08/facebooks-lax-security/</link>
	<description></description>
	<lastBuildDate>Mon, 25 May 2009 11:35:08 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Father_Of_1000000</title>
		<link>http://cubist.cs.washington.edu/Security/2009/03/08/facebooks-lax-security/comment-page-1/#comment-8072</link>
		<dc:creator>Father_Of_1000000</dc:creator>
		<pubDate>Thu, 12 Mar 2009 00:13:55 +0000</pubDate>
		<guid isPermaLink="false">http://cubist.cs.washington.edu/Security/?p=1050#comment-8072</guid>
		<description>The problem with facebook apps is there are too many applications for facebook to monitor and test. One way to reduce the problem is to not have anyone being able to write apps for facebook. Only give &quot;privileged&quot; users the option to do so. That can be in the form of having the user submit their real identity. In that way, attackers can be easily traced to their real identity.

Another idea is to have a large user community to monitor each other&#039;s applications. So for an app to go public, we need at least x number of users in the community approve it after using it and testing it.</description>
		<content:encoded><![CDATA[<p>The problem with facebook apps is there are too many applications for facebook to monitor and test. One way to reduce the problem is to not have anyone being able to write apps for facebook. Only give &#8220;privileged&#8221; users the option to do so. That can be in the form of having the user submit their real identity. In that way, attackers can be easily traced to their real identity.</p>
<p>Another idea is to have a large user community to monitor each other&#8217;s applications. So for an app to go public, we need at least x number of users in the community approve it after using it and testing it.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
