<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Your private photos are still private.</title>
	<atom:link href="http://blogs.smugmug.com/don/2008/01/28/your-private-photos-are-still-private/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.smugmug.com/don/2008/01/28/your-private-photos-are-still-private/</link>
	<description>Thought stream from SmugMug's CEO &#38; Chief Geek</description>
	<lastBuildDate>Tue, 24 Nov 2009 10:26:00 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9-rare</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: mod converter</title>
		<link>http://blogs.smugmug.com/don/2008/01/28/your-private-photos-are-still-private/comment-page-1/#comment-104476</link>
		<dc:creator>mod converter</dc:creator>
		<pubDate>Fri, 06 Nov 2009 15:56:44 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.smugmug.com/don/?p=194#comment-104476</guid>
		<description>Love it! You got me so excited to get one and start shooting video!  </description>
		<content:encoded><![CDATA[<p>Love it! You got me so excited to get one and start shooting video!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: su &#231;i&#231;eği</title>
		<link>http://blogs.smugmug.com/don/2008/01/28/your-private-photos-are-still-private/comment-page-1/#comment-104324</link>
		<dc:creator>su &#231;i&#231;eği</dc:creator>
		<pubDate>Sun, 09 Aug 2009 10:31:41 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.smugmug.com/don/?p=194#comment-104324</guid>
		<description>I found this informative and interesting blog so i think so its very useful and knowledge able.I would like to thank you for the efforts you have made in writing this article. I am hoping the same best work from you in the future as well. In fact your creative writing abilities has inspired me. </description>
		<content:encoded><![CDATA[<p>I found this informative and interesting blog so i think so its very useful and knowledge able.I would like to thank you for the efforts you have made in writing this article. I am hoping the same best work from you in the future as well. In fact your creative writing abilities has inspired me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: donna</title>
		<link>http://blogs.smugmug.com/don/2008/01/28/your-private-photos-are-still-private/comment-page-1/#comment-104248</link>
		<dc:creator>donna</dc:creator>
		<pubDate>Sat, 25 Apr 2009 20:42:10 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.smugmug.com/don/?p=194#comment-104248</guid>
		<description>grrrrrrrrrrrrrrrrr </description>
		<content:encoded><![CDATA[<p>grrrrrrrrrrrrrrrrr</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: FocalPower&#8230;the blog &#187; Blog Archive &#187; Who Controls Your Photos Online?</title>
		<link>http://blogs.smugmug.com/don/2008/01/28/your-private-photos-are-still-private/comment-page-1/#comment-103206</link>
		<dc:creator>FocalPower&#8230;the blog &#187; Blog Archive &#187; Who Controls Your Photos Online?</dc:creator>
		<pubDate>Wed, 09 Jul 2008 16:43:27 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.smugmug.com/don/?p=194#comment-103206</guid>
		<description>[...] sake of their customers rather than ignore it for the sake of their API development community.  SmugMug had a similar security issue be raised in the recent past which they quickly fixed&#8230;this is how a responsible company [...]</description>
		<content:encoded><![CDATA[<p>[...] sake of their customers rather than ignore it for the sake of their API development community.  SmugMug had a similar security issue be raised in the recent past which they quickly fixed&#8230;this is how a responsible company [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: You don&#8217;t need to be secure to be successful &#124; PHP kitchen</title>
		<link>http://blogs.smugmug.com/don/2008/01/28/your-private-photos-are-still-private/comment-page-1/#comment-102588</link>
		<dc:creator>You don&#8217;t need to be secure to be successful &#124; PHP kitchen</dc:creator>
		<pubDate>Mon, 14 Apr 2008 13:51:10 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.smugmug.com/don/?p=194#comment-102588</guid>
		<description>[...] from Don MacAskill, the CEO of smugmug, in response to this article via Chris [...]</description>
		<content:encoded><![CDATA[<p>[...] from Don MacAskill, the CEO of smugmug, in response to this article via Chris [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fotofimmel &#187; 2008 &#187; April &#187; 11</title>
		<link>http://blogs.smugmug.com/don/2008/01/28/your-private-photos-are-still-private/comment-page-1/#comment-102574</link>
		<dc:creator>Fotofimmel &#187; 2008 &#187; April &#187; 11</dc:creator>
		<pubDate>Fri, 11 Apr 2008 14:32:54 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.smugmug.com/don/?p=194#comment-102574</guid>
		<description>[...] Die Sicherheit von Smugmug wird derzeit kontrovers diskutiert. Wer über einen Smugmug Account nachdenkt, sollte beide Seiten zur Kenntnis nehmen. Hier und hier. [...]</description>
		<content:encoded><![CDATA[<p>[...] Die Sicherheit von Smugmug wird derzeit kontrovers diskutiert. Wer über einen Smugmug Account nachdenkt, sollte beide Seiten zur Kenntnis nehmen. Hier und hier. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SmugBlog: Don MacAskill &#187; Blog Archive &#187; Big privacy changes at SmugMug</title>
		<link>http://blogs.smugmug.com/don/2008/01/28/your-private-photos-are-still-private/comment-page-1/#comment-102023</link>
		<dc:creator>SmugBlog: Don MacAskill &#187; Blog Archive &#187; Big privacy changes at SmugMug</dc:creator>
		<pubDate>Fri, 08 Feb 2008 10:03:37 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.smugmug.com/don/?p=194#comment-102023</guid>
		<description>[...] I told you we&#8217;d listen. [...]</description>
		<content:encoded><![CDATA[<p>[...] I told you we&#8217;d listen. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott</title>
		<link>http://blogs.smugmug.com/don/2008/01/28/your-private-photos-are-still-private/comment-page-1/#comment-102005</link>
		<dc:creator>Scott</dc:creator>
		<pubDate>Fri, 01 Feb 2008 23:55:10 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.smugmug.com/don/?p=194#comment-102005</guid>
		<description>@Jeff Dean

&quot;The fact that private pictures can be found simply by iterating over URLs points to a weak implementation&quot;

Disagree -- the problem is not the implementation, it&#039;s the name.  If they called them unlisted, it would be clear what they meant.  For example, &quot;unlisted&quot; phone numbers can be found simply by iterating over phone numbers.  This is not a weak implementation, it&#039;s just what unlisted means -- not listed in a directory.</description>
		<content:encoded><![CDATA[<p>@Jeff Dean</p>
<p>&#8220;The fact that private pictures can be found simply by iterating over URLs points to a weak implementation&#8221;</p>
<p>Disagree &#8212; the problem is not the implementation, it&#8217;s the name.  If they called them unlisted, it would be clear what they meant.  For example, &#8220;unlisted&#8221; phone numbers can be found simply by iterating over phone numbers.  This is not a weak implementation, it&#8217;s just what unlisted means &#8212; not listed in a directory.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Privacy, Security and Elastic Computing &#171; Evil Fish</title>
		<link>http://blogs.smugmug.com/don/2008/01/28/your-private-photos-are-still-private/comment-page-1/#comment-102001</link>
		<dc:creator>Privacy, Security and Elastic Computing &#171; Evil Fish</dc:creator>
		<pubDate>Fri, 01 Feb 2008 12:21:09 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.smugmug.com/don/?p=194#comment-102001</guid>
		<description>[...] is the result of an an interesting debate if security and privacy are separated and how privacy and probability are [...]</description>
		<content:encoded><![CDATA[<p>[...] is the result of an an interesting debate if security and privacy are separated and how privacy and probability are [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff Dean</title>
		<link>http://blogs.smugmug.com/don/2008/01/28/your-private-photos-are-still-private/comment-page-1/#comment-101993</link>
		<dc:creator>Jeff Dean</dc:creator>
		<pubDate>Fri, 01 Feb 2008 04:41:03 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.smugmug.com/don/?p=194#comment-101993</guid>
		<description>I complained about this problem almost a year ago and got the same basic response: we don&#039;t think this is a problem. I thought it was problem then and I still do now.  The fact that private pictures can be found simply by iterating over URLs points to a weak implementation; there is no good reason for allowing this.

I ask again, SmugMug, that you please fix this.

(BTW,  I also reported the problem about being able to determine the owner of an account.  By iterating over URLs, I found a set of private pictures from a January 2003 vacation in Tenerife and I gave SmugMug the names of the owners.  I am glad that you finally fixed this but I am disappointed that it took you so long.)

-- Jeff</description>
		<content:encoded><![CDATA[<p>I complained about this problem almost a year ago and got the same basic response: we don&#8217;t think this is a problem. I thought it was problem then and I still do now.  The fact that private pictures can be found simply by iterating over URLs points to a weak implementation; there is no good reason for allowing this.</p>
<p>I ask again, SmugMug, that you please fix this.</p>
<p>(BTW,  I also reported the problem about being able to determine the owner of an account.  By iterating over URLs, I found a set of private pictures from a January 2003 vacation in Tenerife and I gave SmugMug the names of the owners.  I am glad that you finally fixed this but I am disappointed that it took you so long.)</p>
<p>&#8211; Jeff</p>
]]></content:encoded>
	</item>
</channel>
</rss>
