3 ms·
It will include many URLs that are semi-private, like Google Docs that are shared via link.
by DominikPeters 1y ago
It will include many URLs that are semi-private, like Google Docs that are shared via link.
- high_na_euv 1y agoSo exclude them
- ceejayoz 1y agoHow? How will they know a short link to a random PDF on S3 is potentially sensitive info?
- high_na_euv 1y agoI meant Google docs of which they know share settings
- ryandrake 1y agoIf some URL is accessible via the open web, without authentication, then it is not really private.
- bo1024 1y agoWhat do you mean by accessible without authentication? My server will serve example.com/64-byte-random-code if you request it, but if you don’t know the code, I won’t serve it.
- deleted 1y ago[deleted]
- prophesi 1y agoObfuscation may hint that it's intended to be private, but it's certainly not authentication. And the keyspace for these goog.le short URL's are much smaller than a 64byte alphanumeric code.
- hombre_fatal 1y agoSure, but you have to make executive decisions on the behalf of people who aren't experts. Making bad actors brute force the key space to find unlisted URLs could be a better scenario for most people. People also upload unlisted Youtube videos and cloud docs so that they can easily share them with family. It doesn't mean you might as well share content that they thought was private.
- bo1024 1y agoI'm not seeing why there's a clear line where GET cannot be authentication but POST can.
- prophesi 1y agoBecause there isn't a line? You can require auth for any of those HTTP methods. Or not require auth for any of them.
- deleted 1y ago[deleted]
- wobfan 1y agoI mean, going by that argument a username + password is also just obfuscation. Generating a unique 64 byte code is even more secure than this, IF it's handled correctly.
- charcircuit 1y agoThen use something like argon2 on the keys, so you have to spend a long time to brute force them all similar to how it is today.
- chneu 1y agoThat's not any better than what archiveteam is doing. They're brute forcing the URLs to capture all of them. So privacy won't really matter here.