Posted on 04-21-2008 under best practices, web crawling

If you’ve uploaded photos to facebook, this could be a security risk. Anyone on your friend list can copy the location of your images, and then possibly release them to the public.

Here’s how to test this. Its pretty simple really. Open any photo in facebook, right click it and select “Copy Image Location” in Firefox. (I don’t see any option for this in Internet Explorer 6, but your mileage may vary). Now logout of facebook, and paste the copied url in your location bar. Press Go. See?

Pretty simple, but possibly quite horrifying. If you don’t want people out of your friend circle to see your photos, you better not upload them at all. Anybody in your clique may release this url to anybody else.

I was actually alerted to this risk, when someone pasted a url to a photo of one of his friends in a chat room. Suffice it to say, the photo was not what that particular person would have wanted everyone to see.

I’ve been paranoid for some time so I removed most of my profile from facebook about a month ago. You, however, have been warned. Choose for yourself.