<![CDATA[Gawker: valleywag, Byron Ng]]> http://tags.gawker.com/assets/base/img/thumbs140x140/gawker.com.png <![CDATA[Gawker: valleywag, Byron Ng]]> http://gawker.com/tag/valleywag/byronng http://gawker.com/tag/valleywag/byronng <![CDATA[Photobucket's privacy problem finally solved]]> Photobucket has finally stopped allowing strangers to peek at users' private pictures. Byron Ng, a Canadian sysadmin with a penchant for finding Web security holes, found that knowing a photo's file name and the Photobucket link would be enough to expose the pics. This oversight allowed script kiddies to "fusker" — hacker slang for using an utility to extract images based on an identifiable sequence in the file name — to find uploaded naughty pictures or other interesting bits that weren't intended for public consumption. [News.com]

]]>
http://gawker.com/index.php?op=postcommentfeed&postId=5025605&view=rss&microfeed=true
<![CDATA[Paris Hilton, Lindsay Lohan private pics exposed by Yahoo hack]]> Want to see Paris Hilton's MySpace profile? How about Lindsay Lohan's? Don't worry about those pesky privacy settings. Thanks to "data portability," a faddish technology movement that the Valley has been buzzing about for months, you can see any profile you want on MySpace. Byron Ng, a Canadian computer technician with a knack for finding Web security holes, has discovered that Yahoo's integration with MySpace makes it easy to view photos for any profile. These images, which Ng obtained from Hilton's and Lohan's profiles, speak to the danger Yahoo and MySpace's lax data-sharing habits pose:

How did Ng get them? Here are his instructions, which involve no real hacking or unauthorized access — just typing in Web addresses. They work because Yahoo allows its users to add their MySpace profiles to their cell phones without checking their credentials; it requires a login, but accepts any login, not the specific user's login.

This points to a flaw in the notion of data portability, a movement which seeks to have personal information shared between social networks and other websites. Data portability was borne out of a wrongheaded assumption: That data needs to be shared. Most consumers, I believe, aren't particularly interested in the concept; they belong to a few social networks at most, and don't find managing their online personas to be a particular challenge. The technophiles of Silicon Valley, however, join every network they hear about, and find retyping their personal information and manually adding friends maddeningly inefficient.

It's all well and good to speed things up, but how far, how fast? The example discovered by Ng just demonstrates the tendency of Web companies to take shortcuts with security. With data portability, we won't just have to worry about how well a particular social network guards their personal data; we'll now have to worry about every partner website it connects with.

Technical experts — every engineer in the Valley considers himself one — will no doubt weigh in with elaborate approaches to assuring security. I'm skeptical that any of them will work. It's a combinatorial problem; not only will the protocols have to be designed to be airtight, but we'll have to trust that each website implements them flawlessly. It only takes one weak link to break the chain. Already, Facebook has cut off Google's connectivity to its profiles in a dispute over whether Google's software is secure enough. Even the fame-seeking likes of Paris Hilton and Lindsay Lohan deserve better.

]]>
http://gawker.com/index.php?op=postcommentfeed&postId=5012543&view=rss&microfeed=true
<![CDATA[How a Canadian computer guy got Paris Hilton and Lindsay Lohan's pics]]> Byron Ng's instructions for viewing any MySpace profile:
1. you'll need a Yahoo account. go to www.yahoomail.com and create a yahoo account if you don't have one already. and you will need to go to www.myspace.com to sign up for a myspace account first, if you don't have one already.



2.go to http://beta.m.yahoo.com/w/gallery/widget click on the 'mail' button under "sign in to yahoo!"



3. click on 'click here to sign in'



4. enter your yahoo id, yahoo password



5. then on the top of the screen in the white box, enter: myspace then click Search Widgets Gallery



6. you will see a green box in the middle with the word 'myspace' in there.



7. click the green myspace.



8. see in the middle of the screen it says "add it" - click that.



9. click yes when it asks you about sharing info



10. go here http://beta.m.yahoo.com/w/gallery/widget



11. enter myspace into the box. click search widgets gallery



12. click on the green myspace. now, since you have already set it up in the previous steps, it won't ask you to download again



13. click on 'go to widget' (that’s right below the 'already added it" text



14. now sign in to myspace



15. now take the URL I asked you to save above before step 1: http://beta.m.yahoo.com/w/myspace/profile/en.osl?userID=16527727 and click on it. it may ask you to sign into yahoo or my space. sign in as appropriate. now you should be able to see the person's pictures. if you can only see your own profile, then click on it again http://beta.m.yahoo.com/w/myspace/profile/en.osl?userID=16527727 then it will work.

]]>
http://gawker.com/index.php?op=postcommentfeed&postId=5012541&view=rss&microfeed=true