But you didn't make a case either that Facebook is attempting to mislead users, or indeed that their actions are misleading users at all. A number of sites gate outbound traffic for security reasons, and the language Facebook shows users is totally consistent with this - it doesn't read "You are about to visit a dangerous site", instead it warns users in generic language of phishing, etc. The error here is attributing malice to a bug or annoyingly-implemented feature. That feature clearly falls short of any reasonable "badware" criteria.