cleolinda: (wtf)
cleolinda ([personal profile] cleolinda) wrote2010-09-02 01:32 pm

Two major issues: pingback and full names

Well, this is fantastic.

To recap: I cross-posted test comments to both Twitter and Facebook; screencaps and discussion are over here.

You do have to opt in to cross-post, because if you don't connect your LJ to either of those services, it won't know where to post. People have been seeing banners at the top of their journals mentioning this--but I didn't, maybe because I have a permanent account, and the code is treating the banner like an ad? So I hadn't seen that. But it says that if you've already done the Facebook Connect thing, you're going to have to go back in and reactivate it, which also sounds like an opt-in.

Problem: I connected my Cleolinda Jones account--i.e., a pseudonym with no sensitive personal information, which makes me a better guinea pig than most people. For Science! What LJ did not say anywhere in the FAQs was that it will then announce on your user info page (the page strangers are most likely to see, other than your latest entry), under "External Services," that you, Full Name, are on Facebook. The only reason we even found out was because [livejournal.com profile] maetang just happened to notice.




If I had used my personal Lauren Lastname account, I would have been screwed. If your full name being on the page that Unwelcome People are most likely see is a problem for you, REMOVE FACEBOOK CONNECT NOW.

Guess what? There's also ANOTHER PROBLEM. The pingback thing is automatically turned on, according to that banner. My understanding is that if it's on, it sends you emails that someone has linked to you and emails to someone else that you have linked to them. People link to me a lot. Not unreasonably, they have linked to that last entry with the "Here's what cross-posting looks like" screencaps. So I've gotten a couple dozen in the last twelve hours, as well as--weirdly--two-year-old links to Breaking Dawn recaps and Troy in Fifteen Minutes.

Obviously, it told me who linked to me. But four of them were to locked entries that I wasn't supposed to know existed.

It sends you a sentence fragment--in theory--of what they linked, and a link back to the entry in which they did it. At first, I was getting emails with quotes like, "...shows what crossposting looks like here." So, wondering what else the entries said (even though I could guess), I started clicking the links back. That's when I realized I was being linked to (but unable to access) locked entries. Multiple times.

Then I started getting longer and longer excerpts, much of which had nothing to do with me at all. I got a pingback from [livejournal.com profile] maetang, for example, on an entry where she talks about all of this business (linked and quoted with her permission). Here's what the bot emailed me, just to give you the visual impact of it. The part referring to me is in bold:

A bug whereby "/" in tags isn't working. This is an actual bug, and should be fixed. For now, you can manually correct the URL when you select any tags with a "/" in them, and it will still work. It's labourious, but can be done.

Of course it's particularly irritating for all of fandom, to suddenly discover they can't sort through their slash.

Meanwhile, there's also problems with the implementation of pingbacks. Some users in are saying that since it's been reintroduced, they got pingbacks even though they had previously turned those off. Others are saying they got pingbacks from F-locked posts. This is in direct oppostion to the LJ FAQ on how pingbacks are supposed to work:

Pingback notifications include the name and URL of the page that is linking to your entry as well as a brief quote from the text where your entry is linked. Pingback comments to your journal will be left as screened comments. Please note that pingbacks only work for public entries. Friends-Only or Private entries cannot receive pingbacks. [Emphasis mine.]


THE PLAIN STUPID

Not bugs, but just dumb effects of the implementation of the crossposting to Twitter/Facebook "feature".

If you connect your LJ to Facebook, your Facebook name will be listed on your LJ profile page, under "external services". helpfully tested what happens if you do crosspost comments (including long comments with a lot of text), and also has a screencap of her FB name appearing on her profile page. You can check out the screencaps here [...]

What if you had written a locked, very personal entry about something upsetting? But then, at the end, you had switched gears and said (to use the most recent example), "But reading [livejournal.com profile] cleolinda's Breaking Dawn recap really cheered me up"? And then it sent me five paragraphs about your personal business?

Or, what if, blithely assuming I couldn't read the entry because, you know, I'm not on that filter, you gave out your full name and mailing address for, say, Christmas cards?

Or, worse: what if you were writing an entry to vent about someone who pissed you off, and you linked to an entry of theirs as an example?

Yeah. You're probably going to want to turn that off.


And you know why I linked to my own recap up there? Because I'm curious to see if it'll send me a pingback to myself. And if it does: how much of this entry will it quote back at me?



Site Meter

cleolinda: Two (more) major Livejournal security issues and how to fix them: http://cleolinda.livejo

[identity profile] pingback-bot.livejournal.com 2010-09-02 06:37 pm (UTC)(link)
User [livejournal.com profile] cleotwitter referenced to your post from cleolinda: Two (more) major Livejournal security issues and how to fix them: http://cleolinda.livejo (http://syndicated.livejournal.com/cleotwitter/3332461.html) saying: [...] ssues and how to fix them: http://cleolinda.livejournal.com/902080.html [...]

Re: cleolinda: Two (more) major Livejournal security issues and how to fix them: http://cleolinda.li

[identity profile] cleolinda.livejournal.com 2010-09-02 06:54 pm (UTC)(link)
Unscreened as a point of interest. (Someone syndicated my Twitter so they could read it on their LJ friendslist rather than get a Twitter account.)
Edited 2010-09-02 18:55 (UTC)

[identity profile] quarantedeux.livejournal.com 2010-09-02 06:38 pm (UTC)(link)
Wow. I was just going to leave the pingback on because it seemed relatively harmless.

Thanks for the info! I'll definitely be turning that feature off now.

[identity profile] elynne.livejournal.com 2010-09-02 06:53 pm (UTC)(link)
Yeah, ditto here. OFF NOW KTHXNO.

(no subject)

[identity profile] anolinde.livejournal.com - 2010-09-02 19:33 (UTC) - Expand

(no subject)

[identity profile] icepearls.livejournal.com - 2010-09-02 22:00 (UTC) - Expand

[identity profile] ook.livejournal.com 2010-09-02 06:39 pm (UTC)(link)
Pssst! Your post is showing up TWICE. This Facebook thing must really have you flustered.

I'm so glad that I've never signed up for Facebook or Twitter.

[identity profile] cleolinda.livejournal.com 2010-09-02 06:46 pm (UTC)(link)
Fucking Dreamwidth. Well, that answers my question as to whether their journal cross-posting function works. In fact, it works so well that it did it AFTER I TURNED IT OFF.

(I really, really do not want to have to go to Dreamwidth. At this point, I'm going to start mirroring this journal over there because I am really afraid everyone's going to flee LJ and tumbleweed will be blowing through. I DON'T WANT TO LEAVE, LIVEJOURNAL. GODDAMMIT, START ACTING RIGHT.)

(no subject)

[identity profile] cleolinda.livejournal.com - 2010-09-02 18:53 (UTC) - Expand

(no subject)

[identity profile] finch - 2010-09-02 19:02 (UTC) - Expand

(no subject)

[identity profile] auraesque.livejournal.com - 2010-09-02 22:50 (UTC) - Expand

(no subject)

[identity profile] katharhino.livejournal.com - 2010-09-02 19:01 (UTC) - Expand

(no subject)

[identity profile] notemily.livejournal.com - 2010-09-02 22:51 (UTC) - Expand

(no subject)

[identity profile] katharhino.livejournal.com - 2010-09-03 00:26 (UTC) - Expand

(no subject)

[identity profile] ook.livejournal.com - 2010-09-02 19:05 (UTC) - Expand

(no subject)

[identity profile] cleolinda.livejournal.com - 2010-09-02 19:48 (UTC) - Expand

(no subject)

[identity profile] caeliat.livejournal.com - 2010-09-02 21:12 (UTC) - Expand

(no subject)

[personal profile] tephra - 2010-09-02 22:17 (UTC) - Expand

[identity profile] weird-cowgirl.livejournal.com 2010-09-02 06:39 pm (UTC)(link)
Thanks for the update. I hadn't turned off pingback because I figured "no one ever links to me anyway" but now that you've demonstrated the big problem with it, I'd disabled that 'feature.'

[identity profile] ladyairy.livejournal.com 2010-09-02 10:14 pm (UTC)(link)
This, eugh. I guess livejournal hasn't realized that not all links are for the purpose of "see how great link x is".

[identity profile] aymaera.livejournal.com 2010-09-02 06:39 pm (UTC)(link)
Well... that's concerning.

[identity profile] lea724.livejournal.com 2010-09-02 06:39 pm (UTC)(link)
I really appreciate your keeping up with this; it's getting a bit confusing for me and I've been following your updates since the issue began, so I can only imagine random LJ'er John Doe coming in and trying to figure the whole thing out.

A reassurance at this point (for me) is that lately I've been posting so infrequently and about topics only applicable/interesting to me that I'm low enough on the radar of people who'd be taking my posts/comments/etc. to post them elsewhere. (I hope)

Still, I want to reiterate that I'm really glad you're keeping everyone updated about this newest LJ feature.

[identity profile] jadesfire55.livejournal.com 2010-09-02 06:50 pm (UTC)(link)
Seconded. I really appreciate the tests you've conducted!
azurelunatic: Vivid pink Alaskan wild rose. (Default)

[personal profile] azurelunatic 2010-09-02 06:40 pm (UTC)(link)
So far, most of the locked-entry pingbacks I am hearing about are when someone posts public at first but then locks the entry later.

[livejournal.com profile] helens78 has done an asston of testing: http://helens78.dreamwidth.org/860769.html

[identity profile] rabidrainbow.livejournal.com 2010-09-02 07:03 pm (UTC)(link)
What the actual fuck.

I didn't really care about having the Pingback feature enabled (I'm low key enough that I never get linked anywhere and I really only post icons to my journal so there's never really an opportunity to link to someone's specific post) but after reading the results of all that testing I'm going to disable it on principle.

I really don't want to have to move to Dreamwidth, LJ. Stop giving me reasons to do so.

(no subject)

[identity profile] anatsuno.livejournal.com - 2010-09-02 22:23 (UTC) - Expand

(no subject)

[identity profile] cleolinda.livejournal.com - 2010-09-03 01:41 (UTC) - Expand

[identity profile] skiesfyre.livejournal.com 2010-09-02 06:40 pm (UTC)(link)
...this just keeps getting better and better, doesn't it? /sarcasm

Nice job breaking it, LJ.

[identity profile] mermaidkween.livejournal.com 2010-09-02 08:49 pm (UTC)(link)
LJ can no longer help me make shoes for orphans. Sigh.

[identity profile] sideofzen.livejournal.com 2010-09-02 06:40 pm (UTC)(link)
Oh, good.

Thank you for your constant vigilance on this.

[identity profile] sucrelefey.livejournal.com 2010-09-02 06:41 pm (UTC)(link)
I looked and Pingback was not automagically on for me since I disabled and overrode a bunch of stuff years ago. But always double check when changes roll out. Then again I use the old discontinued style sheets which don't support half of the new features.

[identity profile] aka-paloma.livejournal.com 2010-09-02 06:42 pm (UTC)(link)
This is making my brain all hurty.

[identity profile] crowsilike.livejournal.com 2010-09-02 06:45 pm (UTC)(link)
And people wonder why I'm against all this "linking everything online together". This is why.

[identity profile] cmdr-zoom.livejournal.com 2010-09-02 06:52 pm (UTC)(link)
That's only because you have something to hide. Normal people have no problem living in a fishbowl and being watched 24/7, right?

(no subject)

[personal profile] snippy - 2010-09-02 21:37 (UTC) - Expand

(no subject)

[identity profile] robling-t.livejournal.com - 2010-09-03 09:51 (UTC) - Expand

(no subject)

[identity profile] crowsilike.livejournal.com - 2010-09-03 11:02 (UTC) - Expand
ext_18053: (dearjack)

[identity profile] djarum99.livejournal.com 2010-09-02 06:50 pm (UTC)(link)
My brain hurts, too. I'm not linked to Facebook and pingbacks are disabled (checked everything twice), but my understanding is that people who are linking LJ to Facebook can crosspost from my journal, even from locked posts (?)

I don't like it. I don't want a kitty icon. It is perversely amusing to watch the comment count on LJ news continue to rise with no real response from staff. I've got money on 8,765 with a 20 point spread.
msilverstar: (drowning in splooge)

[personal profile] msilverstar 2010-09-02 07:44 pm (UTC)(link)
yep, they can cross-post replies without really meaning to, LJ is making it too easy

[identity profile] tinylegacies.livejournal.com 2010-09-02 06:51 pm (UTC)(link)
It is possible that those posts were unlocked at the time they linked to you and locked later.

I did a mass flock on my journal yesterday and got PMs from two people who got pingbacks from me for stuff that used to be public.

[identity profile] bexone.livejournal.com 2010-09-02 08:13 pm (UTC)(link)
from the testing helens78 has done, it looks like any edit to a public post, even making it flocked or private without changing a single letter, will trigger a pingback. so it looks like for the anti-pingback-inclined, leaving all your posts as-is is actually safer than flocking the whole journal and running the risk of triggering a pingback from a link in an (originally) public post. the bugginess of the pingback code alone would make this code push a pretty epic fail on lj's part, even without all the unprivacy creepiness.

[identity profile] glenvorian.livejournal.com 2010-09-02 06:54 pm (UTC)(link)
Well done, LJ, on making yourselves look like asshats once again.

[identity profile] randomdiversion.livejournal.com 2010-09-02 06:55 pm (UTC)(link)
I turned off pingbacks the minute I saw the banner for them. :)

[identity profile] cleolinda.livejournal.com 2010-09-02 07:06 pm (UTC)(link)
But I didn't get the banner! Who else didn't get the banner!

D: D: D:

(no subject)

[identity profile] tygress.livejournal.com - 2010-09-02 19:21 (UTC) - Expand

(no subject)

[identity profile] cleolinda.livejournal.com - 2010-09-02 19:39 (UTC) - Expand

(no subject)

[identity profile] tabbyclaw.livejournal.com - 2010-09-02 19:49 (UTC) - Expand

(no subject)

[identity profile] eofs.livejournal.com - 2010-09-02 23:12 (UTC) - Expand

(no subject)

[personal profile] pandorasblog - 2010-09-02 20:27 (UTC) - Expand

(no subject)

[identity profile] surrexi.livejournal.com - 2010-09-02 20:53 (UTC) - Expand

(no subject)

[personal profile] gorgeousnerd - 2010-09-02 21:31 (UTC) - Expand

(no subject)

[identity profile] crowsilike.livejournal.com - 2010-09-03 11:08 (UTC) - Expand
ext_15529: made by jazsekuhsjunk (icon_me - inconceivable)

[identity profile] the-dala.livejournal.com 2010-09-02 06:55 pm (UTC)(link)
All of these discussions are starting to remind me of that scene in "Labyrinth" with the door to certain doom - "one of us always tells the truth, and one of us allllways lies."

I did not realize the pingback feature worked like that - I just figured hey, it's fun to know when people have recced me or whatever. NO GOOD. Thanks for posting this!

[identity profile] kauricat.livejournal.com 2010-09-02 06:55 pm (UTC)(link)
Thank you, thank you, thank you. I had no idea what potential havoc pingbacks could wreak.

[identity profile] randomdiversion.livejournal.com 2010-09-02 06:58 pm (UTC)(link)
Cleo, thanks for doing this as a public service to everyone.

[identity profile] sixthbrightest.livejournal.com 2010-09-02 08:53 pm (UTC)(link)
Agreed. You're really on top of this and you're keeping us informed (and safe). We appreciate it.

[identity profile] editornia.livejournal.com 2010-09-02 06:59 pm (UTC)(link)
Pingbacks: disabled. Facebook Connect: not connected and never will be.

Thanks for all the heads-ups and testing in the name of science, Cleo. :)
tephra: (kitty squid)

[personal profile] tephra 2010-09-02 07:27 pm (UTC)(link)
I also added the custom CSS shown here so that, theoretically, no one has those ticky boxes to cross post their comments when commenting on my journal.

(no subject)

[personal profile] tephra - 2010-09-02 19:32 (UTC) - Expand

(no subject)

[identity profile] eofs.livejournal.com - 2010-09-02 23:14 (UTC) - Expand

(no subject)

[personal profile] tephra - 2010-09-02 23:39 (UTC) - Expand

[identity profile] shadowmaat.livejournal.com 2010-09-02 07:00 pm (UTC)(link)
I hadn't bothered to turn off pingback because no one ever links to me but after this I've decided to turn it off just to be safe. I don't think there's anything dangerous in any of my locked entries, but I'd rather not find out the hard way that I was wrong. ;)

[identity profile] demonoflight.livejournal.com 2010-09-02 07:00 pm (UTC)(link)
I turned it off the second I realized what it is. This is seriously compromising my privacy. My parents read my Facebook, man, they don't need to know about my LJ...

[identity profile] ambiguousreason.livejournal.com 2010-09-02 07:01 pm (UTC)(link)
Hm, as far as I can tell the pingback is opt-in? When I went to check/turn it off, it was already disabled. I don't know.

[identity profile] cleolinda.livejournal.com 2010-09-02 07:07 pm (UTC)(link)
Other people have told me it was automatically enabled for them (in fact, I think that's what the banner said). People keep saying one thing, then other people say another, and half of it worked the opposite way for me. I don't even knooooow.

(no subject)

[identity profile] angelene.livejournal.com - 2010-09-03 08:13 (UTC) - Expand

(no subject)

[personal profile] soprano - 2010-09-04 03:48 (UTC) - Expand

(no subject)

[personal profile] soprano - 2010-09-04 04:09 (UTC) - Expand

[identity profile] queenanthai.livejournal.com 2010-09-02 07:01 pm (UTC)(link)
"ZOMG DAYNA YOU HAVE TO GET A FACEBOOK EVERYBODY ELSE IS DOING IT"

Yeah, no.

[identity profile] aka-paloma.livejournal.com 2010-09-02 07:19 pm (UTC)(link)
This is me! Ugh. Why are people so flabberghasted to learn I'm not on Facebook? And don't even get me started at the shock, horror, and dismay when they learn I don't have a cellphone. It's like I've told them I've mugged their grandmother or shot their dog or something.

(no subject)

[identity profile] pleure.livejournal.com - 2010-09-03 03:26 (UTC) - Expand

(no subject)

[identity profile] crowsilike.livejournal.com - 2010-09-03 11:20 (UTC) - Expand

(no subject)

[identity profile] greyduck.livejournal.com - 2010-09-02 19:22 (UTC) - Expand

(no subject)

[identity profile] cleolinda.livejournal.com - 2010-09-02 19:38 (UTC) - Expand

(no subject)

[identity profile] crowsilike.livejournal.com - 2010-09-03 11:12 (UTC) - Expand

(no subject)

[identity profile] friggeng.livejournal.com - 2010-09-02 23:42 (UTC) - Expand

[identity profile] trinastar.livejournal.com 2010-09-02 07:03 pm (UTC)(link)
Facebook has been self-destructing because they keep initiating things that will invoke privacy invasion problems. LiveJournal shouldn't be following in Facebooks footsteps. Really, it's a BAD IDEA.

[identity profile] cleolinda.livejournal.com 2010-09-02 07:11 pm (UTC)(link)
You're not going to want to look at this, then.

http://www.journalfen.net/community/clairvoyantwank/473988.html?thread=21566084#t21566084

Page 1 of 2