4 ms·
Nope you're not missing anything. The longer you wait to use the URL, the less secure it is. I could just generate a bunch of random URLs and wget them until
by ToastyMallows 12y ago
Nope you're not missing anything. The longer you wait to use the URL, the less secure it is. I could just generate a bunch of random URLs and wget them until I get something.
- bobwaycott 12y ago> The longer you wait to use the URL, the less secure it is. Potentially true if you've chosen to upload with the 'one download' expiry time set, and then whomever you've shared the link with does not use it within 30 days (at which point it is expired & deleted). With the 'two days' option, the link does not become less secure than it was at generation because it (and the content) is deleted forever after 48 hours.
- dbpatterson 12y agoTake a look at the urls and do some calculation on how likely you are to actually get anything. It looks like 14 characters, alphanumeric with uppercase, which is about 10^25. Even if you can try a thousand urls per second, that would take you about 10^16 days to go through them all (that's a long time). Or, if you want to calculate probabilities, assume that a billion urls are used (this is an astronomic overestimate). That's 10^9 urls. The chance of hitting one of those with a random guess is 0.00000000000014% (if I counted the 0s right). Not very likely. Now if the url is observed in transit - that's a completely different thing. Just don't think that random guessing is going to reveal this. It's similar to people thinking you can guess your way to product keys for software (hint: you can't).