Thousands of private fotos leaked, privacy disaster for Quiptxt.com users
reddit.com
reddit.com
1) A significant portion of people love taking pictures of themselves naked. This portion seems to be growing.
2) Another significant potion of people love publishing and making fun of people for whatever reason they can find. These people will dig through your trash, hack your servers, socially-engineer your passwords, etc. The more they can publicly debase you the happier they are. This portion of the population is also growing.
Yes, I understand the technical angle to this story is whacked security. I'm just amazed at the comments over on reddit (I don't visit reddit very often) From reddit I surfed over to a couple of other links (drama-a-pedia or something?) and the festival of public debasement continues. Somebody even mentioned hacking some girl's senior picture and uploading her naked pics. Man that has to make you feel really special to do something like that.
2) It's not clear to me this portion of the population is growing, but it does bother me that those people don't get the disdain they deserve (according to me).
That said, I think the company in question should be held liable for these kind of breaches. It's your responsibility as an online service to protect the privacy of your users. Even if the service is free you're still obligated to properly secure the service, and if you don't have the expertise to secure it yourself hire somebody to do it for you or don't run the service!
I don't expect most of you here to agree with me, in fact, I expect most of you to vehemently disagree. And web services? Reddit: didn't hash passwords, database got stolen. HN? Still doesn't hash passwords, as far as I know. 37signals? Same. The list goes on.
Yes, it sucks that people take advantage of lousy security, but in the end I think it's the web service that's been grossly negligent, and I think that we shouldn't accept this kind of malpractice.
That phones have put personal private cameras in more hands than even Polaroid certainly contributes. But I think a 30, 50 or 100% increase in cameras is nothing compared to the exponential increase in perfect digital copies and transfers of any given image.
The evidence can no longer be counted on to get lost, get damaged, decay, etc - and it duplicates and multiplies as a default behavior at every step of an exchange.
1 naughty polaroid = 1 naughty image
1 naughty cell-phone pic = 1 pic on camera, 1 pic on home PC, 1 pic in thumbnail cache, 1 pic on flickr, 1 pic in uploader's browser cache, 1 pic in recipient's browser cache, 1 pic on recipient's machine, 1 pic in recipient's thumbnail cache, etc.
Even if an image is never intentionally distributed, it's effectively distributed.
Reddit users are seemingly busy sharing nsfw pictures and linking them to facebook accounts, will probably result in a couple of suicides when all is said and done :(
I like reddit so I'm a little saddened to see this behavior there but this is another reminder that the internet isn't as segregated as we think it is. Reddit is no gated community. Its best and worst feature.
The application is described in the iTunes store: http://itunes.apple.com/app/quip-free-photo-texting/id291358...
http://www.reddit.com/r/pics/comments/bjezp/massive_privacy_...
If you launch something like QuipTxt, make it obvious to people that their images are public, so that the idiots who harbour the impression that stuff uploaded on a public URL on a free website don't come running at you with pitchforks.
Additional benefit: more network effects.
I don't really see the difference between this service and Twitpic (hard to tell since the site is down, though).
I think your statement (where you call the users idiots) represents everything that's wrong with the current security-lax web services crowd.
If you launch something like QuipTxt, make it obvious to
people that their images are public
Google Picasa stores images as public URLs without any such warning. Because with random URL's, you effectively have passworded each image. Even more secure than if they were all locked into a nice MySQL database, because then they would all be behind only a single password.I think you don't have to freak out users with too much information. The images are effectively password controlled.
The problem here is that the passwords were too short (and sent in plain text via SMS).
Once a user has authenticated themselves then it is a separate problem to decide what they are authorized to see.
Even really complex keys in links are still a big problem as they are far too easy to pass around - I've seen multiple problems on commercial systems and products where documents didn't require authentication before access and "security" relied on having an obscure key value directly represented in a link.
A password is not a magic spell. It's a set of letters and numbers that, if guessed correctly, will give me access to something you wanted kept private.
An obfuscated URL is a set of letters and numbers that, if guessed correctly, will give me access to something you wanted kept private.
Because one uses a MySQL database, and the other uses a file system, is irrelevant. They are functionally identical when directory listing is disabled, as it can be for Amazon S3.
Edit: like daleharvey says, the point is really that the hash simply happens to be difficult to find, whereas a proper application will challenge everyone who attempts to access the resource. For instance, say Alice looks at Bob's picture, and does "copy image url", and sends it to Carol. Carol has no way of knowing whether it's supposed to be private or not, since Alice didn't communicate that information.
If you build those same measures into your URL then they have the same level of security; plus you can make your URL key a lot longer than would be comfortable for a password.
I figured since these messages were being passed around via txt, forwarded e-mails, etc., there was no real benefit in shortening them.
S3 hosting of private images was a terrible idea. It doesn't provide any kind of protection.
S3 offers privacy protections with the ability to require an expiring token in the URL. The theory is the web site should authenticate a user, and only generate a valid token for that user (for a fuzzy definition of "that" user) that works only for a limited time.
Doubling the characters to 10 would pretty much completely solve the problem. It would take many, many years to find a single image. Far below the threshold where Amazon S3 would ban you.
You can add an option to delete/rekey the image too. At that point the URL is exactly as secure as the method you use to send the URL -- just like a password.
It would also include other services by the same management to the list :-)
Not even the shadow of a cloud (pun intended) was involved.
I was pretty surprised that Google goes through your javascript, harvesting your ajax links.