Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

Tracking System
Tracking System
Private Detectives
Quality Security Services in California
Fleet Management
Hosting

Popular content

Last viewed:

  • Craigslist Win Good for Free Speech, But Court Creates Murky "Section 230" Precedent
  • Web-based Anonymizer Discontinued
  • DNSSEC Advances in gTLDs; Bernstein Intros DNSCurve
  • Judge Lifts Unconstitutional Gag Order Against MIT Students
  • Black Hat/DefCon: Welcome to the funhouse
  • Phishers point scam at Apple's iTunes
  • Digital Signage and Consumer Privacy

tags in Topics

Activists Alert Anonymity Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

MySpace's Leaked Photos More Popular Than Sweeney Todd

Submitted by MacRonin on January 30, 2008 - 7:10am
  • Activists
  • Companies
  • Data Breach
  • Databases
  • Editorial
  • Entertainment
  • Exploits
  • Hmmm
  • MySpace
  • P2P
  • Photos Five
  • Privacy
  • Reviews
  • Security
  • Spin Zone

MySpace's Leaked Photos More Popular Than Sweeney Todd - Via Threat Level:

The 17-gigabyte file containing half-of-million photos pillaged from MySpace accounts made the Pirate Bay's top -ten list of most popular downloads over the weekend, beating out pirated copies of No Country For Old Men,  Sweeney Todd and the sci-fi flick I Am Legend.

Sunday afternoon the file -- compiled using a still-unacknowledged hole in MySpace's architecture that exposed photos in private profiles --  was the 9th most popular download on the torrent site, with over 6,700 downloads in progress.

On Monday, though, the file's popularity plummeted as the first round of downloaders completed their transfers and found that the photos -- a mix of images from public and private profiles -- just weren't that interesting.

"Wedding, baby, party, wedding, baby, party, etc. Truly boring stuff," one disappointed downloader posted to the torrent's message board. "Anyone have that porn image recognition software? That would help a lot."

Another pirate offered a more positive review of the purloined pics. "There are countless great pictures in here like cross-dressing metal-heads," he wrote. "If you want porn, then download porn, idiots."

At Ed Felton's blog Freedom to Tinker, Felton wonders if "DMaul" -- the TribalWar.com user who compiled and later published the file -- might have been motivated by a desire to punish MySpace for leaving the hole open for over three months.

"This may be the most serious privacy breach yet at MySpace," Felton writes. "Kevin Poulsen's story at Wired News implies that the leak may have been deliberate payback for MySpace failing to fix the vulnerability that allowed the leaks"

Now suppose you know that a company???s product has a flaw that is endangering its customers, and the company is denying and delaying. There is something you can do that will force them to fix the problem -- you can arrange an attention-grabbing demonstration that will show customers (and the press) that the risk is real. All you have to do is exploit the flaw yourself, get a bunch of private data, and release it. Which is pretty much what DMaul did.

To be clear, Im not endorsing this course of action. I???m just pointing out why someone might find it attractive despite the obvious ethical objections.

DMaul compiled the images before MySpace fixed the bug, but didn't put them on BitTorrent until after.  So unless DMail had plans to publish the file anyway, this isn't a case of somebody staging a splashy exploitation of a vulnerability in order hasten its closure.

DMaul did say he was trying to prove a point by publishing the photos, but his point wasn't that MySpace should fix its bugs faster, but rather, "It is ridiculous to think that there is privacy on public websites."

Some of the people downloading the file this weekend, though, were apparently motivated by "disgust at Myspace," as a user named "delton19" put it.

Another downloader named "blaine00" wrote, "I am now only downloading this to spite MySpace. I can see this is going to be half a million pieces of crap. But I'd like to go ahead and get it so I can help seed it out to the people that are going to download it no matter what comments they read."

"Sixbirdnine" added, "Maybe people will think twice about uploading personal info."

(Photo by TheAlieness GiselaGiardino????)

  • MySpace Quietly Fixes Bug that Gave Voyeurs Access to Teens' Private Photos
  • Five Questions With the Guy Who Made the MySpace Private Photo Torrent
  • MySpace Bug Leaks 'Private' Teen Photos to Voyeurs
  • More Charges in MySpace Cyber Stalking Case
  • Convicted Hacker Charged With Extortion After Attack On Model's MySpace Account
  • Federal Grand Jury Issues Subpoenas in Teen Cyberbullying Case
  • 29,000 Sex Offenders Found on Myspace
  • No Charges Will Be Filed In Cyberbullying Case
  • MySpace to Purge Sex Offenders

(Read Original Article - Via Threat Level.)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • Hi-tech governments growing keener on snooping, says report
  • Classmates.com’s Facebook Mimicking Prompts Privacy Suit
  • Zeus botnet dealt a blow as ISP Troyak knocked out
  • Better U.S. Net Rules for Iran, Cuba and Syria
  • European Parliament Rips Global IP Accord (ACTA)
  • Hackers exploit latest IE zero-day with drive-by attacks
  • Government No-Fly List Includes the Dead
  • Mobile that allows bosses to snoop on staff developed
  • New "Smart Meters" for Energy Use Put Privacy at Risk
  • The Limits of Identity Cards (Schneier)
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.