<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>AllFacebook - Latest Comments in Facebook Applications Prove Insecure</title><link>http://allfacebook.disqus.com/</link><description></description><language>en</language><lastBuildDate>Mon, 31 Mar 2008 08:49:24 -0000</lastBuildDate><item><title>Re: Facebook Applications Prove Insecure</title><link>http://www.allfacebook.com/2008/03/facebook-applications-prove-insecure/#comment-1639813</link><description>Ha! I saw this coming five months ago. Scope this post....&lt;br&gt;&lt;br&gt;&lt;a href="http://deftlabs.com/2007/10/facebook-application-security/" rel="nofollow"&gt;http://deftlabs.com/2007/10/facebook-applicatio...&lt;/a&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ryan</dc:creator><pubDate>Mon, 31 Mar 2008 08:49:24 -0000</pubDate></item><item><title>Re: Facebook Applications Prove Insecure</title><link>http://www.allfacebook.com/2008/03/facebook-applications-prove-insecure/#comment-1639812</link><description>All requests from fb pass a signature using a shared secret key. There is no way a hacker could generate this sig without knowing the secret key. The default libraries use this key to validate the user, so anyone simply following the example apps would have a pretty secure app.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Tom</dc:creator><pubDate>Fri, 28 Mar 2008 11:45:08 -0000</pubDate></item></channel></rss>