Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I started playing with this new api today. My room mate and I spent an hour with various privacy settings and it does not appear there is any way to prevent your account from being accessed via this.


That is because the info that is available at http://graph.facebook.com/name is <= the info that is available at http://facebook.com/name . What part of your account are you trying to stop from being accessed? This makes no sense.


I set my profile to private. I turned off "Public Search Results" and "Facebook Search Results" is set to "Only Friends".

If you're not logged in, my URL returns a 404: http://www.facebook.com/davetufts (or by ID: http://www.facebook.com/profile.php?id=603069147 )

Not a huge deal, because the graph page only shows my name and ID, but they are publicly accessible: http://graph.facebook.com/davetufts or http://graph.facebook.com/603069147


Appending /picture?type=large to your graph page works, too. Uh, oh...


I can see the following as a logged-in facebook user, which is identical to what the graph api returns: http://imgur.com/8y8hf.png

I'm not seeing a discrepancy here?


Like I said, the discrepancy is if you're NOT logged in.


I'm not seeing an issue here though -- that profile information was readily available in html (if you have a facebook cookie) and is now even more accessible via json.

In fact, the json api gives out less information than the html frontend (e.g. all 18 pages you currently follow).


Like he said, the discrepancy is when you are not logged in. I can see his info and his private profile pic although I don't even have a facebook account and the html version gives me a 404.


It's not a big deal, anyone could make a throwaway FB account and see the same data. The difference is almost immeasurable.


You don't think its a big deal that I can crawl FB to capture the names and pictures of people, regardless of their privacy settings?


I don't like the fact that Facebook makes any of my data available and doesn't provide me options to make it private at will. I have my privacy settings turned all the way up for everything. Perhaps I, and others, simply would like to not have any of our data available in this manner.


I agree with you. As of now, your only option is to not use fb.


That's good advice. For anyone interested in taking it, see "How to permanently delete your Facebook account": http://www.facebook.com/group.php?gid=16929680703


My “graph” link is public, but my “public page” link is not. It might be because I don’t allow my profile to appear in public searches (non logged in), but still they made it visible to anyone in the graph API. I hope they add a privacy setting to change this.


So you're able to get someone's facebook id and name? How useful is that? It seems about as useful as scraping web pages for random names & numbers. Might as well go to classmates.com and get a list of names there.


name, id, AND full size profile picture




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: