Author

Topic: offsite profile image risks (Read 794 times)

full member
Activity: 168
Merit: 100
June 22, 2011, 07:36:22 PM
#3
Agreed.  For best security, images should be uploaded and/or cached/pulled from the bitcoin.org server before being displayed.

Not to mention image signatures are annoying as crap.
hero member
Activity: 812
Merit: 1022
No Maps for These Territories
June 22, 2011, 02:04:13 PM
#2
+1

also links to external HTTP images break the lock icon in HTTPS connections
newbie
Activity: 59
Merit: 0
June 22, 2011, 01:55:04 PM
#1
When viewing this thread..

http://forum.bitcoin.org/index.php?topic=21052.0;topicseen

..I got an HTTP login prompt, apparently because the page was trying to display this image from someone's profile..

http://pool.bloodys.com/?action-userbar&cmd=2a8ca8960d59854f4e04b1963161b766.png

An unsophisticated user might enter their forum.bitcoin.org credentials into that prompt.

More generally, loading offsite images is an information leak (IP addresses of forum readers) and possibly even security risk (if any browser image-handling flaw would let the source site do more, such as redirect to some other site's XSS CSRF flaw, run JS, or in a worst-case, buffer-overflow for local code execution).

I suggest in our new security-conscious era, loading of offsite images as profile icons be disabled.

Jump to: