4 ms·
I agree that Facebook should try to prevent private information from leaking out. Even if they are indirectly involved. But I also think sites should never use
by starquake 10y ago
I agree that Facebook should try to prevent private information from leaking out. Even if they are indirectly involved.
But I also think sites should never use personally identifiable information in the URL. There are much more sites that cause issues when sharing these kinds of URLs. To name a few: bit.ly, twitter, Comments in Hacker News.
- ikeboy 10y agoHow are HN comments an issue? All comments are public, so what's the concern? Keeping information in URLs is fine as long as it has enough entropy to be unbruteforcable. Bit.ly and t.co don't, and so aren't secure.
- starquake 10y agoThat's exactly my point. Because some users don't understand this technical issue, you shouldn't use personally identifiable information in URLs. They might post it to services with enough entropy. But they also might post it to public parts of the internet. I use HN comments as an example of an unsafe way to share URLs with personally identifiable information.