Neat trick for getting private info for Facebook, GMail, Twitter and Digg users
grepular.com
grepular.com
https://twitter.com/account/use_phx?setting=false&format=text
Recognised that URL immediately, and (after first changing to newtwitter which I hate), reloading the page did indeed switch me back to oldtwitter.Edit: Because of the change in URLs between the old and new versions of Twitter, I can only find one alternative to the us_phx option (a fairly obvious one):
http://twitter.com/settings/account
Returns 302 if not logged in, and if logged in then 200 regardless of if your account is set to use new or old twitter.https://twitter.com/account/use_phx?setting=false&format...
But when logged out, it redirects to the login form which ultimately provides a 200 status code.
There are probably several other ways of making twitter generate a HTTP error code.
It's a bit painful to set up at first for all sites that you visit frequently (similar to setting up NoScript), but then you can enjoy a much more lightweight browsing experience - and a more secure one as well.
This will be plugged in future browsers though...its already blocked in chrome
<script>
function twitterSessionsPresent(state) {
console.log(state);
}
</script>
<script src='https://api.twitter.com/sessions/present.js?callback=twitterSessionsPresent'></script>Which sites you log into, is private information.
The Firefox addon "Request Policy" does protect from this attack, but it's not the most user friendly way to browse the web. I've been trying it out myself the past couple of days. Fine for geeks, but not fine for the average user.
The post you responded to is correct in that the title is somewhat incendiary compared to the reality, unless there is some possible hijacking or scraping vector from this, but that seems massively unrealistic.
That's what 'Noscript' is for.
That's what just using Lynx is for.
Yeah, lots of people go to this amount of trouble. Hell, why feel bad for people injured in car crashes? That's what five-point restraints and helmets are for.
Chill out, mon.
Here's code I wrote to display the "digg this" button only to digg users: http://int2e.com/blog/improved-digg-integration-script/
http://hacks.mozilla.org/2010/03/privacy-related-changes-com...
There are definitely privacy implications when doing it on a large scale, but I wish there was a middle ground.
I'm sure this isn't what you're thinking, but just to double check... You don't think that you're logged out of twitter just because it's not open anymore do you? If you log in, and then close the tab without logging out, then you're still logged in...
The test could easily be modified so it checks some other url first to make sure twitter isn't generally blocked.
The intention of the article was to describe a general technique, rather than to provide some complete fully functional tests. Although they do work for the vast majority of people.