Facebook Friending Fluke?

Is there a major security breach in Facebook’s mutual friending system? An article over at Loose Wire indicates that an engineering loophole has rendered it possible for someone to add another Facebook user to their friend list without mutual consent. Facebook’s mutual friending system can get a little tricky at times, but this particular fluke could be worrisome.

When Jeremy of Loose Wire received a Facebook invite in his email inbox from someone he didn’t know, he was perplexed, since he’s already a Facebook member. But he clicked on the invite link, which directed him to the regular Facebook login page. After logging in, he didn’t see any more information on the person that had sent him the Facebook invite. Jeremy then Googled the invitee’s name and found that he was already on this person’s friends list.

The odd thing is that the invitee was not, however, on Jeremy’s friends list, meaning the friendship was not mutual. The worrisome part about it all? The invitee could now see all of Jeremy’s profile information, and Jeremy could see none of his.

While this fluke has yet to be confirmed, there are a few standing issues regardless. Assuming that the email address Jeremy received the invite through is also the email address he’s associated with his Facebook account, then he shouldn’t be receiving invites from other Facebook users in the first place. Red flag #1.

Even legitimate Facebook invites typically don’t provide direct links to the invitee’s profile, so being redirected to the login page isn’t entirely atypical. But being on the invitee’s friend list without having them on your friends list is red flag #2.

The confusing aspect of this is the fact that certain actions on Facebook enable a user to view someone else’s profile for a definite amount of time, even if they’re not mutual friends. Should this be the case, then Jeremy’s situation could in fact be a friending “loophole” that seems to violate certain privacy standards found on Facebook. This may be something that Facebook needs to look into, especially if “fake invites” are at the core of this fluke.

  Tags:, , ,



Recommended Articles


Announcing The AllFacebook Marketing Conference 2012

The AllFacebook Marketing Conference is coming back to San Francisco on June 28-29. We are proud to announce our second conference that offers a how-to guide for marketing to Facebook’s 800 million users. Special early pricing is available for only $199 until today, so register now. A full agenda will be announced soon. Keep an eye on our event site for more information

1 Comment »

  1. I can’t log on to my facebook!
    Despite entering my user-name and password, im being redirected to the log-in page.
    Help Please -.-

    Comment by Callie — September 23, 2009 @ 7:16 am

RSS feed for comments on this post. TrackBack URL

Leave a comment

Send us a Tip

tips@allfacebook.com
[Inside Social Apps 2012]
[AllFacebook Stats: Facebook Analytics for Your Business]
[How can Facebook change your business?]

Upcoming Events

Inside Social Apps

February 8-9, 2012 | San Francisco

Inside Social Apps

Developing & monetizing on social & mobile platforms

Social Gaming Summit

23-24 May, 2012 | Berlin

Social Gaming Summit

Where Gaming Meets the Social Web

AllFacebook Marketing Conference

June 28-29, 2012 | San Francisco

AllFacebook Marketing Conference

Your how-to guide for Facebook marketing.