Lesson: If you launch something like QuipTxt, make it obvious to people that their images are public, so that the idiots who harbour the impression that stuff uploaded on a public URL on a free website don't come running at you with pitchforks. Additional benefit: more network effects. I don't really see the difference between this service and Twitpic (hard to tell since the site is down, though).
The users aren't the idiots here, they had no reason to assume their private pictures would be shared (and even if you put a disclaimer on there, you can't expect people to read that). Besides, the admins of the service must have been fully aware people were sharing sensitive pictures, and they did nothing about it! And it wasn't a public URL, it was a URL secured by a lousy hash. Virtually indistinguishable from a U…
Thousands of private fotos leaked, privacy disaster for Quiptxt.com users
41–50 of 60 posts
Re: Thousands of private fotos leaked, privacy disaster for Quiptxt.com users
#42Earlier quoted context omitted.
I disagree. A password is not a magic spell. It's a set of letters and numbers that, if guessed correctly, will give me access to something you wanted kept private. An obfuscated URL is a set of letters and numbers that, if guessed correctly, will give me access to something you wanted kept private. Because one uses a MySQL database, and the other uses a file system, is irrelevant. They are functionally identical whe…
Locks on houses aren't infallible either, but establish intent: "you should not be here". Very short hashes don't do that quite so much.
Re: Thousands of private fotos leaked, privacy disaster for Quiptxt.com users
#43Earlier quoted context omitted.
I just had google index my ajax directory. I have a directory where I keep ajax files. The only link to them is through my javascript ajax calls. I was pretty surprised that Google goes through your javascript, harvesting your ajax links.
Well, you linked to them via JavaScript. The whole rest of the Internet might not have been that careful, though.
Re: Thousands of private fotos leaked, privacy disaster for Quiptxt.com users
#44Earlier quoted context omitted.
Locks on houses aren't infallible either, but establish intent: "you should not be here". Very short hashes don't do that quite so much.
I'd be interested in knowing what the length a hash needs to be to communicate "you should not attempt to circumvent this and post the nude pictures behind it", and also how secure a lock needs to be to communicate "you should not attempt to jimmy this with a credit card and post the nudie pictures behind it."
Edit: like daleharvey says, the point is really that the hash simply happens to be difficult to find, whereas a proper application will challenge everyone who attempts to access the resource. For instance, say Alice looks at Bob's picture, and does "copy image url", and sends it to Carol. Carol has no way of knowing whether it's supposed to be private or not, since Alice didn't communicate that information.
Re: Thousands of private fotos leaked, privacy disaster for Quiptxt.com users
#45Earlier quoted context omitted.
if you only need to guess something address to see it, it is public
I disagree. A password is not a magic spell. It's a set of letters and numbers that, if guessed correctly, will give me access to something you wanted kept private. An obfuscated URL is a set of letters and numbers that, if guessed correctly, will give me access to something you wanted kept private. Because one uses a MySQL database, and the other uses a file system, is irrelevant. They are functionally identical whe…
If you build those same measures into your URL then they have the same level of security; plus you can make your URL key a lot longer than would be comfortable for a password.
Re: Thousands of private fotos leaked, privacy disaster for Quiptxt.com users
#46Re: Thousands of private fotos leaked, privacy disaster for Quiptxt.com users
#47Re: Thousands of private fotos leaked, privacy disaster for Quiptxt.com users
#48The founder of the company responded on the Reddit thread: http://www.reddit.com/r/pics/comments/bjezp/massive_privacy_... The application is described in the iTunes store: http://itunes.apple.com/app/quip-free-photo-texting/id291358...
Re: Thousands of private fotos leaked, privacy disaster for Quiptxt.com users
#49Re: Thousands of private fotos leaked, privacy disaster for Quiptxt.com users
#50Two things in this story that are not new, but still amazing to me. 1) A significant portion of people love taking pictures of themselves naked. This portion seems to be growing. 2) Another significant potion of people love publishing and making fun of people for whatever reason they can find. These people will dig through your trash, hack your servers, socially-engineer your passwords, etc. The more they can publicl…
RE point 1) That phones have put personal private cameras in more hands than even Polaroid certainly contributes. But I think a 30, 50 or 100% increase in cameras is nothing compared to the exponential increase in perfect digital copies and transfers of any given image. The evidence can no longer be counted on to get lost, get damaged, decay, etc - and it duplicates and multiplies as a default behavior at every step…