Facebook nearly gets network-level privacy right

With all the recent furore around Facebook privacy, I've been looking at various online services I use, and seeing how well they support SSL. Twitter is probably the winner here, as they send everything over https once you modify the URL. I did however read that their SSL certificate may be insecure due to using the md5 signing method. More on twitter later
Facebook start off well. You can jump over to https easily, and they have a nicely signed ceritificate. Sadly, that's where the fun ends. All links on the page are absolute, and lead straight back to http land. As a user, I'm confused by the warnings, and would have a false sense of security without knowledge of having moved from https to http. Still, I'll keep my fingers crossed they fix that particular schoolboy error soon.
UPDATE: Someone else is having similar thoughts, as the EFF have just launched the HTTPS Everywhere Firefox extension. However, I still believe that Facebook need to fix their link strategy.
Now, if only we can get a Chrome extension to do the same thing!







