Comment Some details on how it works (Score 1) 139
It's a CSRF attack. For more details see this blog post http://getahead.ltd.uk/blog/joe/2007/01/01/csrf_at tacks_or_how_to_avoid_exposing_your_gmail_contacts .html#preview
Check out DocTree.
The rule on staying alive as a program manager is to give 'em a number or give 'em a date, but never give 'em both at once.