Leaking URLs to the Clown
rachelbythebay.com
rachelbythebay.com
Which one? No names were named at any point in this post.
Why??
You know, that character trait for DnD that determines how gullible your character is? LIE ability was it? Row 3 d20 to LIE check?!
I think there needs to be a balance between "if you really want to research this alleged invasion of privacy then you should look here" and "that guy is bad, everybody go harass him". I haven't seen the logs and I haven't read the company's website in detail, so I'm not going to point the finger at someone for what could be a misunderstanding.
Maybe the website does point out this behavior. Maybe it's a badly configured script. Maybe it's as bad as described. I certainly don't know and I'd rather not join an internet mob until I've done my due diligence.
This is an amazing way to express an extremely important concept, one that unfortunately doesn't have enough representation on the internet. Kudos.
I am often told What A Bad Boy I Am, because I won't tell.
I cry myself to sleep over it, every night.
I assumed the opposite: she knows that she has readers who will go trash on the developers of whatever random app she happens to be criticizing and doesn't want to be responsible for inciting an internet mob.
In this case she provided enough information that anyone who was seriously concerned about their feed reader could easily find out if it was theirs—searching for the quoted text turns up the guilty RSS reader, her post, and a rip-off of the guilty reader which re-uses their marketing blurb.
That's easy enough for someone who's motivated to find out if they're safe, but maybe not enough for a mob to form?
Everyone needs to accept the fact there's no such thing as a private URL. There are URLs that can be originally communicated to you privately—through a private channel, that is—but insisting on holding onto some (wrong) belief that we can or should be able to mint URLs that themselves possess some "private" quality goes against the fundamental design of the Web and what a URL even is.
(Yes, this does mean that every podcaster that implements subscriptions by giving one feed URL to free listeners and having listeners who pay for premium content use a different URL is fundamentally broken. Yes, this does mean that that big engineering organization that implemented file uploads and read/write access through slugs consisting of unguessable 128+ bit tokens is also wrong.)
Then you have to decide for yourself if you're OK with that or not.
I know Microsoft looks at my files when I put them on my OneDrive. I take that into account when I decide what to put there. I know Google reads my mail when Thunderbird sends it through their SMTP servers. I know it'll be read by some unknown parties along the way to the recipient. I take that into account when I write my mail.
If I pasted a URL into a feed reader, I'd most certainly assume the app, and by extension its creators, would access that URL and read what's there. I'd take that into account when using the app.
Then I wouldn't be surprised.
I haven't read Thunderbirds privacy policy in detail, so for all I know there's a clause about collecting email addresses in there. Could even be for a good reason, spam filtering for example.
And as mentioned I take that into account when writing emails. I do indeed avoid writing certain stuff and avoid sending certain mails due to privacy. For the rest I see it as an acceptable risk/reward tradeoff.
I'm not a tinfoil hat kinda guy, but the innocence is gone when it comes to modern software.
In, fact URLs by design explicitly supported passwords.
A password can be leaked just as well as any URL, particularly if the password needs to be periodically sent to a downstream server to do the feed polling, and hence stored in plaintext.
URLs generally have less protection than a password because that's how we design a lot of our systems (and this is a property of our systems and not of the URLs themselves), but the protection they do have is often enough.
You protect podcast feeds for revenue, not privacy. The negligible loss of revenue you're going to experience if somebody hacks into a feed reader isn't worth inventing a new protocol. You need to protect against abusive sharing of URLs by authorized users anyway, usually by having a system that forces the url to be re-generated when it's getting too many visits, so if one of these databases becomes fully public, the problem is already solved anyway.
That's an understatement. Passwords are supposed to be private by design. URLs are not.
> because that's how we design a lot of our systems (and this is a property of our systems and not of the URLs themselves)
That's simply not true. URLs don't have protection because the notion of a private URL is a flat-out contradiction. As I said before: it goes against the fundamental design of the Web.
URLs are not in any sense designed to be private. Like, at all. If anything, they are designed not to be private. URLs are by their nature public information[1]. Anyone who believes or wishes otherwise is someone who believes or wishes that the Web is something other than the thing actually proposed, designed, and implemented.
Anyone can, at their own peril, try to devise other higher-level systems that exploit implementation details and other incidentals in non-normative ways while trying to justify it on the basis that it jibes with what you have observed in practice. You are also free to design a content-protection scheme that hinges on the whitespace in the client request varying just so, or where the HTTP heADEr naMEs follow a suPEr seCREt caPITALIZATIOn coNVENTIOn, etc. But no one else has any obligation to conform to the expectations necessarily prescribed by those lame designs nor to commit themselves to any action/inaction implied.
"Leaking URLs" is a non-offense.
1. <https://roy.gbiv.com/untangled/2008/rest-apis-must-be-hypert...>
The clown emoji is also useful in this regard in SSIDs or strings in programs (breaks all sorts of things that it shouldn't too)
Never had heard that but it was obvious from the title.
Cloud quite often is clown-computing, or maybe clown-car-computing.
URLs are not secrets. Don't treat them as such.
I have bad news for you… the general public won’t care.
https://www.tomsguide.com/news/microsoft-edge-is-sending-all...
At least Google is fairly transparent about it, if you look for it. And I'd trust them way more than a tiny company making a "dime a dozen" app.
[1]: https://support.google.com/chrome/answer/13730681?hl=en#zipp...
[2]: https://support.google.com/chrome/answer/13844634?hl=en&ref_...
Yeah autosuggest is there and it has a toggle. But that's still far from every URL you browse.
If you think more "point" than that is necessary, you are deeply confused about a great many things.
Of all the comments here what was the point of only replying to that one?