Search the Help Forum
|
[not a bug] Non-public photos viewable by others if url known
|
|
I noticed today that, if you know the specific url for a photo, it can be viewed in anyone's browser, whether or not it has been marked as public. Does this suggest a security gap?
Posted at 9:11AM, 19 April 2005 PDT
(
permalink
)
|
|

|
This is by design. There is no practical way for us to hit the database for each image we serve.
But there is no way that another person can learn the url of a photo without you sharing it.
Posted 86 months ago.
( permalink
)
|
|
|
>there is no way that another person can
> learn the url of a photo
>without you sharing it
This is not strictly true. When a person views a photo, the photo's URL remains in the browser's history list until it is cleared. Any other people who then use the browser on that same computer may encounter the image's URL, either by accident or design.
The notion of 'private' photos implies, at least to me, that the image can not be viewed by anyone unless they are logged in as an appropriately authorised member, but this is evidently not the case. The images may not be indexed, but they are not really private in any secure sense.
I think this needs to be more clearly explained to users who mark images as private, to help avoid potential embarassment.
As a side issue, are these images and their URLs able to be indexed by search engines?
Posted 86 months ago.
( permalink
)
|
|

|
> This is not strictly true.
Actually it is true. Unless you share a photo with someone, they have no way of getting the URL of the photo.
As for search engines, private photos will not be indexed, because no search engines will be able to see the photo page.
Posted 86 months ago.
( permalink
)
|
|
|
Eric, what I mean is that once you share that URL with another person, they can visit your private photo and that the photo's URL will then remain in the web browser's history. If another person then comes along and uses the same computer (say, for example, in an internet cafe), I assume the URL would be accessible through the browser history.
But I may be wrong about this...
Posted 86 months ago.
( permalink
)
|
|
|
This is also a problem if you decide to revoke permissions. If I send a photo link to someone and then subsequently decide that I don't want them (or anyone else) to see the photo anymore, then they still can as they have the URL in their history.
Posted 80 months ago.
( permalink
)
|
|
|
If I'm not mistaken, the image URL changes when you change the permissions. The "secret" part is changed.
Posted 80 months ago.
( permalink
)
|
|
|
I don't think the URL ever changes (to prevent link rot)... unless this is very new functionality.
Posted 80 months ago.
( permalink
)
|
|
|
tell them to go into internet options and clear their history, that will remove the image from the temp files and remove the url from their history.
if you don't want something out there, don't put it on the internet in the first place. =D
Posted 80 months ago.
( permalink
)
|
|
|
I just spent over 30min trying to find out if this 'issue' was how Flickr was designed. This thread is "THE" only place which states the truth about the privacy settings.
I 100% believe that Flickr must add more information to the FAQs pertaining to how the Privacy setting 'really' works.
The way it's worded is misleading and gives people a false sense of security.
The way it should be worded...
We can only offer a certain degree of protection which only controls the display of your photos on the actual Flickr.com site. No matter the setting you've selected, if the URL to the photo is known, it can be viewed. If you change a photo from public to private, the image URL will still be viewable to the public.
Every photo comes with its own privacy settings. You can make a photo available to everyone (That's public, and includes people visiting the site who aren't Flickr members), only make it visible to people who are your friends, just to your family, to both your friends and family, or you can select to not share or display your photo on Flickr.
This is the way it's curently worded:
That's not a problem. Every photo comes with its own privacy settings. You can make a photo available to everyone (That's public, and includes people visiting the site who aren't Flickr members), only make it visible to people who are your friends, just to your family, to both your friends and family, or you can keep an image completely private.
Come on Flickr - be kind and don't change the definition of "Private"
:)
Posted 77 months ago.
( permalink
)
|
This thread was closed automatically due of a lack of responses over the last month.
|