Google's Unguessable URLs
Schneier on Security 2015-07-20
Summary:
Google secures photos using public but unguessable URLs:
So why is that public URL more secure than it looks? The short answer is that the URL is working as a password. Photos URLs are typically around 40 characters long, so if you wanted to scan all the possible combinations, you'd have to work through 1070 different combinations to get the right one, a problem on an astronomical scale. "There are enough combinations that it's considered unguessable," says Aravind Krishnaswamy, an engineering lead on Google Photos. "It's much harder to guess than your password."
It's a perfectly valid security measure, although unsettling to some.
Link:
https://www.schneier.com/blog/archives/2015/07/googles_unguess.htmlFrom feeds:
Gudgeon and gist » Schneier on SecurityFair Use Tracker » Current Berkman People and Projects
Berkman Center Community - Test » Schneier on Security