<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CFP 2009 Blog &#187; security</title>
	<atom:link href="http://www.cfp2009.org/wordpress/?feed=rss2&#038;tag=security" rel="self" type="application/rss+xml" />
	<link>http://www.cfp2009.org/wordpress</link>
	<description>Computers Freedom and Privacy Conference 2009, Creating the Future</description>
	<lastBuildDate>Fri, 19 Jun 2009 22:15:18 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Privacy alert: Twitter disclosed email addresses when people sent DMs (UPDATED)</title>
		<link>http://www.cfp2009.org/wordpress/?p=242</link>
		<comments>http://www.cfp2009.org/wordpress/?p=242#comments</comments>
		<pubDate>Fri, 19 Jun 2009 17:15:43 +0000</pubDate>
		<dc:creator>JonPincus</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[alert]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://www.cfp2009.org/wordpress/?p=242</guid>
		<description><![CDATA[UPDATE, 3 p.m. Pacific time: Twitter appears to have fixed the bug, and DMs from before June 11 do not appear to be affected.  But anybody you sent a DM to between June 11 and June 18 now has the email address you&#8217;re using on your Twitter account.
FYI &#8211; when you send a DM, the [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #ff0000;">UPDATE, 3 p.m. Pacific time: Twitter appears to have fixed the bug, and DMs from before June 11 do not appear to be affected.  But anybody you sent a DM to between June 11 and June 18 now has the email address you&#8217;re using on your Twitter account.</span></p>
<blockquote><p>FYI &#8211; when you send a DM, the receiver CAN SEE YOUR EMAIL ADDRESS from the DM sent via email. BE AWARE!!! @twitter #security #fail</p></blockquote>
<blockquote><p>&#8211; ChicagoBungalow about 18 hours ago <a href="http://twitter.com/ChicagoBungalow/status/2229669091">on Twitter</a></p></blockquote>
<p>For those who aren&#8217;t on Twitter, a DM is a &#8220;direct message&#8221;, twitterspeak for a private message between two people.  When you receive a DM, Twitter notifies you via email.  And sure enough, just as ChicagoBungalow said, if I send you a DM, if you look at the email header information, you&#8217;ll see that the &#8220;Sender&#8221; field has an address like</p>
<blockquote><p>twitter-dm-jon_pincus=yahoo.com@postmaster.twitter.com</p></blockquote>
<p>This field is hidden by default &#8212; in gmail, you need to select &#8220;Show original&#8221; to see it &#8212; but once you find it, it doesn&#8217;t take a rocket scientist to figure out what yahoo.com account name I used to sign up on Twitter.</p>
<p>If I want somebody to have my email address, I&#8217;ll send it to them.  I don&#8217;t want Twitter giving it out for me. And most especially, I don&#8217;t want Twitter doing it behind my back.</p>
<p>jon</p>
<p>PS: I updated this post several times to clarify the description; thanks to all for the feedback, and @NiteStar for the gmail instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cfp2009.org/wordpress/?feed=rss2&amp;p=242</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
		<item>
		<title>Day Two, Recap Part 2 (via 4hours)</title>
		<link>http://www.cfp2009.org/wordpress/?p=186</link>
		<comments>http://www.cfp2009.org/wordpress/?p=186#comments</comments>
		<pubDate>Thu, 04 Jun 2009 20:26:01 +0000</pubDate>
		<dc:creator>GuestBlogger</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[censorship]]></category>
		<category><![CDATA[cfp09]]></category>
		<category><![CDATA[future]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.cfp2009.org/wordpress/?p=186</guid>
		<description><![CDATA[Mark Belinsky, co-director of the nonprofit Digital Democracy, and a guest blogger for the conference writes from the cloud on the second part of the second day of the conference.
He covers privacy, censorship and circumvention as well as laws on cloud computing and some research. READ MORE!

]]></description>
			<content:encoded><![CDATA[<p><a href="http://4hours.wordpress.com/" target="_blank">Mark Belinsky</a>, co-director of the nonprofit <a href="http://www.dtwo.org/">Digital Democracy</a>, and a guest blogger for the conference writes from the cloud on the second part of the second day of the conference.</p>
<p>He covers privacy, censorship and circumvention as well as laws on cloud computing and some research. <a href="http://4hours.wordpress.com/2009/06/04/computers-freedom-privacy-day-2-part-2/" target="_blank">READ MORE!</a></p>
<div class="wp-caption aligncenter" style="width: 459px"><a href="http://4hours.wordpress.com/2009/06/04/computers-freedom-privacy-day-2-part-2/"><img src="http://4hours.files.wordpress.com/2009/06/cfp09-notes-wordle.png?w=499&amp;h=303" alt="" width="449" height="272" /></a><p class="wp-caption-text">Word Cloud of Popular Words at CFP09</p></div>
<p style="text-align: center;">
]]></content:encoded>
			<wfw:commentRss>http://www.cfp2009.org/wordpress/?feed=rss2&amp;p=186</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
