mapsedge: (scowl)
mapsedge ([personal profile] mapsedge) wrote2009-06-22 12:28 pm
Entry tags:

It's never as secure as it looks...

For my friends who have posted pictures to their LJ account:

A friend of mine pointed out to me a method of getting around "Friends Locked" filters, so that it is possible to view items that only people on your Friends list should be able to view. The items in this case were photographs that might not want to be made public.

The kicker is that he wasn't trying. He was just randomly clicking about, following interesting links and people, "chasing Rabbits" as we say back home, sorted a list in a certain way and, lo and behold, the Friends Only filter fell away and he was able to browse pretty much everything. To his credit, he noted the steps, backed out, and emailed me the warning.

So, if you've posted pictures and think they're private, be aware that they aren't necessarily.

Ah, The Internet. Making the private, public, since 1993.

[identity profile] nottygypsy.livejournal.com 2009-06-22 06:27 pm (UTC)(link)
We'll hear they are using [livejournal.com profile] lightonthesill to advertise a Czech grocer next week!

I don't really post many pictures, and any I post of myself I'm not worried about being public. Because I DO feel if it's on the internet someone can get it. But thanks for the heads up!

[identity profile] duane-kc.livejournal.com 2009-06-22 06:45 pm (UTC)(link)
Anyone who's worried about this should know there's an *easy* way to look at friends-locked pics as well, even if it's not particularly controllable; if anybody reading this wants to know what it is, message me privately.

[identity profile] bleuberi21.livejournal.com 2009-06-22 08:14 pm (UTC)(link)
Yes, please.

Um...

[identity profile] iarraidh.livejournal.com 2009-06-25 05:18 pm (UTC)(link)
Are you offering to *help* somebody circumvent the security of someone's journal?

Anybody else feel uneasy about that?

Re: Um...

[identity profile] billthetailor.livejournal.com 2009-06-25 05:59 pm (UTC)(link)
Actually, Duane's referring to a feed that LJ makes available. There are several websites that make use of it, such as toothpastefordinner. It's not exactly what it sounds like.

Rhetorically, for thought

[identity profile] iarraidh.livejournal.com 2009-06-25 06:47 pm (UTC)(link)
So, a random violation of privacy is acceptible?
If you use a service that ignores privacy settings, but you never know what piece of candy the box of chocolates will yield...It's OK?
If you are looking in a girl's locker room, it's OK if you don't know any of the girls?

I went to that site and decided to use the max (250).
At my speed it only took a couple of minutes to load.

A) WOW there are a lot of personal pics on LJ - and a lot of their owners probably think they are private

B) For each photo, there is an HTML code so you, too can post these to YOUR LJ. So you can take images that may well have been intended to be private, and "out" them.

C) Part of that code contains the LJ user ID. With that info, and the flaw I brought up, a body could now go see a specific person's stuff. NOW is it not OK?

4) Another weirdness. Many images actually don't link to LJ users' scrapbooks, but to other sites with the image. That kind of relaying seems to also be a dicey practice.

My 2 cents again :)

[identity profile] 5rings.livejournal.com 2009-06-22 07:06 pm (UTC)(link)
Nothing is ever as secure as it seems.

I knew a national guard unit years ago that stored their arms in an approved arms room, with an approved (bank vault, really) door. The walls that the door was hung on? Lathe and plaster.

[identity profile] billthetailor.livejournal.com 2009-06-22 07:39 pm (UTC)(link)
Classic!

[identity profile] glesyn.livejournal.com 2009-06-22 11:31 pm (UTC)(link)
Interesting.

Welp, good thing I post boring photos....
themadblonde: (circle of friends)

honey...

[personal profile] themadblonde 2009-06-25 04:40 pm (UTC)(link)
anybody who saw "private" pix of me would be so busy trying to claw her/his eyes out that there would be no possibility of future harm. Not, of course, that such pictures exist. I only flist lock posts to say evil things about people behind their backs & plan surprise parties.