4 ms·
How many major social media sites try to prevent this behavior? Facebook links expire[1]; but Reddit, Tumblr, and Twitter all generate seemingly permanent image
by kr0bat 3y ago
How many major social media sites try to prevent this behavior? Facebook links expire[1]; but Reddit, Tumblr, and Twitter all generate seemingly permanent image links.
Also semi-related fun fact, I think most sites lack authorization checks when accessing images via direct urls. A logged out user can follow direct image links from private accounts/servers/subs on all these sites, including Discord. Not like that means much of anything security wise (if you have the url you likely had access to the image)
https://stackoverflow.com/questions/30477877/facebook-image-url-gets-expired https://stackoverflow.com/questions/30477877/facebook-image-...
- codetrotter 3y ago> Tumblr […] generate seemingly permanent image links They did, and people hosted a bunch of things there, and then they changed the ToS to not allow NSFW stuff. What happened to all of the NSFW images people hosted on Tumblr? I assume they were all deleted with the ToS change.
- pndy 3y agoMajority was hidden for non-logged in users (nowadays seems they provide a blurred curtain), some were deleted with either copyright or content rules violations as reasoning
- hunter2_ 3y ago> A logged out user can follow direct image links from private accounts/servers/subs on all these sites, including Discord. Not like that means much of anything security wise (if you have the url you likely had access to the image) This is a concept I think about often. Tons of services use unguessable URLs for access control. A long time ago, I would've called it "security by obscurity" but it's become so normalized that I've come to mostly agree that it's sufficient because users who give out the URL can generally perceive it as equivalent to giving out any other secret (such as a password). But on the other hand, using other HTTP headers instead of the URL (authorization headers, cookie headers, etc.) do have a rather major benefit: not typically being stored in logs as cleartext, which cannot generally be said for URLs. So if you run a service that uses URLs as secrets, and you don't keep those URLs in your logs, then it's pretty decent security, I think. Although if your logs fall into the hands of a bad actor, then the actual data probably did as well, so it's kind of moot.
- Scaless 3y agoAs of a few months ago, Reddit no longer allows linking directly linking to their hosted images. You are directed to a pseudo-page that links back to original thread it was posted in. This sucks because it's now not possible to use the browser's built-in image viewer which has better UX. I am expecting them to eventually put ads on the page as well. Random example: https://i.redd.it/144knacbw3rb1.jpg https://i.redd.it/144knacbw3rb1.jpg
- qingcharles 3y agoYeah, that behavior killed me. Solutions are here: https://www.reddit.com/r/uBlockOrigin/comments/14ks1tm/reddit_ireddit_webp_hijack_of_direct_image_link/ https://www.reddit.com/r/uBlockOrigin/comments/14ks1tm/reddi...
- pndy 3y agoYou may want to check this: https://addons.mozilla.org/en-US/firefox/addon/load-reddit-images-directly/ https://addons.mozilla.org/en-US/firefox/addon/load-reddit-i...
- UndyingHorse 3y agoTelegram Web loads images over websocket and shows them as blobs. This way it prevents users from copying url and not knowing that it will stop working after 24h.