<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/rss-style.xsl" type="text/xsl"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	    xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	     xmlns:dc="http://purl.org/dc/elements/1.1/"
	   xmlns:atom="http://www.w3.org/2005/Atom"
	     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	  xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>
<channel>
	<title>path &#8211; Terence Eden’s Blog</title>
	<atom:link href="https://shkspr.mobi/blog/tag/path/feed/" rel="self" type="application/rss+xml" />
	<link>https://shkspr.mobi/blog</link>
	<description>Regular nonsense about tech and its effects 🙃</description>
	<lastBuildDate>Mon, 16 Jan 2012 11:19:43 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://shkspr.mobi/blog/wp-content/uploads/2023/07/cropped-avatar-32x32.jpeg</url>
	<title>path &#8211; Terence Eden’s Blog</title>
	<link>https://shkspr.mobi/blog</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title><![CDATA[Path - Privacy & Security Problems]]></title>
		<link>https://shkspr.mobi/blog/2012/01/path-privacy-security-problems/</link>
					<comments>https://shkspr.mobi/blog/2012/01/path-privacy-security-problems/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Mon, 16 Jan 2012 11:19:43 +0000</pubDate>
				<category><![CDATA[mobile]]></category>
		<category><![CDATA[http]]></category>
		<category><![CDATA[https]]></category>
		<category><![CDATA[path]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[ssl]]></category>
		<guid isPermaLink="false">http://shkspr.mobi/blog/?p=5261</guid>

					<description><![CDATA[I&#039;m trying out the new Android app for Path - the new social networking service.  I&#039;ve discovered something rather troubling...  Most of the app&#039;s communication with the Path servers is over SSL.  This means that no-one can see the data you&#039;re sending and receiving.  If there are snoops on your network, they will only be able to see the encrypted data flowing back and forth.  In general, this is…]]></description>
										<content:encoded><![CDATA[<p>I'm trying out the new Android app for Path - the new social networking service.  I've discovered something rather troubling...</p>

<p>Most of the app's communication with the Path servers is over SSL.  This means that no-one can see the data you're sending and receiving.  If there are snoops on your network, they will only be able to see the encrypted data flowing back and forth.  In general, this is a good thing.</p>

<p>Apart from images.  If your friends are posting images, they are sent over http.  <strong>No security</strong>.  Anyone monitoring your network connection will be able to see all the images you're viewing.</p>

<p>Now, that's bad enough - but it turns out that all the images you <em>send</em> are visible to the the world even if you've set your post to private.</p>

<p>The images are sent over SSL, but as soon as you return to your "Path", a thumbnail is shown of what you've just posted!</p>

<p>Here's a picture of the logs, so you can see what's happening.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2012/01/path-ssl.png" alt="path ssl" title="path ssl" width="600" height="339" class="aligncenter size-full wp-image-5262">

<p>So, every image you post or see - including the avatars of your friends - are visible to all.  A rather serious security and privacy problem.</p>

<p>Oh, does anyone know what the unencrypted call to "sendgrid.net" is all about?</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=5261&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2012/01/path-privacy-security-problems/feed/</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
			</item>
	</channel>
</rss>
