An Australian technologist has caused a global stir after discovering Facebook tracks the websites its users visit even when they are logged out of the social networking site.
Separately, Facebook's new Timeline feature, launched last week, has been inadvertently accessed by users early, revealing a feature that allows people to see who removed them from their friends lists.
Facebook's changes - which turn profiles into a chronological scrapbook of the user's life - are designed to let its 800 million members share what they are reading, listening to or watching in real-time. But they have been met with alarm by some who fear over-sharing.
Of course, Facebook's bottom line improves the more users decide to share. Reports suggest that Facebook staff refer internally to "Zuck's law", which describes Facebook founder Mark Zuckerberg's belief that every year people share twice as much online - a trend that has seen Facebook's valuation skyrocket towards $US100 billion.
In alarming new revelations, Wollongong-based Nik Cubrilovic conducted tests which revealed that when you log out of Facebook, rather than deleting its tracking cookies the site merely modifies them, maintaining account information and other unique tokens that can be used to identify you.
Whenever you visit a web page that contains a Facebook button or widget, Cubrilovic says, your browser is still sending details of your movements back to Facebook.
"Even if you are logged out, Facebook still knows and can track every page you visit," Cubrilovic wrote in a blog post.
"The only solution is to delete every Facebook cookie in your browser, or to use a separate browser for Facebook interactions."
Cubrilovic is working on a new unnamed startup but has previously been involved with large technology blog TechCrunch and online storage company Omnidrive.
He backed up his claims with detailed technical information. His post was picked up by technology news sites around the world but Facebook has yet to provide a response to Fairfax Media and others.
Indeed, Cubrilovic said he tried to contact Facebook to inform them but didn't get a reply. He said there were significant risks to the privacy of users particularly those using public terminals to access Facebook.
"Facebook are front-and-center in the new privacy debate just as Microsoft were with security issues a decade ago," Cubrilovic said.
"The question is what it will take for Facebook to address privacy issues and to give their users the tools required to manage their privacy and to implement clear policies - not pages and pages of confusing legal documentation, and 'logout' not really meaning 'logout'."
The office of the Australian Privacy Commissioner has been approached for comment.
The findings come after technology industry observer Dave Winer declared Facebook was scaring him because the new interface for third-party developers allows them to post items to your Facebook timeline without your intervention. This has been dubbed "frictionless sharing".
Meanwhile, Facebook's Timeline feature, which shows users a timeline of their activity on the site throughout the years, has not officially been switched on but many are using it already. Instructions can be found here.
But inadvertently or by design, the Timeline feature also let people to see which users had unfriended them by following a few simple steps:
1. Enable the new Timeline feature
2. Pick a year in the timeline and locate the Friends box
3. Click on "Made X New Friends"
4. Scroll through the list and when you see an "Add Friend" box, those are the people either you have unfriended or vice-versa.
However, it appears Facebook has now disabled this function, describing it to gadget blog Gizmodo as a "bug".
Finally, security researchers were quick to hose down a hoax that spread through the social network claiming that Facebook was planning to start charging users for the new features.
- Sydney Morning Herald