Facebook is ignoring a serious shortcoming in the way it limits application developers’ access to information about Facebook users, according to a pair of hackers. Hackers say Facebook’s API keys have too much power from the moment they are issued, and obtaining one is simple. A Facebook spokesman dismissed the claims, saying: “What this person calls an ‘FQL Injection’ is simply our Facebook Platform APIs working as intended” The two hackers even provided working proof-of-concept code in their advisory.”]

