Facebook doesn't want people to enable cross domain authentications/spoofing. If Facebook enabled their plugins to work inside iframes external to the Facebook environment, it'd be easy to maliciously authenticate users to give data to a fourth party.
Comments
http://forum.developers.facebook.net/viewtopic.php?id=60571
http://bugs.developers.facebook.net/show_bug.cgi?id=9777#c66
So, the problem is framebusting code not playing well with iframes. ;-)
Facebook doesn't want people to enable cross domain authentications/spoofing. If Facebook enabled their plugins to work inside iframes external to the Facebook environment, it'd be easy to maliciously authenticate users to give data to a fourth party.