top | item 44684152

(no title)

DominikPeters | 7 months ago

It will include many URLs that are semi-private, like Google Docs that are shared via link.

discuss

order

ryandrake|7 months ago

If some URL is accessible via the open web, without authentication, then it is not really private.

bo1024|7 months ago

What do you mean by accessible without authentication? My server will serve example.com/64-byte-random-code if you request it, but if you don’t know the code, I won’t serve it.

chneu|7 months ago

That's not any better than what archiveteam is doing. They're brute forcing the URLs to capture all of them. So privacy won't really matter here.

charcircuit|7 months ago

Then use something like argon2 on the keys, so you have to spend a long time to brute force them all similar to how it is today.

high_na_euv|7 months ago

So exclude them

ceejayoz|7 months ago

How?

How will they know a short link to a random PDF on S3 is potentially sensitive info?