<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Big privacy changes at SmugMug</title>
	<atom:link href="http://blogs.smugmug.com/don/2008/02/08/big-privacy-changes-at-smugmug/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.smugmug.com/don/2008/02/08/big-privacy-changes-at-smugmug/</link>
	<description>Thought stream from SmugMug's CEO &#38; Chief Geek</description>
	<pubDate>Thu, 03 Jul 2008 23:07:49 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6-bleeding2</generator>
		<item>
		<title>By: pysmug version 0.4 coming soon &#171; I&#8217;m not here.</title>
		<link>http://blogs.smugmug.com/don/2008/02/08/big-privacy-changes-at-smugmug/#comment-102912</link>
		<dc:creator>pysmug version 0.4 coming soon &#171; I&#8217;m not here.</dc:creator>
		<pubDate>Sun, 11 May 2008 05:19:46 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.smugmug.com/don/?p=196#comment-102912</guid>
		<description>[...] the biggest changes are compatibility with new security changes required for version 1.2.2 of the SmugMug API. It&#8217;s now also possible to register function [...]</description>
		<content:encoded><![CDATA[<p>[...] the biggest changes are compatibility with new security changes required for version 1.2.2 of the SmugMug API. It&#8217;s now also possible to register function [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://blogs.smugmug.com/don/2008/02/08/big-privacy-changes-at-smugmug/#comment-102194</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Sat, 08 Mar 2008 04:04:34 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.smugmug.com/don/?p=196#comment-102194</guid>
		<description>It would be very nice if you would start issuing API keys again...</description>
		<content:encoded><![CDATA[<p>It would be very nice if you would start issuing API keys again&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SmugBlog: Don MacAskill &#187; Blog Archive &#187; On so-called &#8216;holes&#8217; in our new privacy scheme</title>
		<link>http://blogs.smugmug.com/don/2008/02/08/big-privacy-changes-at-smugmug/#comment-102106</link>
		<dc:creator>SmugBlog: Don MacAskill &#187; Blog Archive &#187; On so-called &#8216;holes&#8217; in our new privacy scheme</dc:creator>
		<pubDate>Tue, 19 Feb 2008 18:29:04 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.smugmug.com/don/?p=196#comment-102106</guid>
		<description>[...] clear: If you try their so-called exploit on a &#8216;new&#8217; photo or video (one uploaded after our privacy changes on February 8th), it just won&#8217;t work. If you try it on an &#8216;old&#8217; photo or video, [...]</description>
		<content:encoded><![CDATA[<p>[...] clear: If you try their so-called exploit on a &#8216;new&#8217; photo or video (one uploaded after our privacy changes on February 8th), it just won&#8217;t work. If you try it on an &#8216;old&#8217; photo or video, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Johnson</title>
		<link>http://blogs.smugmug.com/don/2008/02/08/big-privacy-changes-at-smugmug/#comment-102040</link>
		<dc:creator>Matt Johnson</dc:creator>
		<pubDate>Fri, 08 Feb 2008 22:16:46 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.smugmug.com/don/?p=196#comment-102040</guid>
		<description>I just checked the holes I found last week. The bugs that allowed me to view an image where external linking was even disabled have now been fixed, even on the old images. With the addition of the imagekey on the images it locks images down even tighter so that it will be harder for hackers to even find such holes in the future, and it prevents the ability to just iterate through images.

If you want the images protected, then they need to be password protected, and external linking disabled. Password protecting essentially locks the front door, while disabling external linking locks the back door, all windows, and covers the windows.</description>
		<content:encoded><![CDATA[<p>I just checked the holes I found last week. The bugs that allowed me to view an image where external linking was even disabled have now been fixed, even on the old images. With the addition of the imagekey on the images it locks images down even tighter so that it will be harder for hackers to even find such holes in the future, and it prevents the ability to just iterate through images.</p>
<p>If you want the images protected, then they need to be password protected, and external linking disabled. Password protecting essentially locks the front door, while disabling external linking locks the back door, all windows, and covers the windows.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kevin Forbes</title>
		<link>http://blogs.smugmug.com/don/2008/02/08/big-privacy-changes-at-smugmug/#comment-102039</link>
		<dc:creator>Kevin Forbes</dc:creator>
		<pubDate>Fri, 08 Feb 2008 21:57:49 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.smugmug.com/don/?p=196#comment-102039</guid>
		<description>Wow, that was quick!  Personally, I have no problem with the way it worked before.  It worked the way I was expecting, having read through the options.  But you've definitely done your customers (and future customers) a good turn by making these changes.</description>
		<content:encoded><![CDATA[<p>Wow, that was quick!  Personally, I have no problem with the way it worked before.  It worked the way I was expecting, having read through the options.  But you&#8217;ve definitely done your customers (and future customers) a good turn by making these changes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Luis Feinzaig</title>
		<link>http://blogs.smugmug.com/don/2008/02/08/big-privacy-changes-at-smugmug/#comment-102038</link>
		<dc:creator>Luis Feinzaig</dc:creator>
		<pubDate>Fri, 08 Feb 2008 19:44:49 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.smugmug.com/don/?p=196#comment-102038</guid>
		<description>This is a good fix for the problem.  However, if technically possible, you should add the possibility of opting out of this feature (the new alphanumerical key). In my case I am not that concerned about privacy as I am about ease of use ( I handle a very large quantity of galleries). Good job!</description>
		<content:encoded><![CDATA[<p>This is a good fix for the problem.  However, if technically possible, you should add the possibility of opting out of this feature (the new alphanumerical key). In my case I am not that concerned about privacy as I am about ease of use ( I handle a very large quantity of galleries). Good job!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Philipp Lenssen</title>
		<link>http://blogs.smugmug.com/don/2008/02/08/big-privacy-changes-at-smugmug/#comment-102035</link>
		<dc:creator>Philipp Lenssen</dc:creator>
		<pubDate>Fri, 08 Feb 2008 16:49:44 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.smugmug.com/don/?p=196#comment-102035</guid>
		<description>&#62; I wasn't completely happy that it was so easy
&#62; to guess an album but I don't really have
&#62; anything that needs to be hidden that well
&#62; and still be accessible without a password,
&#62; so I wasn't concerned.

Mark, just to clarify in case you missed this: photos set to password-protection also showed up publicly when iterating image IDs. So even if you set your old album to password protection and private, its pics were publicly crawlable -- only disabling external linking stopped the pics from showing when iterating IDs. Not sure what the current status is as we didn't test the site for some time now, but if old galleries remain unfixed, all that would still be the case -- maybe Don can clarify if that's the case or not.</description>
		<content:encoded><![CDATA[<p>&gt; I wasn&#8217;t completely happy that it was so easy<br />
&gt; to guess an album but I don&#8217;t really have<br />
&gt; anything that needs to be hidden that well<br />
&gt; and still be accessible without a password,<br />
&gt; so I wasn&#8217;t concerned.</p>
<p>Mark, just to clarify in case you missed this: photos set to password-protection also showed up publicly when iterating image IDs. So even if you set your old album to password protection and private, its pics were publicly crawlable &#8212; only disabling external linking stopped the pics from showing when iterating IDs. Not sure what the current status is as we didn&#8217;t test the site for some time now, but if old galleries remain unfixed, all that would still be the case &#8212; maybe Don can clarify if that&#8217;s the case or not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Johnson</title>
		<link>http://blogs.smugmug.com/don/2008/02/08/big-privacy-changes-at-smugmug/#comment-102034</link>
		<dc:creator>Matt Johnson</dc:creator>
		<pubDate>Fri, 08 Feb 2008 16:33:56 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.smugmug.com/don/?p=196#comment-102034</guid>
		<description>You guys rock as always! I am impressed with the speed in which this was taken care of.

At first I was a little concerned about some of the loop holes, although I didn't see them as critical, I was impressed that you were willing to address it publicly and openly. 

You have made us aware of the problems, listened to our concerns, and acted quickly. For that you have earned more of my respect.</description>
		<content:encoded><![CDATA[<p>You guys rock as always! I am impressed with the speed in which this was taken care of.</p>
<p>At first I was a little concerned about some of the loop holes, although I didn&#8217;t see them as critical, I was impressed that you were willing to address it publicly and openly. </p>
<p>You have made us aware of the problems, listened to our concerns, and acted quickly. For that you have earned more of my respect.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Seann</title>
		<link>http://blogs.smugmug.com/don/2008/02/08/big-privacy-changes-at-smugmug/#comment-102029</link>
		<dc:creator>Seann</dc:creator>
		<pubDate>Fri, 08 Feb 2008 14:49:18 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.smugmug.com/don/?p=196#comment-102029</guid>
		<description>You guys are awesome. Undoubtedly the best photo site on the web for consumers or pros. Keep up the great work, openness and uncomprmising user support.</description>
		<content:encoded><![CDATA[<p>You guys are awesome. Undoubtedly the best photo site on the web for consumers or pros. Keep up the great work, openness and uncomprmising user support.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://blogs.smugmug.com/don/2008/02/08/big-privacy-changes-at-smugmug/#comment-102028</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Fri, 08 Feb 2008 14:10:28 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.smugmug.com/don/?p=196#comment-102028</guid>
		<description>I'm glad you did this.  I already have an account and I understood the distinction between private and public when I opened it.  I wasn't completely happy that it was so easy to guess an album but I don't really have anything that needs to be hidden that well and still be accessible without a password, so I wasn't concerned.  (I guess it was more of a technical concern than practical and practice is what matters).

But still, I'm happy with this change and how quickly you turned it around.  The naming change from Private to Unlisted is probably the most important part so people are more aware of what it means.

I used to have my pictures on another website that would talk about quick fixes when bugs came up but it rarely happened.  That's what drove me away, so keep up the good work!</description>
		<content:encoded><![CDATA[<p>I&#8217;m glad you did this.  I already have an account and I understood the distinction between private and public when I opened it.  I wasn&#8217;t completely happy that it was so easy to guess an album but I don&#8217;t really have anything that needs to be hidden that well and still be accessible without a password, so I wasn&#8217;t concerned.  (I guess it was more of a technical concern than practical and practice is what matters).</p>
<p>But still, I&#8217;m happy with this change and how quickly you turned it around.  The naming change from Private to Unlisted is probably the most important part so people are more aware of what it means.</p>
<p>I used to have my pictures on another website that would talk about quick fixes when bugs came up but it rarely happened.  That&#8217;s what drove me away, so keep up the good work!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
