Today on Slashdot: "Facebook Bug Could Give Spammers Names, Photos (it.slashdot.org)"
"Facebook is scrambling to fix a bug in its website (www.pcworld.idg.com.au) that could be misused by spammers to harvest user names and photographs. It turns out that if someone enters the e-mail address of a Facebook user along with the wrong password, Facebook returns a special 'Please re-enter your password' page, which includes the Facebook photo and full name of the person associated with the address. A spammer with an e-mail list could write a script that enters the e-mail addresses into Facebook and then logs the real names. This could help make a phishing attack more realistic."