Tuesday, April 14, 2009

Facebook “Private” RSS Feeds Probably Don’t Leach Data…

Last year I experimented with private group microblogging systems via authenticated feeds. Didn’t go anywhere, because many of the biggest newsreaders don’t properly support authenticated feeds. And “obscure but public” feeds get indexed by aggregators like Bloglines, by design, making sensitive content much less obscure.

Enter feed access control, a several- (3-?) year-old RSS/ATOM extension that tells Bloglines, and anyone else who is listening, that this feed should be treated as private, even though it’s public.

Facebook’s feeds are intended to support this protocol:


Which seems reasonable enough.

There are a couple of issues though. First, this approach is based on a third-party’s positive action to prevent or “opt-out” of publishing and indexing, in a system that normally defaults to syndication, indexing, etc. So it’s easier for a glitch to expose data.

Second, the whole “fac” extension is a gentlemen’s agreement among parties that couldn’t even agree on making authenticated feeds work well. Perhaps they all make a best effort to isolate the marked content. But tomorrow, a startup with a rocking aggregator could simply ignore “fac” and expose all of the feeds it has.

In some sense, the same vulnerability exists with other systems – if you signed up with some random webmail provider, who’s to say they don’t expose your mail. But because RSS is public by nature, almost all feeds live utterly unprotected, and this extension is one vendor’s hack, it’s not quite the same.

All in all, probably not a big reason for concern. But when people tell me how private things can be on facebook (where you can sneeze and end up revealing your data because the IxD is tilted so heavily toward sharing everything) it always seems worth noting how your data (via your friends’ feed subscriptions) can slowly leach out into the open ocean of the indexed net.


gaohui said...

The holidays are a time ed hardy of getting together with friends ed hardy shoes and family, attending elaborate ed hardy clothing parties, and other exciting events ed hardy clothes that involves dressing up in stunning ed hardy store wardrobes. If you ed hardy Bikini are pregnant during ed hardy swimsuits the holidays, it does not ed hardy Caps mean that you are unable buy ed hardy to look fabulous and ed hardy swimwear stylish. Now, an expectant ed hardy sale mother has many styles of chic ed hardy glasses maternity clothing that allows cheap ed hardy her to show off her baby bump Christian audigier while looking spectacular.

Jack said...

I came across a nice quote while re-reading Randall Gould's great China memoir China in the Sun the other day. Gould was a veteran member of the old China press corps before the war.

cheap wow gold|Tera account|Tera gold|buy eden gold|wow gold

RS Gold said...

I'd personally label your site your dreamland! Though Santa claus hits from all of our home just the once a year, you actually blog is actually open up an entire twelve months


Anonymous said...

the cambridge satchel|satchel cambridge|cambridge satchel|cambridge satchel company|the cambridge satchel company|cambridge satchel bags|cambridge satchel company bag|cambridge leather satchel|women ugg boots on sale

Anonymous said...

Information relating to the CIA terrorist detention program has been placed in a TOP Secret/SCI program to enhance protection ... Cheap Soccer Shirts | Cheap Football Shirts | henry 12 arsenal jersey | messi jersey 10 argentina | fabregas jersey arsenal | david villa barcelona youth jersey | benzema soccer jerseys | cristiano ronaldo real madrid jersey | cheap rooney soccer jerseys | kaka soccer jersey | real madrid shirt | new fc barcelona jersey | argentina jersey 2012 | Brazil jerseys wholesale | cameroon jerseys wholesale | england jerseys sale

Anonymous said...

In some sense, the precise same vulnerability Buy rs gold
exists with other software programs – if you actually signed up with some arbitrary webmail provider, who’s to say they don't expose your mail. But using the performance that RSS is community by nature, Cheapest Diablo 3 goldmore or much less all feeds reside utterly unprotected, and also this extension is simply one vendor’s hack, it is not reasonably the same.

Anonymous said...

You can get delicate doggie games dog leashes or even lush doggy animals and interactive animal games. The first sort is an activity how the pet dog is cast as within the haphazard vogue. You want virtually all izes and shapes can also are available the sort of tennis balls as well as animal-shaped tender educational baby toys. They've been a fantastic way to make your pet dogs occupied. At times dog collar you might need to be present at quite a few significant house chores both at home and want your pet to step away for some time; these particular are undoubtedly occasions when these particular doggie educational baby toys prove useful.dy.

Active canine animals dog collars and leashes are really a means of don't just keeping your pooches pre-occupied but fascinated and then confounded pet supplies wholesale.

Anonymous said...

Way it is noteworthy all around you sunglasses wholesale, additionally, the stylish exploring rarely leave you the only one. Who has a two of awesome fashion accessory drinking glasses, you are the shining an individual who stalls in the center from the fashion world. >

You have eyeglasses frames to land which will people that you're a beautiful an individual who has actually different mastering in regards to the street fashion? We should appear like the far more very popular glasses frames person who has this named flavor involving trendy? In basic terms. The perfect means spectacles is really effective acceptable to help teach all these whizzes.

Seacanoeist Mark said...

I liked your article, I will share your article to everyone!!

WoW gold|Diablo 3 Gold|RS Gold|Cheap Diablo 3 Gold

Robert Welain said...

You should also take a look at this blog guys, there are more articles on this topic.