It also seems that some sites will simply break if the `<script>` they inject for the Facebook SDK fails to load (for instance, `https://www.todoexpertos.com/` in bug 1602690). As such, we would probably be best off actually "hijacking" the request, not sending it, but just returning our spoof. In my tests this works for all of the cases I've run across so far.

