Privacy Digest

News that can impact your privacy.
Login/Register
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
  • FAQ
  • Wishlists
  • Contact
  • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

RSS Feed + Site Map

Syndicate content
more

Advertisements

GPS Tracking
Search By Phone Number
Hosting
Home Security Systems Toronto
Mercedes-Benz Luxury Cars News
Disk Encryption
spy camera

Popular content

Last viewed:

  • Comcast's Disappointing Defense
  • Google Online Security Blog: All Your iFrame Are Point to Us
  • Technology: Data mining - Fighting crime with databases
  • Viacom Vs YouTube, Beyond Privacy
  • How Private Are Sites' Membership Lists?
  • Are Xbox Live support staff helping hackers hijack accounts?
  • New ATM Malware Captures PINs and Cash — Updated

tags in Topics

Activists Alert Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Software Spin Zone Surveillance Telecommunications Tracking
more tags

Performancing Metrics Blog Statistics
EatonWeb Blog Directory
Listed on BlogShares
View blog authority
Congressional Research
Broadcast Flag

MySpace Quietly Fixes Bug that Gave Voyeurs Access to Teens' Private Photos

Submitted by MacRonin on January 20, 2008 - 2:13am.
  • Activists
  • Alert
  • Databases
  • Entertainment
  • Exploits
  • Hmmm
  • MySpace
  • Privacy
  • Remember
  • Security
  • Software

MySpace Quietly Fixes Bug that Gave Voyeurs Access to Teens' Private Photos - Via Threat Level:

I reported yesterday on a bug in MySpace's architecture that allowed strangers to peer inside the MySpace photo galleries of some private profiles, despite assurances from MySpace that those pictures can only be seen by people on a user's friends list.

The bug had been around since at least October (Thanks to Rose for tipping me off), during which time it had been gleefully exploited by voyeurs, hackers, entrepreneurs and lechers; you can find pages and pages of  public message board comments around the web in which posters are peeking in on 14 and 15-year-old girls and sharing what they find.

Ad-supported web sites with names like Can't Hide and MySpacePrivateProfile.com emerged to earn a buck off the glitch. One such site reports that its users have accessed, or attempted to access, 77,000 private profiles -- 3,000 of them today.

While all this going on more-or-less in plain sight, you have to wonder where MySpace's safety and security team was. Was this glitch that hard to fix?

Apparently not. Barely 24 hours after my story hit the front door of Wired.com, MySpace has, without comment, closed the backdoor, and the websites that were exploiting it are no longer delivering private photos. That seems to leave just two possibilities:

  1. MySpace didn't know this was going on before.

  2. MySpace knew about it, but didn't take action until the press noticed.

I'll have more next week.

See Also:

  • MySpace Bug Leaks 'Private' Teen Photos to Voyeurs
  • More Charges in MySpace Cyber Stalking Case
  • Convicted Hacker Charged With Extortion After Attack On Model's MySpace Account
  • Federal Grand Jury Issues Subpoenas in Teen Cyberbullying Case
  • 29,000 Sex Offenders Found on Myspace
  • No Charges Will Be Filed In Cyberbullying Case
  • MySpace to Purge Sex Offenders

(Read Original Article - Via Threat Level.)


Bookmark/Search this post with:
  • Delicious Delicious
  • Digg Digg
  • Reddit Reddit
  • Google Google
  • Yahoo Yahoo
  • Technorati Technorati
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • Apple patching serious SMS vulnerability on iPhone
  • Enter the Advertisers - self-regulatory principles ?
  • Out of business, Clear may sell customer data
  • TSA asked to ensure safety of customer data after Clear closing
  • Several Facts about Google and HTTPS
  • China thinks twice – and its 300m internet users scent a rare victory
  • Did the Sanford E-Mail Tipster or the Newspaper Break the Law?
  • Supreme Court Serves Up Remote-Recording Victory
  • Deep-Packet Inspection in U.S. Scrutinized Following Iran Surveillance
  • ATM Vendor Halts Researcher’s Talk on Vulnerability
more
Compilation © Copyright 1997-2009 Paul Hardwick, with Web Hosting provided by MacRonin.com.