Need help sorting out how to use 23? Or have you discovered one of those nasty bugs?

Private photos are NOT so private

minkus   October 10, 2009, 09:14 PM

The way things are set at 23hq is to assign an address to each photo right? If I upload multiple photos, the addresses will be in numerical order.

Now, I linked one of my private photos in a discussion forum because I wanted to share it with the forum only and not the rest of the world. The photo is visible in the forum, even though it is set to private. That isnt my concern. My concern is posting it in a forum will also display the address for that picture. By changing the "last" digit of the address, they may be able to see my other private pictures.

I uploaded these pictures for use in the example below

Example: I link this photo onto a website or a discussion forum

http://www.23hq.com/minkus/photo/5006967

Although it is private, the people in the forum can view it.

But when I uploaded this picture along with other pictures that I want to be private, 23hq assigns it in numerical order. So if someone wanted to, they could change the address to 5006966 or 5006968 and they can see those private photos which I didnt want them to see.

Maybe 23hq can use a Random Number Generator when it assigns addresses to the photos.

 
Steffen Tiedemann Christensen Team 23   October 10, 2009, 10:35 PM

Hey minkus,

I think you're misunderstanding the way private photos work on 23; for example, here are links to two of my photos:
http://www.23hq.com/steffen/photo/4946038 (private)
http://www.23hq.com/steffen/photo/4946039 (public)

When visiting the private photo you'll be asked to log in if you're not already; and otherwise you'll see a message telling you that you don't have permissions to see the photo. The point is that simply having the ID of the photo won't give you access to see it. (Try logging out of 23 and browse to one of your own private photos using only the assigned number.)

Now, if I actually wanted to link to the mentioned private photo (#4946038) in a forum, I could link to the photo along with its randomized token: http://www.23hq.com/23666/4946038_a6cb8948ba379659921521d3abe764b1_mblog.jpg. This URL will actually give you access to the photo even if you're not logged in. (This URL, btw, is available through the More sizes for sharing option.)

I hope this clears up how private photos work.

 
minkus   October 10, 2009, 10:54 PM

Sorry Steffen...you are right.

When I was testing it, I must have still been logged in.

 
To participate in this conversation, you'll need to join the group




About 23

About 23
What is 23 and who's behind the service?
Just In
Discover the world from a different angle.
Here's a crop of the latest photos from the around the world.
Search
Search photos from users using 23
Help / Discussion
Get help or share your ideas to make 23 better
23 Blog / 23 on Twitter
Messages and observations from Team 23
Terms of use
What can 23 be used for and what isn't allowed
More services from 23
We also help people use photo sharing in their professional lives
RSS Feed
Subscribe to these photos in an RSS reader
  • Basque (ES)
  • Bulgarian (BG)
  • Chinese (CN)
  • Chinese (TW)
  • Danish (DK)
  • Dutch (NL)
  • English (US)
  • French (FR)
  • Galician (ES)
  • German (DE)
  • Italian (IT)
  • Norwegian (NO)
  • Polish (PL)
  • Portuguese (PT)
  • Russian (RU)
  • Spanish (ES)
  • Swedish (SE)

Popular photos right now

See also