6 ms·
The issue though, is that we had thought that the address wasn't exposed. We're still baffled as to how the address got exposed to google, but we're assuming on
by edb 18y ago
The issue though, is that we had thought that the address wasn't exposed. We're still baffled as to how the address got exposed to google, but we're assuming one of our employees must have done it somehow.
That made me thing though... can you trust your users not to expose their private URL addresses? Aren't you trusting it to them, and if you have a user without internet experience signing up, what happens if he submits his private URL to google and makes it public? Doesn't that create a security hole?
- makecheck 18y agoThere is no such thing as a "private URL" that is hosted on a public web site. You need to augment the URL with something like: - A server-side authentication scheme; so if the URL is visited, it can't trigger anything important without a password. - An expiration mechanism; so that after a certain amount of time, a particular URL has no effect even if it is "visited". - A cookie; so that the URL only works if visitors are people you expect (because they have the right cookie on the client side, and someone like Google would not). Cookies are actually another way to implement expiration, too.
- toni 18y agoOf course it creates a security hole! You are vulnerable to 'reply attacks'. It seems to me that you already know the answer to your question, but are struggling in a last chance to refuse believing the reality. Putting any sensitive information into a url is bound to be exploited sooner or later. Liberally, you can hold the info in urls for the duration of user session but anything beyond that is totally unwise. For the reasons you already mentioned. Other possibilities for unintentional exposing of your personal ulr include: - Users who have google/alexa/amazon/etc. toolbars installed on their browsers, they browse to their personal page, or maybe bookmark it, and alexa/google immediately realize that it is not indexed so they start crawling it. - Other phenomenons like Google Desktop Search crawls and caches all user bookmarks. You should not use http GET method to perform unrelated operations. If you want to offer a delete option to your users, use http POST method. For authentication purposes, i absolutely recommend using HTTPS with POST method.