Very interesting -- I wonder if this is the result of having so many API access points. The documentation page lists FBML+FQL, Graph, "Old Rest API", and "Old Javascript Client Library" as options: http://developers.facebook.com/docs/ Or are we back to good old XSS attacks?