« Followup on Orkut | Main | Looking at Wiki »

Confirmed Email Privacy Hole at Orkut

Another Orkut user and I have confirmed a privacy hole in Orkut whenever you send a message to someone via Orkut.

For instance, whenever I send a message to anyone in the system that is forwarded by email, in the message headers it will read:

From: "Christopher Allen" <member@orkut.com>
Reply-To: "Christopher Allen" <christophera@alacritymanagement.com>;

When someone reads the message in their email software, the "From:" line will be my name but the fake email of <member@orkut.com> -- however, when you reply to it, it will use my real email address. This appears to happen whether or not I have my privacy settings to reveal my email address. For instance, I can set it so that no one (not friends, not friends of friends, only myself) can see my email address, but the address will still be revealed when I send an email

I had reported what I thought was a security flaw when you emailed to "friends of friends" a couple of days ago, but I was mistaken, as I reported in my blog Insecurity at Orkut. However, as I didn't want risk "crying wolf" this time, so my friend and I triple checked this and have confirmed this privacy flaw.

They only way that I know of to avoid this is in your prefences to set that all of your messages should be sent to you via the web, not email. [Updated: I was wrong, there is no way currently to avoid this other then not using an email address you care about.]

There are some that will say that this is a feature, i.e. when using email "what good is communicating with someone if there is no chance of a response" -- my answer to this is that an expectation has been set that email addresses can remain private, and if this is to be a feature, then users should be warned before sending an email "Your email address user@domain will be revealed when you send this." More ideally, like other social networking services, the "Reply-to:" should be to a special email address at Orkut that will do the lookup and forward appropriately.

One of the essential problems that Orkut needs to fix very soon is how to report problems like these, and if you are trying to help how to know that these problems exist. I want my criticism to be constructive, but it is very hard when you have no idea what is the best way to offer feedback. I've had many people reply to me in my blog and via email that they feel the same way.

For instance, right now there are 6 Orkut groups about Orkut:

Which groups should I post this problem to? Which will will be read by the Orkut staff?

As I've said in another of my blog postings Followup on Orkut:

Part of the problem is that even though Orkut is in beta, there is no organized feedback system. For instance they could offer a forum read by the developers, or even better a bug/issues tracking system like TypePad has, or Bugzilla.

In addition, feedback is a two-way street -- they could do a lot by offering a developers daily blog, or some type of regular announcement of what feature they wanted beta testers to test that day, or even acknowledgement "we already know that is an issue". Also, they need to show respect for good feedback publicly, as that will encourage more good feedback.

None of this is happening at this time, which means that people get frustrated, which also makes it easy rumors and conspiracy to spread. I want to be a constructive critic, but Orkut makes it hard for me to be so.

For now, I recommend that these type of bug reports go into Orkut Beta. Why not in "Flaws in Orkut" or in one of the other groups? Because I feel that focusing on 'Flaws' is too strongly negative, and none of the others quite fit. I've been a software developer -- everything is a compromise and good design is hard. By staying on the topics of current features, feature requests, bugs, suggestions, and by encouraging constructive critism and a balance of both positive and negative feedback, this group will be the best community for us to help Orkut until they offer us better alternatives.

Posted on February 1, 2004 at 05:12 PM in Social Software, Web/Tech | Permalink

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/t/trackback/14990/427814

Listed below are links to weblogs that reference Confirmed Email Privacy Hole at Orkut:

» Is Orkut Disruptive from Unbound Spiral
Hate it or love it it is hard to ignore. Drop out of the blogworld for a week and just start ORKUTTING your newsreader. Newsreaders make it so easy to catch up on posts and difficult to quote or capture... [Read More]

Tracked on Feb 2, 2004 10:53:51 PM

» Confirmed Email Privacy Hole at Orkut from Anders Jacobsen's sideblog
Life With Alacrity: Confirmed Email Privacy Hole at Orkut... [Read More]

Tracked on Feb 3, 2004 4:16:09 AM

» A la sombra from eCuaderno v.2.0
Aclaraba edmz hace unos días que "Orkut no ofrece premio alguno a aquel que logre agregar a más personas a su lista de amigos". Lo cierto es que es más bien lo contario, nos castiga: la polémica Orkut jail ya... [Read More]

Tracked on Feb 18, 2004 8:07:28 AM

» Four Kinds of Privacy from Life With Alacrity
I've been thinking about the nature of privacy a lot lately. (Full post includes discussion of my background relatd to the topic of privacy, and proposes four different kinds of privacy: defensive, human-rights, personal privacy, and contextual privacy.) [Read More]

Tracked on Apr 22, 2004 2:01:28 AM

» Orkut Sucks from readme.blog
In light of the Google IPO, I decided to see how Orkut, a site somehow related to Google, is doing.... First of all, I have no need for a "social network." [Read More]

Tracked on Aug 19, 2004 11:55:49 AM

» Orkut Sucks from readme.blog
In light of the Google IPO, I decided to see how Orkut, a site somehow related to Google, is doing.... First of all, I have no need for a "social network." [Read More]

Tracked on Aug 19, 2004 11:59:40 AM

» Orkut Sucks from readme.blog
In light of the Google IPO, I decided to see how Orkut, a site somehow related to Google, is doing.... First of all, I have no need for a "social network." [Read More]

Tracked on Aug 19, 2004 12:01:06 PM

» Orkut Sucks from readme.blog
In light of the Google IPO, I decided to see how Orkut, a site somehow related to Google, is doing.... First of all, I have no need for a "social network." [Read More]

Tracked on Aug 19, 2004 12:03:15 PM

» Orkut Sucks from readme.blog
In light of the Google IPO, I decided to see how Orkut, a site somehow related to Google, is doing.... First of all, I have no need for a "social network." [Read More]

Tracked on Aug 19, 2004 12:04:47 PM

» Orkut Sucks from readme.blog
In light of the Google IPO, I decided to see how Orkut, a site somehow related to Google, is doing.... First of all, I have no need for a "social network." [Read More]

Tracked on Aug 19, 2004 12:08:32 PM

» Orkut Sucks from readme.blog
In light of the Google IPO, I decided to see how Orkut, a site somehow related to Google, is doing.... First of all, I have no need for a "social network." [Read More]

Tracked on Aug 19, 2004 12:12:45 PM

» Orkut Sucks from readme.blog
In light of the Google IPO, I decided to see how Orkut, a site somehow related to Google, is doing.... First of all, I have no need for a "social network." [Read More]

Tracked on Aug 19, 2004 12:19:51 PM

» Orkut Sucks from readme.blog
In light of the Google IPO, I decided to see how Orkut, a site somehow related to Google, is doing.... First of all, I have no need for a "social network." [Read More]

Tracked on Aug 19, 2004 12:20:23 PM

» Orkut Sucks from readme.blog
In light of the Google IPO, I decided to see how Orkut, a site somehow related to Google, is doing.... First of all, I have no need for a "social network." [Read More]

Tracked on Oct 9, 2004 8:09:57 AM

Comments

In the above I said "They only way that I know of to avoid this is in your prefences to set that all of your messages should be sent to you via the web, not email."

However, this is incorrect, it will still send your email address in the
"Reply-To:"

At this time there is no way I know of to avoid this flaw if you are concerned about your email address other then changing it to a temporary one.

Posted by: Christopher Allen at Feb 1, 2004 9:47:40 PM

That's a pretty big "bug" (or unpublished feature) indeed (!)

For example, personally I try to keep my work email address off the net as much as possible, and have set pretty strict privacy settings on orkut, assuming they'd keep it private...

Coincidentally (!!??) the amount of spam I'm receiving at my work email address has gone up vastly since joining Orkut... A very odd coincidence...

Posted by: Anders at Feb 3, 2004 4:14:32 AM

I discovered why I got 'jailed' for a third time today. Two of us appear to have been jailed because of a bug when posting to groups. What happens is that if you write a long post, rather then the system tell you something is wrong, your posting form will just be refreshed. This will prompt you to submit a few more times, unsuccessfully. Then you realize it must be because your post is too long, so you'll remove text a few times, and submit. At some point in this process, typically before you successfully trim it down enough to successfully post, you will discover you are in Orkut jail.

Of course, that makes us long-winded bloggers particularly vulnerable ;-)

Posted by: Christopher Allen at Feb 3, 2004 7:17:25 AM

my suggestion for forum: orkut design, because orkut the man himself is a member of that community.

Posted by: reader at Feb 4, 2004 5:18:21 PM

beta testing for www.swakto.com social networking is open

Posted by: jemai at Jul 14, 2004 12:40:16 PM

ive been banned on orkut. what is the maximum time you are banned or when they reply to you?

Posted by: sherrzz at Jul 18, 2004 7:06:48 PM

i don't know much more about orkut i just want to know what this side about of side.

Posted by: nawin at Oct 12, 2004 12:51:10 AM

Post a comment