Re: Google Web Accelerator
This WebDNA talk-list message is from 2005
It keeps the original formatting.
numero = 62012
interpreted = N
texte = Doesn't this kind of activity expose Google to serious liability, such as, say, a whole bunch of web-developers who have had their sites damaged by this 'feature', getting together and filing a class-action lawsuit? I know that I give some users of my sites password-protected access to portions of the back-end, but I don't recall ever giving Google that kind of access... or does the 'ability' to prevent the 'feature' from accessing our sites (via non-billable time that we have to waste), shield them from liabilty? Any lawyers on the house?-DanOn Thu, 12 May 2005 08:33:27 -0700 sal danna
wrote:> If one of your customers is using it, and they log into your an admin> section, it will start going through all the links including any> delete function you might have made for them. It won't even see any> safe guards that have been put in place like a pop up that says "are> you sure you want to delete this record", etc. It will just start> deleting.> > Sal D'Anna> >> >> >> On 5/12/05, Donovan Brooke wrote:>> > sal danna wrote:>> > > [snip]They can't get to password protected areas, they don't cache>> > > https links, they don't cache news or large files. If you have the>> > > ability to "delete" or "cancel" something sensitive without all of those >> > > protections you are just asking for it to be deleted or canceled.[/snip]>> > >>> > > Doesn't matter if it's password protected or not because Google Web>> > > Accelerator is software you install in your browser so it's seeing >> > > whatever you are seeing (even if it's password protected). This is>> > > what the first link says you should do to protect your site:>> > >>> > > "If you have a web app, it might be worth returning a 403 when the >> > > HTTP_X_MOZ is set to "prefetch" header is sent. This will keep Web>> > > Accelerator from clicking destructive links.">> > >>> > > Sal D'Anna>> > >> > I guess I don't get your point Sal, if its installed on someoneelses >> > browser that doesn't have access to my sensitive content, how is that>> > a problem?>> > >> > Donovan>> > >> > -->> > =o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o>> > DONOVAN D. BROOKE Eucalyptus Design>> > <-Web Development (specializing in eCommerce), ->>> > <- Graphic Design, Custom Tags and Labels ->>> > >> > ADDRESS:> Donovan Brooke>> > DBA Eucalyptus Design>> > N2862 Summerville Park Rd.>> > Lodi, WI 53555>> > PH:> 1.608.592.3567>> > Web:> http://www.euca.us>> > =o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o>> > >> > ------------------------------------------------------------->> > This message is sent to you because you are subscribed to >> > the mailing list .>> > To unsubscribe, E-mail to: >> > To switch to the DIGEST mode, E-mail to >> > Web Archive of this list is at: http://webdna.smithmicro.com/>> > >> >>> > -------------------------------------------------------------> This message is sent to you because you are subscribed to> the mailing list .> To unsubscribe, E-mail to: > To switch to the DIGEST mode, E-mail to > Web Archive of this list is at: http://webdna.smithmicro.com/-------------------------------------------------------------This message is sent to you because you are subscribed to the mailing list .To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://webdna.smithmicro.com/
Associated Messages, from the most recent to the oldest:
Doesn't this kind of activity expose Google to serious liability, such as, say, a whole bunch of web-developers who have had their sites damaged by this 'feature', getting together and filing a class-action lawsuit? I know that I give some users of my sites password-protected access to portions of the back-end, but I don't recall ever giving Google that kind of access... or does the 'ability' to prevent the 'feature' from accessing our sites (via non-billable time that we have to waste), shield them from liabilty? Any lawyers on the house?-DanOn Thu, 12 May 2005 08:33:27 -0700 sal danna wrote:> If one of your customers is using it, and they log into your an admin> section, it will start going through all the links including any> delete function you might have made for them. It won't even see any> safe guards that have been put in place like a pop up that says "are> you sure you want to delete this record", etc. It will just start> deleting.> > Sal D'Anna> >> >> >> On 5/12/05, Donovan Brooke wrote:>> > sal danna wrote:>> > > [snip]They can't get to password protected areas, they don't cache>> > > https links, they don't cache news or large files. If you have the>> > > ability to "delete" or "cancel" something sensitive without all of those >> > > protections you are just asking for it to be deleted or canceled.[/snip]>> > >>> > > Doesn't matter if it's password protected or not because Google Web>> > > Accelerator is software you install in your browser so it's seeing >> > > whatever you are seeing (even if it's password protected). This is>> > > what the first link says you should do to protect your site:>> > >>> > > "If you have a web app, it might be worth returning a 403 when the >> > > HTTP_X_MOZ is set to "prefetch" header is sent. This will keep Web>> > > Accelerator from clicking destructive links.">> > >>> > > Sal D'Anna>> > >> > I guess I don't get your point Sal, if its installed on someoneelses >> > browser that doesn't have access to my sensitive content, how is that>> > a problem?>> > >> > Donovan>> > >> > -->> > =o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o>> > DONOVAN D. BROOKE Eucalyptus Design>> > <-Web Development (specializing in eCommerce), ->>> > <- Graphic Design, Custom Tags and Labels ->>> > >> > ADDRESS:> Donovan Brooke>> > DBA Eucalyptus Design>> > N2862 Summerville Park Rd.>> > Lodi, WI 53555>> > PH:> 1.608.592.3567>> > Web:> http://www.euca.us>> > =o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o=o>> > >> > ------------------------------------------------------------->> > This message is sent to you because you are subscribed to >> > the mailing list .>> > To unsubscribe, E-mail to: >> > To switch to the DIGEST mode, E-mail to >> > Web Archive of this list is at: http://webdna.smithmicro.com/>> > >> >>> > -------------------------------------------------------------> This message is sent to you because you are subscribed to> the mailing list .> To unsubscribe, E-mail to: > To switch to the DIGEST mode, E-mail to > Web Archive of this list is at: http://webdna.smithmicro.com/-------------------------------------------------------------This message is sent to you because you are subscribed to the mailing list .To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://webdna.smithmicro.com/
"Dan Strong"
DOWNLOAD WEBDNA NOW!
Top Articles:
Talk List
The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...
Related Readings:
Today's suggestions (1998)
Re:Emailer problem....still (1997)
[AppendFile] problem (WebCat2b13 Mac .acgi) (1997)
Netscape v. IE (1997)
Shipping charges depending on tax rate? (1997)
Never ending problem.... (2000)
Firesite cache vs webcat cache (1997)
test (2002)
webcat- multiple selection in input field (1997)
authorizenet and netscape (2002)
Shop from PDF (2004)
The Guru and the Cyclops (1998)
WebCat2 - [format thousands] (1997)
Re:Help name our technology! (1997)
Authenticate (1999)
[WebDNA] Date and Time as numbers (2009)
RE: Error: template (1997)
[showif] problem (1999)
Payment Processors (2003)
Email Attachments (1998)