论文标题
Twitter DM视频可供未经验证的用户访问
Twitter DM Videos Are Accessible to Unauthenticated Users
论文作者
论文摘要
在Twitter Direct消息(DMS)中共享的视频具有基于其内容的哈希的不透明URL,但否则可用于未经验证的HTTP用户。因此,这些DM视频URL很难猜测,但是如果它们以某种方式发现,则可以向任何用户,包括没有Twitter凭据的用户(即Twitter.com特定的HTTP Cookie或授权请求标题)。这包括Web档案,例如著名的Internet档案Wayback机器,可用于将DM视频移至Twitter.com之外的域。 DM视频缺乏身份验证与DMS中的Twitter模型相反,DMS也具有不透明的URL,但需要在DM参与者之间共享特定于会话的HTTP cookie。我们回顾了两个演示帐户之间共享的图像和视频的最低可再现示例,并表明,虽然图像受到保护免受未经身份验证的访问以及从身份验证的第三方的保护,但该视频本身对于任何知道URL的用户都可以持续使用。
Videos shared in Twitter Direct Messages (DMs) have opaque URLs based on hashes of their content, but are otherwise available to unauthenticated HTTP users. These DM video URLs are thus hard to guess, but if they were somehow discovered, they are available to any user, including users without Twitter credentials (i.e., twitter.com specific HTTP Cookie or Authorization request headers). This includes web archives, such as the well-known Internet Archive Wayback Machine, which can be used to move DM videos to domains outside of twitter.com. This lack of authentication for DM videos is in contrast to Twitter's model for images in DMs, which also have opaque URLs but require a session-specific HTTP cookie shared only between the DM participants. We review a minimal reproducible example of an image and video shared between two demo accounts, and show that while the image is protected from unauthenticated access as well as from an authenticated third party, the video itself is persistently available for any user who knows the URL.