7 ms·
From 0 to Skype in 9 Months
- coldcode 13y agoPhono seems to support any browser, why does this only support Chrome and Firefox?
- cmatthieu 13y agoOnly Chrome and FireFox support WebRTC video. We are working on adding Phono voice support for Safari, IE, and Opera using Phono's Flash and Java Applet capabilities.
- ryanseys 13y agoTheir voicemails seem to be public... Just pick a key from https://twelephone-voicemail.s3.amazonaws.com https://twelephone-voicemail.s3.amazonaws.com and voila! https://twelephone-voicemail.s3.amazonaws.com/1rajmadugulaedwardallison12013-04-23T17:06:49Z.wav https://twelephone-voicemail.s3.amazonaws.com/1rajmadugulaed...
- cmatthieu 13y agoYou would need to know the exact millisecond of the timestamp and usernames to access it. Our plans are to allow sharing of video/voice messages publicly if the user chooses. Feedback welcome...
- ryanseys 13y agoI think this is unacceptable because this is easily brute-forceable, especially when you (by default) tweet the other user that a voicemail has been left. https://twitter.com/ryanseys/status/355009243306405890 https://twitter.com/ryanseys/status/355009243306405890 EDIT: Also, the timestamp is per-second (1rajmadugulaedwardallison12013-04-23T17:06:49Z.wav) not per millisecond, making bruteforce a rather elementary task when combined with twitter tweet information.
- cmatthieu 13y agoGood point. Salting the key should make this better.
- ryanseys 13y agoAnd restrict access to this page (which lists all the keys, salted or otherwise)... https://twelephone-voicemail.s3.amazonaws.com/ https://twelephone-voicemail.s3.amazonaws.com/
- pathy 13y agoOh my, why isn't this page restricted? That is a very serious flaw in the system. Not exactly caring about the users' privacy, or security.
- cmatthieu 13y agoWe haven't yet officially released voice messaging but the feature stuck into this release. We'll correct the access on our next update (prior to it being announced). Thanks everyone.
- aw3c2 13y agoThis is a issue where you pull the plug right now, fix the issue and tell your users about. Otherwise your company just dug its own grave publicity-wise. Privacy is the foremost important issue if you handle people's communication.
- jabbernotty 13y agoAs ryanseys points out, a timestamp and username doesn't provide any kind of security. Since this uses Twitter, a good move may be to use Twitter's API to check if the correct user has been logged in (I don't know the Twitter API). Would using direct messages work?
- aw3c2 13y agoWhat do you mean? I just picked random Key values from that and could download those files with no problem. This is a crazy privacy issue!
- swinglock 13y agoIt's totally understandable to make a mistake like this and it's early, but it's scary how you think that's an acceptable solution.
- untog 13y agoTo be clear, I just went to that first URL, copy and pasted the key to the end of the URL, and I listened to you leaving a message saying "This is a test. 1,2,3". I did not need to know anything else. This is not good.
- methehack 13y agoWouldn't it be better to share this directly with the service provider instead of exposing users' data like this? Also kinder?
- deleted 13y ago[deleted]
- pbhjpbhj 13y agoI'm interested in the Twitter permissions required. * Read Tweets from your timeline. * See who you follow, and follow new people. * Update your profile. * Post Tweets for you. Does Twelephone only require posting tweets and following new people for completing positive actions by the user or is this like FB apps that spam your feed? Could those permissions be added as needed; I'm assuming that you don't need to follow new users or tweet anything for me to direct connect a Twelephone session with a current friend?? It seems incongruous you tout privacy features as a bonus (http://twelephone.com/#learnmore http://twelephone.com/#learnmore) but that to use the service Twelephone gets access to everything one does on twitter. Perhaps these are just standard permissions that twitter hands out with user authorisation?
- cmatthieu 13y agoI believe that these are standard Twitter permissions. Twelephone only needs tweet permissions. We're not using any other Twitter APIs (other than OAuth).
- tinfoilhat 13y agohow exactly WebRTC going to solve raised questions regarding privacy ? in light of a fact that, for ICE to operate, you need STUN server and exchange ICE candidates (and SRTP keys) through WebRTC server