Regarding the social CAPTCHA: I hope they use some heuristics to gather who is really my friend and who is a "friend-me-once-and-never-talked-to-me" connection. There are a number of faces they could show that I wouldn't be able to put a name to.<p>I <i>also</i> hope they change the default privacy settings so that a person's friend list is hidden from unrelated viewers, otherwise a determined attacker could presumably browse your friends until they find the person in the CAPTCHA.