<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; private galleries</title> <atom:link href="http://www.ghacks.net/tag/private-galleries/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 17:32:23 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Private Galleries can be accessed at Smugmug</title><link>http://www.ghacks.net/2008/01/28/private-galleries-can-be-accessed-at-smugmug/</link> <comments>http://www.ghacks.net/2008/01/28/private-galleries-can-be-accessed-at-smugmug/#comments</comments> <pubDate>Mon, 28 Jan 2008 12:32:25 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Hacking]]></category> <category><![CDATA[Online Services]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[download pictures]]></category> <category><![CDATA[picture gallery]]></category> <category><![CDATA[private galleries]]></category> <category><![CDATA[smugmug]]></category> <guid
isPermaLink="false">http://www.ghacks.net/2008/01/28/private-galleries-can-be-accessed-at-smugmug/</guid> <description><![CDATA[If you would use an image host, put up some of your images and set them to private, would you expect them to be still accessible by anyone ? This is apparently the case over at Smugmug where a private setting simply means that the pictures and image galleries are not directly linked from the homepage anymore but can still be accessed by simply entering the url directly in the browser address bar or download manager.]]></description> <content:encoded><![CDATA[<p>If you would use an image host, put up some of your images and set them to private, would you expect them to be still accessible by anyone ? This is apparently the case over at <a
href="http://www.smugmug.com/">Smugmug</a> where a private setting simply means that the pictures and image galleries are not directly linked from the homepage anymore but can still be accessed by simply entering the url directly in the browser address bar or download manager.</p><p>The real problem arises because files are named sequentially at Smugmug which means that anyone with just a little bit of technical knowledge will be able to download all images from all galleries set to public and private. The only galleries that are not accessible are the password protected ones obviously.</p><p>The urls for the galleries can be accessed by opening a url starting with http://www.smugmug.com/gallery/*, for example http://www.smugmug.com/gallery/1000, http://www.smugmug.com/gallery/1001 in your browser. Pictures can be accessed directly by loading http://www.smugmug.com/photos/*-M.jpg in your browser where * is a number between 1 and x. So, everyone can access pictures like  http://www.smugmug.com/photos/1000-M.jpg, http://www.smugmug.com/photos/10001-M.jpg and so on.</p><p><span
id="more-3020"></span><a
href="http://blogoscoped.com/archive/2008-01-28-n59.html">Google Blogoscope</a> who discovered this loophole contacted Smugmug and received a reply that was not that satisfactory. According to CEO Don MacAskill this is the intended way it should work:</p><blockquote><p>First of all, we view security and privacy as two separate, but related, issues. Security is like locking your front door (no-one can get in with out a key) and privacy is like closing your window drapes (no-one can look in from the outside, but you can tell people where you live and they can visit without a key).</p><p>At SmugMug, the feature you’re talking about, private galleries, falls under the privacy umbrella, not security. It’s intentionally designed so that you can “tell other people” about your photos (share a URL in an email, embed or hyperlink on your blog or message forum, etc) without having to share something like a password. Only people you’ve shared this URL with can find the gallery and/or photos in question.</p></blockquote> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/01/28/private-galleries-can-be-accessed-at-smugmug/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> </channel> </rss>
