{"id":161840,"date":"2016-04-15T11:37:04","date_gmt":"2016-04-15T09:37:04","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=161840"},"modified":"2016-04-15T11:38:11","modified_gmt":"2016-04-15T09:38:11","slug":"url-shorteners-expose-your-private-data","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/161840-url-shorteners-expose-your-private-data.html","title":{"rendered":"URL shorteners expose your private data"},"content":{"rendered":"<p>Cornell Tech researchers have published a paper warning that URL shorteners cause potential privacy problems in cloud services.<\/p>\n<p>Titled <strong><a href=\"http:\/\/arxiv.org\/pdf\/1604.02734v1.pdf\" target=\"_blank\">Gone in Six Characters: Short URLs Considered Harmful for Cloud Services<\/a><\/strong>, the paper said that for many services it was easy to search through all possible combinations of URL mappings.<\/p>\n<p>Until September 2015, Google used\u00a0five characters in its URL shortener.<\/p>\n<p>The researchers were able to search through all of the short links generated by Google Maps, discovering people&#8217;s private addresses and other sensitive information, <strong><a href=\"https:\/\/boingboing.net\/2016\/04\/13\/url-shorteners-are-a-short-pat.html\">Boing Boing reported<\/a><\/strong>.<\/p>\n<p>Google has since increased the token size of its Maps URLs to 11 or 12 characters.<\/p>\n<p>Microsoft\u2019s One Drive was similarly easy to search, and in 7% of cases One Drive accounts exposed in this way let anyone write into them.<\/p>\n<p>This could let an attacker copy files\u00a0onto your\u00a0system.<\/p>\n<p><strong><a href=\"http:\/\/arstechnica.com\/security\/2016\/04\/guess-what-url-shorteners-short-circuit-cloud-security\/\" target=\"_blank\">Ars Technica reported<\/a><\/strong> that the researchers also looked through 100 million addresses on bit.ly\u2019s domain space, using 189 machines to access the bit.ly service\u2019s search API.<\/p>\n<p>Of the six-character tokens they searched, 42\u00a0million\u00a0resolved to URLs. Of these, 19,524 lead to OneDrive files and folders, most of them live, the researchers said.<\/p>\n<p>Searching through seven-character tokens resulted in a 29% hit rate, with 47,081 OneDrive and SkyDrive URLs &#8211; of which 35,541 were live.<\/p>\n<p>According to the researchers, Microsoft has stopped offering bit.ly URL shortening directly in OneDrive, but the company\u00a0did not\u00a0acknowledge short URLs as a security hole.<\/p>\n<h3 id=\"related\">More security news<\/h3>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/cellular\/161396-beware-of-new-whatsapp-vodacom-call-sponsor-scam.html\"><strong>Beware of new WhatsApp Vodacom Call Sponsor scam<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/161498-apply-online-for-a-gauteng-school-spot-at-your-own-risk.html\"><strong>Apply online for a Gauteng school spot at your own risk<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/161020-how-safe-your-smartphone-lock-screen-is.html\"><strong>How safe your smartphone lock screen is<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/160824-how-whatsapp-keeps-your-messages-secret.html\"><strong>How WhatsApp keeps your messages secret<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new research paper warns that the URL shortening systems built into various cloud services expose the private data of users.<\/p>\n","protected":false},"author":23,"featured_media":161842,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[36,36628,167,14757,123],"class_list":["post-161840","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-active","tag-bit-ly","tag-google","tag-google-url-shortner","tag-microsoft"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/161840"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=161840"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/161840\/revisions"}],"predecessor-version":[{"id":161854,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/161840\/revisions\/161854"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/161842"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=161840"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=161840"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=161840"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}