Why there will not be facebook connect on my site

The following is why there will not be a facebook connect on my site.  We may allow Open ID connect in the future; Open ID is the only single sign-on that would be considered.  Forget Facebook, Twitter, Microsoft, google+ and any other.

 

Note the part that stated the bug has been live for a whole year; and they just now fixed it because it was brought to their attention.

 

"A Facebook security bug exposed users’ personal contact information (email or phone number) to other users who were connected to them; the bug has affected 6 million accounts.

“When people upload their contact lists or address books to Facebook, we try to match that data with the contact information of other people on Facebook in order to generate friend recommendations,” the security team wrote in a blog post published today.

“Because of the bug, some of the information used to make friend recommendations and reduce the number of invitations we send was inadvertently stored in association with people’s contact information as part of their account on Facebook,” the post continued. “As a result, if a person went to download an archive of their Facebook account through our Download Your Information (DYI) tool, they may have been provided with additional email addresses or telephone numbers for their contacts or people with whom they have some connection.”

A Facebook spokesperson tells me the bug has been live since last year, and was discovered last week. Facebook says the security team fixed the bug less than 24 hours after it was brought to their attention."

Geeks, making the world a better place
Quote · 22 Jun 2013

Ah. But facebook connect would have to be written to deliberately access that information, which it is not. Neither the boonex version or mine contains code to access that information.

And what makes you think Open ID is 100% safe.

Most everything has bugs.

https://www.deanbassett.com
Quote · 22 Jun 2013

 

Ah. But facebook connect would have to be written to deliberately access that information, which it is not. Neither the boonex version or mine contains code to access that information.

And what makes you think Open ID is 100% safe.

Most everything has bugs.

It is the constant security risk of Facebook and others that is the problem.  It the compromising of accounts that is the risk.  The difference between Open ID and using single-sign on from Facebook, Google+, Twitter, and so forth is that they are for-profit corporations with the sole goal of profits.  Over the years, Facebook has weaken their security in the name of profits; the idea is to make it easier for corporations to target their users.  Therefore, they have made it harder for their users to lock down their accounts.

Geeks, making the world a better place
Quote · 22 Jun 2013
 
 
Below is the legacy version of the Boonex site, maintained for Dolphin.Pro 7.x support.
The new Dolphin solution is powered by UNA Community Management System.