Re: [Full-disclosure] flickr not truly private

2007-02-26 Thread Michael Holstein
> apologies if this is lame or already known.

What, you mean the part about stuff you post to the Internet not being 
private?

Well .. *duh*.

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] flickr not truly private

2007-02-26 Thread Line Noise
On 2/25/07, John Duhuh <[EMAIL PROTECTED]> wrote:
> flickr say you can mark your photos private. when you look at the web
> interface maybe. just give the direct address of a picture to one with no
> access he grabs it no problem.
> google images tips left as an exercise.

Rest snipped. Of course they're not *private*, in that sense of the
word. Other than keeping web spiders from archiving your pictures, it
serves no purpose whatsoever. If you have pictures you don't want to
share with strangers, don't put them on Flickr.

Seems simple enough.

-- 
It's Full Disclosure.
Post the disclosure here, not on your website.
You may not have a web site tomorrow.

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


[Full-disclosure] flickr not truly private

2007-02-25 Thread John Duhuh

flickr say you can mark your photos private. when you look at the web
interface maybe. just give the direct address of a picture to one with no
access he grabs it no problem.
google images tips left as an exercise.
for the brute forcers it looks like feasible, maybe difficult.
targetting someone is easier with an estimation of the time of upload, as
first part of the filename is incremental.
for the rest maybe they did the job right, maybe not.
apologies if this is lame or already known.
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/