In follow-up to Friday’s blog post entitled Fortinet’s ‘Facebook Widget’ Advisory False, Zango earlier today issued a formal press release confirming that the company had no involvement with the “Secret Crush” Facebook widget.
As a result of the press release, as well as a number of other communications, clarifications and corrections are starting to trickle in. Matt Hines of InfoWorld posted a blog this afternoon that disputes the accuracy and/or interpretation of Fortinet’s Advisory – particularly any assertion that the Facebook widget “secretly installed Zango adware.” In a post entitled “Zango strikes back over reported Facebook hack,” Mr. Hines graciously admitted that, “upon further review,” there was “at least” a mistake in interpretation of the Fortinet Advisory on InfoWorld’s part. Apologizing for “any confusion,” Mr. Hines cautioned that “we in the security community who picked up on this story so eagerly should also be reminded to look into all the details of any security bulletin before we report on it.”
For InfoWorld, the truth is this: “it does seem based on the reported details that Zango at least served up its EULA before allowing end users to click through and grab its programs, which is all it is required to do really.”