Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

Tracking System
Tracking System
Private Detectives
Quality Security Services in California
Fleet Management
Hosting

Popular content

Last viewed:

  • US$250 people tracking device - gizmag
  • California county tags gang members with GPS
  • Zune DRM Cracked
  • Tucker Carlson and the right's perpetual self-victimhood
  • Air Marshals’ Secret Communication Weapon
  • EU Politicians Strikes Back Against Three Strikes
  • Obama's Transparent Transition

tags in Topics

Activists Alert Anonymity Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

MySpace Quietly Fixes Bug that Gave Voyeurs Access to Teens' Private Photos

Submitted by MacRonin on January 20, 2008 - 2:13am
  • Activists
  • Alert
  • Databases
  • Entertainment
  • Exploits
  • Hmmm
  • MySpace
  • Privacy
  • Private
  • Remember
  • Security
  • Software

MySpace Quietly Fixes Bug that Gave Voyeurs Access to Teens' Private Photos - Via Threat Level:

I reported yesterday on a bug in MySpace's architecture that allowed strangers to peer inside the MySpace photo galleries of some private profiles, despite assurances from MySpace that those pictures can only be seen by people on a user's friends list.

The bug had been around since at least October (Thanks to Rose for tipping me off), during which time it had been gleefully exploited by voyeurs, hackers, entrepreneurs and lechers; you can find pages and pages of  public message board comments around the web in which posters are peeking in on 14 and 15-year-old girls and sharing what they find.

Ad-supported web sites with names like Can't Hide and MySpacePrivateProfile.com emerged to earn a buck off the glitch. One such site reports that its users have accessed, or attempted to access, 77,000 private profiles -- 3,000 of them today.

While all this going on more-or-less in plain sight, you have to wonder where MySpace's safety and security team was. Was this glitch that hard to fix?

Apparently not. Barely 24 hours after my story hit the front door of Wired.com, MySpace has, without comment, closed the backdoor, and the websites that were exploiting it are no longer delivering private photos. That seems to leave just two possibilities:

  1. MySpace didn't know this was going on before.
  2. MySpace knew about it, but didn't take action until the press noticed.

I'll have more next week.

See Also:

  • MySpace Bug Leaks 'Private' Teen Photos to Voyeurs
  • More Charges in MySpace Cyber Stalking Case
  • Convicted Hacker Charged With Extortion After Attack On Model's MySpace Account
  • Federal Grand Jury Issues Subpoenas in Teen Cyberbullying Case
  • 29,000 Sex Offenders Found on Myspace
  • No Charges Will Be Filed In Cyberbullying Case
  • MySpace to Purge Sex Offenders

(Read Original Article - Via Threat Level.)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • In Bid to Sway Sales, Cameras Track Shoppers
  • Unprecedented 25-Year Sentence Sought for TJX Hacker
  • EFF Appeals Dismissal of Warrantless Wiretapping Case
  • Viacom Makes Its Case Against Yesterday's YouTube
  • Obama supports Senators draft plan to rework U.S. immigration policy - Includes National Biometric ID card for all.
  • Domain Names Can't Defend Themselves
  • Hacker Disables More Than 100 Cars Remotely
  • Judges Approves $9.5 Million Facebook ‘Beacon’ Accord
  • Hooking Up The Big Brother Machine... And Fighting It
  • Court: State Can Dump Non-Sex Offenders Into Registry
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.