Jonathan Richards
The man, the films, those blondes. Free DVD collection starting this Sunday
Facebook users were today left contemplating the security of private details stored on the social networking site after part of its source code leaked onto the internet.
The site today acknowledged that a section of its code had been copied and published on a blog, but stressed that none of the personal details of its 52 million users had been compromised.
At the weekend, a blog called Facebook Secrets published details of part of Facebook's 'source code', the set of commands which determine the way the site appears when it is viewed by users.
Facebook said that a fraction of its code had been "exposed to a small number of users as a result of a single, misconfigured web server" but that the problem was "fixed immediately."
"It was not a security breach and did not compromise user data in any way," the company said in a statement released to TechCrunch, the news site which first reported the story.
Security experts said that there was relatively little that could be learnt from the leaked code, which appeared to give details of the structure of the home page, but that Facebook's reputation as a secure site would be called into question.
"With the amount of personal information that's on there, the security should be tip top," Lloyd Brough, a security consultant with NCC Group, said. "This kind of thing just shouldn't be happening."
The mistake was likely to have happened during maintenance of the site, when a command that would usually cause the page to appear when loaded up did not execute, Mr Brough said.
"If that is what did occur, they shouldn't be doing it that way. They should be configuring another server and then switching over," he said.
TechCrunch said: "This leak is not good news for Facebook, as it raises the question of how secure a Facebook user's private data really is."
The code that was leaked referred to the 'front end' of Facebook's website, and detailed various of the modules used by the home page, in a language known as 'PHP script'.
Ian Moulster, a former programmer who is now a product manager at Microsoft, said: "Gaining access to the way a website's user interface works might enable a hacker to see a security gap that in turn may assist in inflicting an attack in the future."
Many bloggers expressed excitement at being able to witness the workings of the Facebook, which has quickly become one of the most trafficked sites in the world. One noted that this "roughly as exciting as someone leaking the prologue to the Harry Potter novel."
Others, however, were dismissive: "Source code secrecy is over-rated, part of the myth that programming is something mystical and irreproducible," wrote 'Carlfish' on the Valleywag website.
One report suggested that the code may have been leaked to assist in an ongoing court case brought against Facebook by ConnectU, a rival site whose owners claim Facebook stole their idea and code three years ago – a claim Facebook denies. This suggestion was dismissed by many commentators, who said that after three years of development the code would have changed beyond recognition.
It is the second time that Facebook – whose users spend an average of just over three hours per month on the site, according to comScore – has had its security procedures questioned.
In June, it was forced update its privacy settings after it was revealed that some users had unwittingly been exposing personal details, such as sexual preference and religious beliefs, even though their profiles were set to keep those details private.
Read the training tips and advice that helped our London Triathletes
Times Online's new TV show helps you make the right decisions for your pet
Read our exclusive 100 Years of Fleming and Bond interactive timeline, packed with original Times articles and reviews
The latest travel news plus the best hotels and gadgets for business travellers
Shortcuts to help you find sections and articles

Get Times news, business and sport on your mobile. Text Times to 86626



Overseas contacts and local business information

Our Credit Clinic has free help and advice
2007
£47,700
2007
£41,899
2008
£41,445
Great car insurance deals online
£25,510 – 32,000
Transport for London
London
£50k
NHS
Nationwide
£
£90,000 + PRP
Essex County Council
Essex
100K
Confidential
London
5% below developer pre-launch price!
Luxury Appts, beautiful gardens w/ Thames views
Great Investment, River Views
By Funway – Thailand
from £589pp
Christmas Cruises
From only £995pp
APTs East Coast now from only
£2425pp.
Great travel insurance deals online
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times. Globrix Property Search - find property for sale and rent in the UK. Visit our classified services and find jobs, used cars, property or holidays. Use our dating service, read our births, marriages and deaths announcements, or place your advertisement.
Copyright 2008 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.