Facebook Offers Canvas Encryption Proposal to Fix the User ID Issue

Facebook has responded to the issue of applications inadvertently sharing user IDs through HTTP referrer headers by proposing a new system for encrypting the parameters passed to applications. This Canvas Encryption Proposal stipulates that UIDs would require the receiving application’s secret key to decrypt, preventing anyone else from reading information about the user.

The company is now soliciting feedback from developers on the proposal. It hopes to implement parameter encryption for iframe-based canvas applications within the next few weeks, add support for all of Facebook’s SDKs, and help applications transition to the system.

Facebook Platform engineer Mike Vernal explains in the post to the Facebook Developer Blog that, “while initial press reports greatly exaggerated the implications of sharing a UID, we take this issue seriously.”

AW+

WORK SMARTER - LEARN, GROW AND BE INSPIRED.

Subscribe today!

To Read the Full Story Become an Adweek+ Subscriber

View Subscription Options

Already a member? Sign in