Shop OBEX P1 Docs P2 Docs Learn Events
Warning: Facebook coming to Parallax fourms? — Parallax Forums

Warning: Facebook coming to Parallax fourms?

I have just been alerted by jmg that there is a link to facebook on this forum page. 
<script src="http://connect.facebook.net/en_US/all.js#xfbml=1&quot; type="text/javascript"></script>
What is that? I have no idea really but it seems to be about FaceBook's SDK, authentication etc
http://hayageek.com/facebook-javascript-sdk/https://github.com/facebookarchive/facebook-js-sdk
Readable source here:
https://connect.facebook.net/en_US/all/debug.js
Now this may be totally harmless, at least it is not used by any JS on the page yet. I use facebooks's excellent react.js UI library myself (although I build it myself from source on github). But it's a sign thatfacebook buttons may soon becoming to the forum.
Needless to say I'm  not happy about this. The day I see a FB button here will be my last day here.

Comments

  • I doubt the FB button will show up, at least based on nothing more than the references js file.  My reasoning is that there's no indication of support for other social media sites (e.g. G+, Twitter, Reddit, etc).  Usually, when those "share" buttons show up, they show up en masse.
    However, if the link is providing legitimate functionality, I still think it would be a good idea to copy the file(s) to the parallax server.  This ensures that changes to the file by FB wont affect this site.  Also, with that script reference, every page load is sending the page's URL to FB, who is most certainly logging it (at the very least).
  • Heater.Heater. Posts: 21,230
    edited 2015-07-02 12:54
    I do hope you are right.
    I have not looked into that library yet so I have no idea what  useful functionality it may have. It's primary purpose does seem to be to allow log in to be authenticated by FB though.
    Whatever else it may bring does not seem to be used in anyway by the forum. Currently I have blocked it's download by pointing connect.facebook.net to localhost in my hosts file and every thing here seems to work as usual.
    It really should be removed from the forum page.  
  • I don't remember for certain, but I thought fb was on the old forum also. I've used Ghostery for years to block that kind of junk (along with NoScript and a healthy sized hosts). The only things currently being blocked here are fb and that gravatar thing.
  • Heater, we aren't going to make you get a Facebook account. Nor will you be required to login with Facebook. 
    All of the new forum tools have this feature. 
    We haven't even discussed the possible integration of Facebook, but we won't make any changes until the community is involved. 
    Ken Gracey 
  • Heater.Heater. Posts: 21,230
    edited 2015-07-02 15:30
    Ken,
    I am glad to hear that.
    However Facebook is very good at tracking non-members and sucking up all kinds of details about them.http://tech.firstpost.com/news-analysis/facebook-finally-admits-to-tracking-non-users-208996.html

    So the appearance of facebooks all.js naturally triggers suspicion.
    The Facebook chief considers the users of his system as "Dumb f***s".https://en.wikiquote.org/wiki/Mark_Zuckerbergdo you really want Parallax to be associated with such an outfit?



  • jmgjmg Posts: 15,148
    edited 2015-07-02 20:58

    All of the new forum tools have this feature. 
    We haven't even discussed the possible integration of Facebook, but we won't make any changes until the community is involved. 


    ?? What 'feature', and why is this hook even there ?( Note: This is the only technical forum I have noticed this on. I assumed it was someone's bumbling accident, not a deliberate act )

    All it did on my system was S L O W me down ?! (and waste expen$ive bandwidth on Mobile users).
    Solution: Just remove it.  You have more than enough problems, without adding more for free !!!
  • Heater, we aren't going to make you get a Facebook account. Nor will you be required to login with Facebook. 
    All of the new forum tools have this feature. 
    We haven't even discussed the possible integration of Facebook, but we won't make any changes until the community is involved. 
    Ken Gracey 

    I'll assume that I won't be forced back to Facebook either..  THANK YOU KEN!!
  • Heater.Heater. Posts: 21,230
    Now, a disturbing discovery.
    My cursory search around to find out what that all.js fetched from facebook  is for show that it is all about authentication. That is providing a means for people to log in to this forum with their FB id.
    Now then, how  come that all.js script is not fetched when a user is logged out here. It is only fetched when you have logged in, when it knows something about you.
    This makes no sense to  me. 
    Conclusion: Fetching all.js should be removed from this forum. Especially as it seems to  have no useful purpose, is a potential tracking system and slows down page load. 
  • TorTor Posts: 2,010
    I agree completely. And btw I also block gravatar and fb on my pc (can't on Android), but as far as gravatar is concerned it doesn't prevent your hashed email from being sent - unless everyone reading your posts do the same. So I have adopted Loopy's suggestion of using a blank avatar.

    Posting in raw mode as that's the only way which works in Android 4.1 on this forum.
  • Heater.Heater. Posts: 21,230
    Yeah, as I said the motivation for blocking Gravesecurityriskatar was more to do with removing all the ugly images from the page here.
    Of course if one worries about security it's already too late. Before you have the chance to replace Gravesecurityriskatar with your own image your cover is already blown.
     

  • LoopyBytelooseLoopyByteloose Posts: 12,537
    edited 2015-07-03 15:53
     So I have adopted Loopy's suggestion of using a blank avatar.


    @Tor
    The blank avatar does have one functional drawback.  One may need to click on the avatar to begin the sequence to send a private mail to someone. But it does seem that one may click on the name instead.

    So I was considering going from an all white (which is effectively blank) to another solid color. I suppose any solid color will do, like all black.

    ++++++++++
    Also, I am a bit vexed about the fact that private mail seems to have an election to add other people into the exchange that can occur unilaterally.  So what one might say privately may end up being not so private.  We may have had this feature before, but it wasn't so obvious.. if it did exist.
  • Loopy,
    See:
    http://forums.parallax.com/discussion/161413/warning-facebook-coming-to-parallax-fourms#latest

    I have tested this out with two other people, and it is private.

  • Heater.Heater. Posts: 21,230
    Love the recursive link their Publison.
    @Loopy, surely a blank avatar image is just as good to click on as any other. If you know where it is of course :)
  • Only half my name shows up in the main listings, so an Avatar icon might be helpful there.  I have no idea what is going on with the smart phone and touch pad versions.

    Having an outline might help indicate that a mouse click might work.  Clicking on half my name when that is all that is displayed does work.

    Of course, I doubt it anyone is going to send me a PM anyway. So I am just deluded about my overwhelming popularity.
  • Heater.Heater. Posts: 21,230
    I send you P.Ms Don't forget me.
  • LoopyBytelooseLoopyByteloose Posts: 12,537
    edited 2015-07-03 19:54
    Now that I understand why an Essex girl wears knickers, it is all clear to me.  Slowly I am learning more about the relations of culture to particular geographic areas of the U.K.

    You can see now that I claim to hail from Puddleby-on-the-marsh. Everyone knows it is famous for how little gets done there.
  • Heater.Heater. Posts: 21,230
    Well, those  Puddleby-on-the-marsh girls are something else! :)

Sign In or Register to comment.