When hi5 was launched, it had a reduced number of members. Over the years, it became more and more popular, so there were many people interested in finding out email addresses of the people which were having profiles on hi5. When you sign up, you have to give hi5 an email address which has to be verified after, address with which you're going to login every time you use hi5. So here started everything.
When you register hi5, you have to agree with some terms of use (which nobody reads). And there, you agree that, even if hi5 will not make your mail address public without your permission, it has no responsibility for any failure of their systems. Somehow, it has been discovered that it is not quite complicated to gain access to the addresses from which users are logging on.
So, if you know someone's hi5 profile, you can paste the link of his/her profile into a website, which will return you the email address of the person whose email you want to find. And this happens without his/her permission. First websites of this type were created long time ago, and they are still working pretty well.
Hi5, which is "the authority" which should have done something in this situation long time ago, didn't move a finder to change something until now. It simply let the privacy of the users to be violated. Over the time, it has been shown that hi5 very vulnerable against many attacks/exploits, so, what's worse, an email address of somebody can be found even if that person has his/her profile private!
An example of a website which can do what I told you is yahoo-invisible.us (this one can find only profiles which were registered with Yahoo! emails). Personally, I don't support this type of websites, but I just wanted to show you how easy is to violate the privacy of millions of users.
Will you be still using hi5 from now? Do you agree to have your privacy violated this easy?
Showing posts with label users. Show all posts
Showing posts with label users. Show all posts
Tuesday, July 27, 2010
Monday, July 26, 2010
BREAKING: Jailbreak & Unlock for the iPhone, now officially legal in the US.
The US Government announced today big changes for all iPhone/iPod/iPad users. Starting from today, Jailbreaking and Unlocking of these devices, along with rooting of Android devices and ripping of DVSs (for educational purposes only) are completely LEGAL into the United States, unless they are violating copyright law.
This is a major hit Apple's face, who, because of its strict policy, didn't let users install unauthorized apps. This decision is a big news for users who were afraid that jailbreaking could bring them into illegality, so, starting from now, they can jailbreak and unlock their iDevices without any fear. However, it is not clear if Apple's policy is still applicable, as they might still refuse to offer support if the device was jailbroken (I'm not sure if this decision puts them into illegality if they continue doing that, we'll most probably get a clarification of this on following period).
You can read more on this subject on Redmond Pie (they've also included the new DMCA legislation).
This is a major hit Apple's face, who, because of its strict policy, didn't let users install unauthorized apps. This decision is a big news for users who were afraid that jailbreaking could bring them into illegality, so, starting from now, they can jailbreak and unlock their iDevices without any fear. However, it is not clear if Apple's policy is still applicable, as they might still refuse to offer support if the device was jailbroken (I'm not sure if this decision puts them into illegality if they continue doing that, we'll most probably get a clarification of this on following period).
You can read more on this subject on Redmond Pie (they've also included the new DMCA legislation).
Friday, July 23, 2010
Samsung sends free Galaxy S devices to unsatisfied iPhone 4 users (UK users only).
It seems that Samsung offered free Galaxy S devices to users who declared themselves unsatisfied by Apple's iPhone 4. The only thing that these users from the UK to which Samsung sent these devices did, was to complain on Twitter about the iPhone 4, so that Samsung contacted them offering free Galaxy S devices.
It seems that this is a tactical move made by Samsung, which tries to make a little advertising to its devices in order to increase its market-share. Of course that these devices were sent to people who are really influential, so if you are a normal Twitter user, don't even mind trying to receive a free Galaxy S. You can try if you really want, but there is almost no chance of getting one. And don't forget, devices are being sent only to important people from the UK.
It seems that this is a tactical move made by Samsung, which tries to make a little advertising to its devices in order to increase its market-share. Of course that these devices were sent to people who are really influential, so if you are a normal Twitter user, don't even mind trying to receive a free Galaxy S. You can try if you really want, but there is almost no chance of getting one. And don't forget, devices are being sent only to important people from the UK.
Monday, June 28, 2010
Google removed remotely two applications from some Android devices. And what?
A few days ago, an announcement came officially from Google who said that they removed two applications from the Android Market. The cause was that those two apps were simply not doing what they were intended to do. They were made by a security researcher, and even if they weren't developing any malicious activities or saving sensible data, because they violated Android's Terms of Service, Google decided to remove them. Till now, everything is OK.
But, what created notable flames on the blogs/forums/social networks was the information that Google, in order to remove completely that applications, also removed them (remotely) from the phones of some users who downloaded them. Personally, I don't see what is the problem in this, and why some people became...upset because of this. I think this reaction of Google was something normal.
Google affirmed that the two applications could be used in attacks, so, considering this, I really don't see any problem in Google's action. Are they afraid that if Google can do this, Google can even get access to their private data? So what, do they think that other OS providers didn't implement mechanisms like Google did? I'm sure that they also did. But at least, in Google's situation, it is very good that this is something transparent. Very good, Google!
But, what created notable flames on the blogs/forums/social networks was the information that Google, in order to remove completely that applications, also removed them (remotely) from the phones of some users who downloaded them. Personally, I don't see what is the problem in this, and why some people became...upset because of this. I think this reaction of Google was something normal.
Google affirmed that the two applications could be used in attacks, so, considering this, I really don't see any problem in Google's action. Are they afraid that if Google can do this, Google can even get access to their private data? So what, do they think that other OS providers didn't implement mechanisms like Google did? I'm sure that they also did. But at least, in Google's situation, it is very good that this is something transparent. Very good, Google!
Subscribe to:
Posts (Atom)