What does this mean for developers? It means you need to setup https for your web server as soon as possible. You'll need to purchase an SSL/TLS certificate for your domain and install it on your webserver (GoDaddy has a pretty good deal for certificates). After https is setup, you also need to make sure your code loads all images, css, and scripts on the page with https if the page was loaded with https (otherwise, browsers - especially IE - will complain that the page contains non-secure items). In PHP with Apache or Litespeed web servers, you can check isset($_SERVER['HTTPS']) to know if the page was loaded with https.After you get this all rocking, you need to update the Secure Canvas URL and Secure Tab URL settings in your application settings on Facebook.