By law they need to share what you post publicly, including files. This 'vulnerability' has been around for decades.
By law they need to share what you post publicly, including files. This 'vulnerability' has been around for decades.
"Digital Government: Building a 21st Century Platform to Better Serve the American People". United States Federal CIO Council. May 23, 2012.
This is a bad idea, though, as it makes it easy and legal for non-authorized entities to impersonate the authorized ones: freecreditreport.com
Websites have been using this pattern for 25+ years, so it's pretty universal by now.
The `~` or `~username` is expanded by your shell (but not necessarily all shells) and has nothing to do with the operating system. If you pass a filename like `~myusername/test.txt` to any unix's open() syscall, it's going to either fail or open a file in a directory literally called `~myusername`. This means anywhere you're passing a filename into a program that isn't your shell does not generally support that syntax.
A narrowly defined, poorly recognized convention is not a great thing to rely on for security purposes.
Also, that ® at the end of posix is part of the URL, you will unfortunately get a 404 if you don't copy-paste it right. You might be better to search for "site:opengroup.org posix"
Good luck, man
It was a way to easily allow unprivileged users to share content from their ~/public_html/ directory.
Nevertheless, it's clearly associated with UGC content, and as far as I know there have never been any major sites that have hosted non-UGC content using this scheme. (E.g. there is no history of use for things like Amazon product pages or whatever.)
And in school we were always taught that content coming from user pages on university systems shouldn't be cited as if it were academic content being published or endorsed by the university. I'm sure others were taught the same.
- Browsers might want to treat it differently for malware scanning purposes.
- Content owners might want to treat it differently when filing automated DMCA complaints.
- Search engines might want to treat it differently for ranking purposes.
The benefit of the tilde is that, at least as far as I know, it has never been used for anything other than signaling that something is UGC content. (Even if that was a technological accident and not its original intent.)
Do you think the assumption that the content was created by the organization who owns the domain should be default? Wouldn't it be better for the organization to provide a signature for the content it did create?
Sure, and I think that is the current assumption. What's missing is a way to specify UGC content that wasn't created by the organization.
> Wouldn't it be better for the organization to provide a signature for the content it did create?
I don't think this would be viable for two reasons:
- It would require people to do the work to opt in, without any obvious incentive for doing so.
- No obvious way to different UGC content from javascript dependencies, fonts, ad trackers, etc.
Whereas there are good use cases for allowing folks to mark content as being UGC. For example, let's say the game Draw Something wanted to let users upload their creations. So no security issues, since images are created through their own app, but they don't necessarily want everyone thinking that they're spending all day creating and uploading millions of dick drawings either.
I suggested just adding a ~ to the domain name, because when you see a domain name like this:
http://www.cs.columbia.edu/~allen/
It's universally recognized that the content on that page was not created by columbia.edu or cs.columbia.edu in an official capacity.
Other people said we can't do this because it's not an official standard, so I said let's just make it a standard. Which I think is good because it keeps an important piece of Internet culture alive by codifying it, which would let people rely on it when designing new systems. And ultimately it should work because there is no history of this URL pattern being used for non-UGC content.
it appears your only goal is to be right.