Welcome to the Invelos forums. Please read the forum rules before posting.

Read access to our public forums is open to everyone. To post messages, a free registration is required.

If you have an Invelos account, sign in to post.

    Invelos Forums->DVD Profiler: Desktop Technical Support Page: 1 2  Previous   Next
Privacy Concerns
Author Message
DVD Profiler Unlimited Registrantphelix
Registered: June 10, 2007
Posts: 3
Posted:
PM this userDirect link to this postReply with quote
(ugh this stupid forum has login timeouts set far too short.  This is my second attempt to post)

I have noticed that whenever dvdprofiler downloads the high-quality images for a dvd, it transmits the user's name and registration key in the URL.  Here is an example:

GET www.invelos.com/dvdpro/GetHQImages.aspx?fname=XXXXX&lname=XXXXX&regkey=XXXXX-XXXXX-XXXX-XXXX&file=692865176336.dos HTTP/1.1

(I have X'ed out my name and reg key; they do appear in the clear in the URL)

In addition to the obvious security issues of transmitting such information in the URL unencrypted, this represents a serious breach of the user's privacy.  Since this is transmitted on every request for dvd images, invelos has in effect a list of every user's entire dvd collection, regardless of whether the user has uploaded his list to his online profile or not.  Even if invelos is not currently doing anything with this data, it still exists in their web logs to be analyzed at a later date by them or any future owners of dvdprofiler. 

I think this bears repeating:  Even if a user does not upload his collection to his online profile, invelos still protentially has a list of every dvd the user enters into dvdprofiler (which dvdprofiler downloads a high-quality image for).

Furthermore, any ISP employing a transparent proxy will also have this information in their web logs.  So, third parties can have a record of one's entire dvd collection even without explicitly trying to collect it.  Even more disturbing is that the user's registered name will also be in those logs.

In my limited testing, it appears that turning off the downloading of high-quality images stops the transmission of the user's name and registration key.  I did not notice such behavior with the download of dvd profile data or the master list.


I understand the need to restrict downloading these images to paid members only, but I think that can be accomplished without sacrificing the user's privacy.  While I doubt that many here will consider it a significant issue (since many of you share your profiles anyway), I hope invelos takes this seriously and changes the program to better protect the user's privacy.
 Last edited: by phelix
DVD Profiler Desktop and Mobile RegistrantStar Contributorajm
dvd-aholic
Registered: March 13, 2007
United Kingdom Posts: 525
Posted:
PM this userEmail this userVisit this user's homepageView this user's DVD collectionDirect link to this postReply with quote
It is rather worrying that they are transmitting both user name and reg key unencrypted. That's just not good. Partly I'm sure for Ken as it means some nasty people could quite easily steel other peoples reg keys. So, a totally innocent user could find lots of people using their key.

Personally, I'm less worried about Invelos knowning what dvd's I own. As someone who uploads his collection, they know it all anyway. But as downloading hires images is only something paid users can do, they do need to confirm this info when download them. It's less worrying to me than knowing my local supermarket knows my food choices because I pay by credit/debit card. However, it is something that should be documented.

Home of the phpDVDProfiler forums
DVD Profiler Unlimited RegistrantStar ContributorMithi
Sushi Annihilator
Registered: March 13, 2007
Reputation: Superior Rating
Germany Posts: 2,217
Posted:
PM this userEmail this userVisit this user's homepageView this user's DVD collectionDirect link to this postReply with quote
Quoting phelix:
Quote:
I have noticed that whenever dvdprofiler downloads the high-quality images for a dvd, it transmits the user's name and registration key in the URL.  Here is an example:

GET www.invelos.com/dvdpro/GetHQImages.aspx?fname=XXXXX&lname=XXXXX&regkey=XXXXX-XXXXX-XXXX-XXXX&file=692865176336.dos HTTP/1.1

That is indeed a bit ... unwise ... a registration key shouldn't be submittet via URL, a hashnumber of the reg should suffice. Or a hash of name&reg so the comparison could be made anomynized.
Quote:
Since this is transmitted on every request for dvd images, invelos has in effect a list of every user's entire dvd collection,

To be correct: they could make a list of profiles/covers you queried, they have no way of knowing whether you have them in yout collection or not.

Of course both queries could be anomynized, but simply download 10 random Disney profiles for every porn-movie, so they have to wade through more data.

cya, Mithi
Mithi's little XSLT tinkering - the power of XML --- DVD-Profiler Mini-Wiki
DVD Profiler Unlimited RegistrantStar ContributorLithurge
Paralysis by analysis
Registered: March 13, 2007
Posts: 1,279
Posted:
PM this userView this user's DVD collectionDirect link to this postReply with quote
I never understand why people with empty online collections tick the public  icon in the online collection settings. 
IVS Registered: January 2, 2002
DVD Profiler Unlimited RegistrantVibroCount
The Truth is Silly Putty
Registered: March 13, 2007
Reputation: High Rating
United States Posts: 5,635
Posted:
PM this userEmail this userVisit this user's homepageView this user's DVD collectionDirect link to this postReply with quote
Quoting Lithurge:
Quote:
I never understand why people with empty online collections tick the public  icon in the online collection settings. 


   
If it wasn't for bad taste, I wouldn't have no taste at all.

Cliff
DVD Profiler Unlimited RegistrantStar ContributorWinston Smith
Don't be discommodious
Registered: March 13, 2007
United States Posts: 21,610
Posted:
PM this userEmail this userView this user's DVD collectionDirect link to this postReply with quote
phelix:

As you have discovered there is an easy solution to your problem, simply don't upload your collection. And you better not Contribute anything either somebody might get at you that  way too. While I understand your concerns, the Online paranoia can sometimes go just a bit too far and be quite amusing.

Skip
ASSUME NOTHING!!!!!!
CBE, MBE, MoA and proud of it.
Outta here

Billy Video
DVD Profiler Unlimited RegistrantStar Contributormikl
Mark it zero!
Registered: March 14, 2007
Denmark Posts: 235
Posted:
PM this userVisit this user's homepageView this user's DVD collectionDirect link to this postReply with quote
Quoting skipnet50:
Quote:
the Online paranoia can sometimes go just a bit too far and be quite amusing.

Skip


Since it's so amusing, why not just put your license key in your signature? It's obviously of no concern to you. You can also just post it here to show us that this is of no concern to you. And if you actually read phelix' post you will learn that your license key is transmitted by just downloading cover images into the program as a registered user and it has nothing to do with the online collection.

/Mikkel
DVD Profiler på Dansk
Invelos Software, Inc. RepresentativeKen Cole
Invelos Software
Registered: March 10, 2007
United States Posts: 4,282
Posted:
PM this userEmail this userVisit this user's homepageView this user's DVD collectionDirect link to this postReply with quote
The transmission of registration information is a protection against hacked programs and registration key sharing.  We'll consider moving this to a hash or SSL in a future release.  No user-identifiable information is shared with any third party, as stated in our privacy policy.
Invelos Software, Inc. Representative
DVD Profiler Unlimited RegistrantFloorwalker
Dona Nobis Pacem
Registered: March 16, 2007
Reputation: High Rating
United States Posts: 943
Posted:
PM this userView this user's DVD collectionDirect link to this postReply with quote
Quoting Lithurge:
Quote:
I never understand why people with empty online collections tick the public  icon in the online collection settings. 


Give the guy a break!   Maybe he's just starting!

Just in from somewhere left of the middle of nowhere
The Holy See  
Hell
DVD Profiler Unlimited RegistrantStar ContributorMithi
Sushi Annihilator
Registered: March 13, 2007
Reputation: Superior Rating
Germany Posts: 2,217
Posted:
PM this userEmail this userVisit this user's homepageView this user's DVD collectionDirect link to this postReply with quote
Quoting skipnet50:
Quote:
As you have discovered there is an easy solution to your problem, simply don't upload your collection.

You really should read posting you reply to.

cya, Mithi
Mithi's little XSLT tinkering - the power of XML --- DVD-Profiler Mini-Wiki
Invelos Software, Inc. RepresentativeKen Cole
Invelos Software
Registered: March 10, 2007
United States Posts: 4,282
Posted:
PM this userEmail this userVisit this user's homepageView this user's DVD collectionDirect link to this postReply with quote
This has been switched to a hash for the next release.

For those concerned with plain-text transmissions, be sure to use https://www.invelos.com when signing in as well.
Invelos Software, Inc. Representative
DVD Profiler Unlimited RegistrantStar ContributorKevin
Registered March 22, 2001
Registered: March 13, 2007
Posts: 609
Posted:
PM this userDirect link to this postReply with quote
Now we're going to hash?

Man, I just got off the hard drugs!!!

 
Invelos Software, Inc. RepresentativeKen Cole
Invelos Software
Registered: March 10, 2007
United States Posts: 4,282
Posted:
PM this userEmail this userVisit this user's homepageView this user's DVD collectionDirect link to this postReply with quote
No no no, this kind of hash!
Invelos Software, Inc. Representative
DVD Profiler Unlimited RegistrantStar ContributorMithi
Sushi Annihilator
Registered: March 13, 2007
Reputation: Superior Rating
Germany Posts: 2,217
Posted:
PM this userEmail this userVisit this user's homepageView this user's DVD collectionDirect link to this postReply with quote
Quoting Ken Cole:
Quote:
No no no, this kind of hash!

Isn't cholesterol even worse than THC? 

cya, Mithi
Mithi's little XSLT tinkering - the power of XML --- DVD-Profiler Mini-Wiki
DVD Profiler Unlimited RegistrantStar ContributorWinston Smith
Don't be discommodious
Registered: March 13, 2007
United States Posts: 21,610
Posted:
PM this userEmail this userView this user's DVD collectionDirect link to this postReply with quote
I thought hash was for Thursday night leftovers.        

Skip
ASSUME NOTHING!!!!!!
CBE, MBE, MoA and proud of it.
Outta here

Billy Video
DVD Profiler Unlimited RegistrantStar ContributorKevin
Registered March 22, 2001
Registered: March 13, 2007
Posts: 609
Posted:
PM this userDirect link to this postReply with quote
It's Ken's decision.

We should stop hashing this over.
    Invelos Forums->DVD Profiler: Desktop Technical Support Page: 1 2  Previous   Next