Presumably it means that anyone you show a photo to intentionally can in turn show it to people you don't intend to see the photo. Which, of course, must be true, no matter what Facebook does to protect photos.
Yes, but in addition they also assume that:
- That the only way you know the photo ID is by having access to the photo.
- If you had access to the photo at some point, you have access to it forever (even if it is revoked later on).
It may be industry wide practice as you have noted but the bottom line is that the privacy settings are not explicitly checked on every photo access. Makes you wonder where else they are using similar logic.
Not to lighten the issue, I think this is a security flaw, but the same is true if they simply save it to their computer. You have to trust your audience to begin with or you're hosed. There's no real way of stopping them from copying or disseminating content.
The authorization happens at the time you request the photo url, not the photo itself. So the security is on finding out what the url is, not the actual photo request. It'd be the same as someone being able to login if they know your password. That URL is the password.
Comments
Facebook allows very sophisticated privacy settings, including allowing access to photos for a specific subset of users only.
I wonder what those privacy settings mean then, if the authorization checks are not happenning when the photo is accessed?
Presumably it means that anyone you show a photo to intentionally can in turn show it to people you don't intend to see the photo. Which, of course, must be true, no matter what Facebook does to protect photos.
Yes, but in addition they also assume that: - That the only way you know the photo ID is by having access to the photo. - If you had access to the photo at some point, you have access to it forever (even if it is revoked later on).
It may be industry wide practice as you have noted but the bottom line is that the privacy settings are not explicitly checked on every photo access. Makes you wonder where else they are using similar logic.
Not to lighten the issue, I think this is a security flaw, but the same is true if they simply save it to their computer. You have to trust your audience to begin with or you're hosed. There's no real way of stopping them from copying or disseminating content.
The authorization happens at the time you request the photo url, not the photo itself. So the security is on finding out what the url is, not the actual photo request. It'd be the same as someone being able to login if they know your password. That URL is the password.