Live data from Hacker News

Leaking URLs to the Clown

rachelbythebay.com

21–30 of 57 posts

Re: Leaking URLs to the Clown

#21

So, if you were thinking about using that particular app to read some feed containing something relatively private, guess what, they're reading it too. Which one? No names were named at any point in this post.

It's not hard to find out which one it is, though. I don't want to name names but the post gives a clear hint.

Why not name names? Who are you trying to protect, and why do they need protection from their own misdeeds, and why don't their users and everyone else deserve to know? They don't respect people's privacy, but deserve to have their own corporate privacy respected for some reason?

Re: Leaking URLs to the Clown

#22
post #4

Earlier quoted context omitted.

Artykul https://artykul.org/ >

I doubt it is this one. A quick read of that page and there's a few features that immediately had me assuming data would be synced to the cloud.

The cloud syncing stuff says "if you want", which implies it's opt-in behavior.

Re: Leaking URLs to the Clown

#25

Earlier quoted context omitted.

It's not hard to find out which one it is, though. I don't want to name names but the post gives a clear hint.

Why not name names? Who are you trying to protect, and why do they need protection from their own misdeeds, and why don't their users and everyone else deserve to know? They don't respect people's privacy, but deserve to have their own corporate privacy respected for some reason?

It's possible that it's more of a personal ethic and a view towards their own actions (something like, "I don't disparage others") rather than that they view this company as deserving protection.

Re: Leaking URLs to the Clown

#26
post #3

Can’t tell if “clown” is an incredible typo in the submission or some comment on the owner of the offending platform, but either way I’m all about it

It's been pretty common (derogatory) slang for "the cloud" for many years in certain circles I am in, so I assume that was the usage hear.

The clown emoji is also useful in this regard in SSIDs or strings in programs (breaks all sorts of things that it shouldn't too)

Re: Leaking URLs to the Clown

#27

Sorry, but I just don't see the "bad behavior" in polling a URL you purposefully requested it to retrieve. URLs are not secrets. Don't treat them as such.

She expected it to retrieve the URL to her own device, but it also sent it to the company that makes the app. That like if Chrome sent Google a list of all URLs you visit, people would definitely be angry about that.

Re: Leaking URLs to the Clown

#28
post #10

> read some feed containing something relatively private, guess what, they're reading it too Everyone needs to accept the fact there's no such thing as a private URL. There are URLs that can be originally communicated to you privately—through a private channel, that is—but insisting on holding onto some (wrong) belief that we can or should be able to mint URLs that themselves possess some "private" quality goes again…

The issue is that the company can track what you are reading.

Re: Leaking URLs to the Clown

#29
post #10

> read some feed containing something relatively private, guess what, they're reading it too Everyone needs to accept the fact there's no such thing as a private URL. There are URLs that can be originally communicated to you privately—through a private channel, that is—but insisting on holding onto some (wrong) belief that we can or should be able to mint URLs that themselves possess some "private" quality goes again…

URLs are just as private as passwords.

In, fact URLs by design explicitly supported passwords.

Re: Leaking URLs to the Clown

#30

Sorry, but I just don't see the "bad behavior" in polling a URL you purposefully requested it to retrieve. URLs are not secrets. Don't treat them as such.

She expected it to retrieve the URL to her own device, but it also sent it to the company that makes the app. That like if Chrome sent Google a list of all URLs you visit, people would definitely be angry about that.

> That like if Chrome sent Google a list of all URLs you visit, people would definitely be angry about that.

I have bad news for you… the general public won’t care.

https://www.tomsguide.com/news/microsoft-edge-is-sending-all...

Post reply on HN