Skip to:
Content
Pages
Categories
Search
Top
Bottom

Re: !Security Risk! – forum posts are “promiscuous.” Even private posts are not private.

This is similar to an issue I found and have an open ‘Critical’ ticket on.

If you go to your account and then activity > friends you are able to view updates/comments made by a friend who is a member of a hidden group but which you are not, what is worse is that not only can you read content made to a group that you should not be able to read but you can also use the ‘reply’ to add a comment that will then appear in the hidden group.

I’m afraid that for me hidden groups are no such thing and represent a real issue if people use them believing them to be hidden and private in nature.

To date I have had little response on this, the ticket is still open and but for the very kind help of Boone, who helped or rather provided a interim hack to hide the activity altogether, there feels as though there is not a huge deal of concern over an issue of this nature when Andy dropped into the forum thread I raised on the issue it was simply to tick me off for incorrectly referring to hidden groups as ‘private hidden’ – Sorry Andy just thought it may have merited a little more concern than nomenclature issues :-)

Skip to toolbar