Live data from Hacker News

Leaking URLs to the Clown

rachelbythebay.com

31–40 of 57 posts

Re: Leaking URLs to the Clown

#31

Sorry, but I just don't see the "bad behavior" in polling a URL you purposefully requested it to retrieve. URLs are not secrets. Don't treat them as such.

She expected it to retrieve the URL to her own device, but it also sent it to the company that makes the app. That like if Chrome sent Google a list of all URLs you visit, people would definitely be angry about that.

Except Chrome indeed sends up all URLs you browse, at least by default/outside of incognito mode.

Re: Leaking URLs to the Clown

#32

So, if you were thinking about using that particular app to read some feed containing something relatively private, guess what, they're reading it too. Which one? No names were named at any point in this post.

I feel like this happens every time we see one of her blog posts - she tries very hard to not provide any kind of specific information about anything she is writing about. Maybe it is to stop fanboys from harassing her when she trashes their favorite product or company, but it is the same technique used by people who are just making up stories.

> Maybe it is to stop fanboys from harassing her when she trashes their favorite product or company,

I assumed the opposite: she knows that she has readers who will go trash on the developers of whatever random app she happens to be criticizing and doesn't want to be responsible for inciting an internet mob.

In this case she provided enough information that anyone who was seriously concerned about their feed reader could easily find out if it was theirs—searching for the quoted text turns up the guilty RSS reader, her post, and a rip-off of the guilty reader which re-uses their marketing blurb.

That's easy enough for someone who's motivated to find out if they're safe, but maybe not enough for a mob to form?

Re: Leaking URLs to the Clown

#33

Earlier quoted context omitted.

It's not hard to find out which one it is, though. I don't want to name names but the post gives a clear hint.

Why not name names? Who are you trying to protect, and why do they need protection from their own misdeeds, and why don't their users and everyone else deserve to know? They don't respect people's privacy, but deserve to have their own corporate privacy respected for some reason?

Because I don't have all the facts and I can't put the genie back in the bottle.

I think there needs to be a balance between "if you really want to research this alleged invasion of privacy then you should look here" and "that guy is bad, everybody go harass him". I haven't seen the logs and I haven't read the company's website in detail, so I'm not going to point the finger at someone for what could be a misunderstanding.

Maybe the website does point out this behavior. Maybe it's a badly configured script. Maybe it's as bad as described. I certainly don't know and I'd rather not join an internet mob until I've done my due diligence.

Re: Leaking URLs to the Clown

#34
post #26
post #3

Can’t tell if “clown” is an incredible typo in the submission or some comment on the owner of the offending platform, but either way I’m all about it

It's been pretty common (derogatory) slang for "the cloud" for many years in certain circles I am in, so I assume that was the usage hear. The clown emoji is also useful in this regard in SSIDs or strings in programs (breaks all sorts of things that it shouldn't too)

I also like the Glaswegian "my computer is in the Clyde" meme. I always think of the cloud as a tired PC, bobbing around in the water, near Dumbarton.

Re: Leaking URLs to the Clown

#35
post #10

> read some feed containing something relatively private, guess what, they're reading it too Everyone needs to accept the fact there's no such thing as a private URL. There are URLs that can be originally communicated to you privately—through a private channel, that is—but insisting on holding onto some (wrong) belief that we can or should be able to mint URLs that themselves possess some "private" quality goes again…

URLs are just as private as passwords. In, fact URLs by design explicitly supported passwords.

Of which as bit so many people in the ass so many times that anyone with any security sense will tell you "Don't do that". There are just too many ways URLs leak because there is little difference between security context with users.

Re: Leaking URLs to the Clown

#36
post #19

Earlier quoted context omitted.

It's not hard to find out which one it is, though. I don't want to name names but the post gives a clear hint.

> I don't want to name names Why??

WHATS THAT ONE WORD!!?

You know, that character trait for DnD that determines how gullible your character is? LIE ability was it? Row 3 d20 to LIE check?!

Re: Leaking URLs to the Clown

#37

Earlier quoted context omitted.

Why not name names? Who are you trying to protect, and why do they need protection from their own misdeeds, and why don't their users and everyone else deserve to know? They don't respect people's privacy, but deserve to have their own corporate privacy respected for some reason?

Because I don't have all the facts and I can't put the genie back in the bottle. I think there needs to be a balance between "if you really want to research this alleged invasion of privacy then you should look here" and "that guy is bad, everybody go harass him". I haven't seen the logs and I haven't read the company's website in detail, so I'm not going to point the finger at someone for what could be a misundersta…

> Because I don't have all the facts and I can't put the genie back in the bottle.

This is an amazing way to express an extremely important concept, one that unfortunately doesn't have enough representation on the internet. Kudos.

Re: Leaking URLs to the Clown

#38
post #31

Earlier quoted context omitted.

She expected it to retrieve the URL to her own device, but it also sent it to the company that makes the app. That like if Chrome sent Google a list of all URLs you visit, people would definitely be angry about that.

Except Chrome indeed sends up all URLs you browse, at least by default/outside of incognito mode.

Are you talking about encrypted sync data or something else?

Re: Leaking URLs to the Clown

#40
post #10

> read some feed containing something relatively private, guess what, they're reading it too Everyone needs to accept the fact there's no such thing as a private URL. There are URLs that can be originally communicated to you privately—through a private channel, that is—but insisting on holding onto some (wrong) belief that we can or should be able to mint URLs that themselves possess some "private" quality goes again…

The issue is that the company can track what you are reading.

Unless there's an explicit reason not to, you should indeed assume that men in the middle will look at what you pass by them.

Then you have to decide for yourself if you're OK with that or not.

I know Microsoft looks at my files when I put them on my OneDrive. I take that into account when I decide what to put there. I know Google reads my mail when Thunderbird sends it through their SMTP servers. I know it'll be read by some unknown parties along the way to the recipient. I take that into account when I write my mail.

If I pasted a URL into a feed reader, I'd most certainly assume the app, and by extension its creators, would access that URL and read what's there. I'd take that into account when using the app.

Post reply on HN