[OpenID] Facebook Connect and OpenID (was: My answers to the nominee questions)

SitG Admin sysadmin at shadowsinthegarden.com
Sat Dec 13 00:53:56 UTC 2008


>if they choose. The Facebook model is one of trusting a central repository
>to hold all your data and (heopfully) only release what you authorize. It
>delegates to the developers, admins, and DBAs of Facebook the responsibility
>for safegauarding user privacy.[0]

They just need to *be* responsible (and competent), so the developers 
don't grant ALL the user's data to any 3rd-party app (regardless of 
whether that app NEEDS all, or indeed any, of the user's data), and 
the admins don't leave access to user's passwords (and profiles) 
available to any employee, and the database administrators *track* 
access so they can be aware of problems with the first intrusion, not 
after they've been so widely exploited that the media is exploding 
with news over it.

Of course, Facebook has every reason to keep such things from happening.

Again.

Whether they can convince developers (and users) in the market that 
these incidents are a lasting reminder of humility rather than a sign 
of how things will continue to go at Facebook, is the question. Going 
with OpenID may help Facebook save face.

-Shade



More information about the general mailing list