Author |
Message |
Registered: June 10, 2007 | Posts: 3 |
| Posted: | | | | (ugh this stupid forum has login timeouts set far too short. This is my second attempt to post)
I have noticed that whenever dvdprofiler downloads the high-quality images for a dvd, it transmits the user's name and registration key in the URL. Here is an example:
GET www.invelos.com/dvdpro/GetHQImages.aspx?fname=XXXXX&lname=XXXXX®key=XXXXX-XXXXX-XXXX-XXXX&file=692865176336.dos HTTP/1.1
(I have X'ed out my name and reg key; they do appear in the clear in the URL)
In addition to the obvious security issues of transmitting such information in the URL unencrypted, this represents a serious breach of the user's privacy. Since this is transmitted on every request for dvd images, invelos has in effect a list of every user's entire dvd collection, regardless of whether the user has uploaded his list to his online profile or not. Even if invelos is not currently doing anything with this data, it still exists in their web logs to be analyzed at a later date by them or any future owners of dvdprofiler.
I think this bears repeating: Even if a user does not upload his collection to his online profile, invelos still protentially has a list of every dvd the user enters into dvdprofiler (which dvdprofiler downloads a high-quality image for).
Furthermore, any ISP employing a transparent proxy will also have this information in their web logs. So, third parties can have a record of one's entire dvd collection even without explicitly trying to collect it. Even more disturbing is that the user's registered name will also be in those logs.
In my limited testing, it appears that turning off the downloading of high-quality images stops the transmission of the user's name and registration key. I did not notice such behavior with the download of dvd profile data or the master list.
I understand the need to restrict downloading these images to paid members only, but I think that can be accomplished without sacrificing the user's privacy. While I doubt that many here will consider it a significant issue (since many of you share your profiles anyway), I hope invelos takes this seriously and changes the program to better protect the user's privacy. | | | Last edited: by phelix |
|
Registered: March 13, 2007 | Posts: 525 |
| Posted: | | | | It is rather worrying that they are transmitting both user name and reg key unencrypted. That's just not good. Partly I'm sure for Ken as it means some nasty people could quite easily steel other peoples reg keys. So, a totally innocent user could find lots of people using their key.
Personally, I'm less worried about Invelos knowning what dvd's I own. As someone who uploads his collection, they know it all anyway. But as downloading hires images is only something paid users can do, they do need to confirm this info when download them. It's less worrying to me than knowing my local supermarket knows my food choices because I pay by credit/debit card. However, it is something that should be documented. | | | Home of the phpDVDProfiler forums |
|
Registered: March 13, 2007 | Reputation: | Posts: 2,217 |
| Posted: | | | | Quoting phelix: Quote: I have noticed that whenever dvdprofiler downloads the high-quality images for a dvd, it transmits the user's name and registration key in the URL. Here is an example:
GET www.invelos.com/dvdpro/GetHQImages.aspx?fname=XXXXX&lname=XXXXX®key=XXXXX-XXXXX-XXXX-XXXX&file=692865176336.dos HTTP/1.1 That is indeed a bit ... unwise ... a registration key shouldn't be submittet via URL, a hashnumber of the reg should suffice. Or a hash of name® so the comparison could be made anomynized. Quote: Since this is transmitted on every request for dvd images, invelos has in effect a list of every user's entire dvd collection, To be correct: they could make a list of profiles/covers you queried, they have no way of knowing whether you have them in yout collection or not. Of course both queries could be anomynized, but simply download 10 random Disney profiles for every porn-movie, so they have to wade through more data. cya, Mithi | | | Mithi's little XSLT tinkering - the power of XML --- DVD-Profiler Mini-Wiki |
|
Registered: March 13, 2007 | Posts: 1,279 |
| Posted: | | | | I never understand why people with empty online collections tick the public icon in the online collection settings. | | | IVS Registered: January 2, 2002 |
|
Registered: March 13, 2007 | Reputation: | Posts: 5,635 |
| Posted: | | | | | | | If it wasn't for bad taste, I wouldn't have no taste at all.
Cliff |
|
Registered: March 13, 2007 | Posts: 21,610 |
| Posted: | | | | phelix: As you have discovered there is an easy solution to your problem, simply don't upload your collection. And you better not Contribute anything either somebody might get at you that way too. While I understand your concerns, the Online paranoia can sometimes go just a bit too far and be quite amusing. Skip | | | ASSUME NOTHING!!!!!! CBE, MBE, MoA and proud of it. Outta here
Billy Video |
|
Registered: March 14, 2007 | Posts: 235 |
| Posted: | | | | Quoting skipnet50: Quote: the Online paranoia can sometimes go just a bit too far and be quite amusing.
Skip Since it's so amusing, why not just put your license key in your signature? It's obviously of no concern to you. You can also just post it here to show us that this is of no concern to you. And if you actually read phelix' post you will learn that your license key is transmitted by just downloading cover images into the program as a registered user and it has nothing to do with the online collection. /Mikkel | | | DVD Profiler på Dansk |
|
Registered: March 10, 2007 | Posts: 4,282 |
| Posted: | | | | The transmission of registration information is a protection against hacked programs and registration key sharing. We'll consider moving this to a hash or SSL in a future release. No user-identifiable information is shared with any third party, as stated in our privacy policy. | | | Invelos Software, Inc. Representative |
|
Registered: March 16, 2007 | Reputation: | Posts: 943 |
| Posted: | | | | Quoting Lithurge: Quote: I never understand why people with empty online collections tick the public icon in the online collection settings. Give the guy a break! Maybe he's just starting! | | | Just in from somewhere left of the middle of nowhere The Holy See Hell |
|
Registered: March 13, 2007 | Reputation: | Posts: 2,217 |
| Posted: | | | | Quoting skipnet50: Quote: As you have discovered there is an easy solution to your problem, simply don't upload your collection. You really should read posting you reply to. cya, Mithi | | | Mithi's little XSLT tinkering - the power of XML --- DVD-Profiler Mini-Wiki |
|
Registered: March 10, 2007 | Posts: 4,282 |
| Posted: | | | | This has been switched to a hash for the next release.
For those concerned with plain-text transmissions, be sure to use https://www.invelos.com when signing in as well. | | | Invelos Software, Inc. Representative |
|
| Kevin | Registered March 22, 2001 |
Registered: March 13, 2007 | Posts: 609 |
| Posted: | | | | Now we're going to hash? Man, I just got off the hard drugs!!! |
|
Registered: March 10, 2007 | Posts: 4,282 |
| Posted: | | | | No no no, this kind of hash! | | | Invelos Software, Inc. Representative |
|
Registered: March 13, 2007 | Reputation: | Posts: 2,217 |
| |
Registered: March 13, 2007 | Posts: 21,610 |
| Posted: | | | | | | | ASSUME NOTHING!!!!!! CBE, MBE, MoA and proud of it. Outta here
Billy Video |
|
| Kevin | Registered March 22, 2001 |
Registered: March 13, 2007 | Posts: 609 |
| Posted: | | | | It's Ken's decision.
We should stop hashing this over. |
|