Good Job Plurk! I won't be doing that again.
This is what happens when you use their built-in 'feature' to add people you already know from another service, such as Gmail.
Have we not heard of using ssl or form submission without using querystring values? It's really not that difficult guys...