Slashdot Log In
Is Flixster Using Deceptive Viral Practices?
Posted by
kdawson
on Mon Mar 26, 2007 03:31 AM
from the password-please dept.
from the password-please dept.
Talaria writes "The social networking movie review site Flixster is requesting their users' AOL, Gmail, Yahoo and Hotmail passwords, and then using them to access users' address books and send 'invitations' to join Flixster, making them appear to come from the user. The password prompt screen includes the ISP's logo right next to the password prompt. Rather than hiding this little 'feature,' Flixster brags about it in an interview after receiving $2 million in venture funding earlier this year." American Venture Magazine notes: "...such practices are becoming increasingly... common as new and even established web sites look to attract visitors without expensive marketing campaigns and a hefty advertising budget."
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
Facebook does this too. (Score:4, Informative)
Re: (Score:2, Informative)
Re:Facebook does this too. (Score:5, Informative)
Parent
Re:Facebook does this too. (Score:5, Insightful)
Parent
Exactly; not new (Score:5, Informative)
sms.ac did exactly the same thing; but didn't ask permission to email people. Whilst you'd think people would know better even Joi Ito got caught by this, what's worse is they spammed before the signup process was complete. Joi immediately quit using the service and blogged a public apology [ito.com], referring to sms.ac as spammers. Next thing you know they sent him a cease and desist [ito.com] demanding Joi stopped calling them spammers.
Parent
Re: (Score:2)
Re:Facebook does this too. (Score:4, Insightful)
Think about it, if people never clicked on the links, replied to the emails, or called the numbers these spammers would probably die off. It is the fault of the masses of people to are all too eager and ignorant. Power thru inaction would solve spamming. Well, at least curb it a bit.
So back to the topic at hand, while this is very dasterdly, I have never signed up with facebook, I do not have a myspace page, i don't do that school class reunion site. These sites with their ads also help keep these scary/shady companies alive too. If they do things that are as bad as this publicly, imagine what they're doing behind our digital backs. Let's see, they have just about your entire personal history, background, lifestyle, etc. not mention they probably have every single click on their own respective websites completely tracked. They own you and can probably easily guess all of your secret questions for password reminders on any site such as "Your pets name" or "city your high school was in" or "what is your favorite color", etc.
Sorry for the paranoia and cynicism. I just don't trust these people, especially without some regulatory oversight. I am totally against said regulatory oversight so I just exercise extreme caution and do not generally sign up for these types of sites.
Have a nice day.
Parent
Re:Facebook does this too. (Score:5, Insightful)
1) Boycott the scummers that use these tactics
Parent
My Gmail password?! (Score:4, Insightful)
Re: (Score:2, Funny)
If they want to send me some of their shit, I send them some of fucking mine.
Re:My Gmail password?! (Score:4, Funny)
Edit->Preferences
Select the Security Tab
Click the Show Passwords button
Click the Show Passwords button on the window that comes up
Click the Yes button.
Copy your list of usernames and passwords
Paste the list here so I can make sure for you that the username and passwords are valid.
Parent
Not to mention (Score:3, Informative)
There is no way of telling if the password used is provided to a third party without consent or if the site is hacked. Be careful with your personal data, and keep your login to yourself as much as possible.
If you create a site with interactive content - think twice before if you really need your visitors to log in to request the content.
Re:Not to mention (Score:4, Interesting)
Anybody who gets an account on service X will be asked for a password and a contact email address. Chances are that the password will get you right into their email account, because people don't like having 100s of low security passwords.
Of course, I trust slashdot not to take my password and try to get into all my other accounts. Am I justified?
Parent
So be smart, don't use the same (Score:3, Interesting)
If you have to re-use passwords, at the very least do something like having half a dozen passwords, one for each category. One for your email, one for web forums, one for work, one for the home computer (but use a firewall anyway), one for PayPal/Ebay/whatever, one for MMOs or whatever. Ok, maybe you don't like having 100 passwords, but you _can_ remember 5-6 passwords, right?
That way if one is compromised, basic
Re: (Score:3, Informative)
Re: (Score:3, Informative)
another nasty trick... (Score:5, Interesting)
Re:another nasty trick... (Score:4, Insightful)
That, however, would fall squarely under the category of "cracking". By asking for it, they can claim to have (at least as a pretense) your "permission" to spam your friends and contacts.
I do have to wonder, though, whether this might not count as a DMCA violation for Flixster, regardless of the appearance of having your permission... Virtually all free email hosts have a clause in their terms saying basically that you and only you may use your account. By using it "on your behalf", Flixster has used your password to circumvent an access control mechanism, the magical phrase that triggers a DMCA violation.
Parent
Non-Issue (Score:5, Informative)
I'm not saying I'm a fan of their scheme, but it's not like they're scamming anyone. You even get to select who you want to invite.
I guess some people feel they have to produce content, even if they have to dress a non-story up in inflammatory language and ignore the facts of the situation. Gotta drive those Adsense impressions.
Re:Non-Issue (Score:4, Insightful)
I recently signed up with Facebook to get in touch with some old friends and generally pretend to be one of the cool kids. They have a similar feature where I was able to provide my login information for gmail or yahoo, and it would automatically dend friend requests to folks in my address books. Sure, it's a bit stupid to provide your login information to a third party. If that information is stored, then yes it could be breached. But, ultimately the facebook feature and the one in this article are apparently very straightforward. A user can choose to share the login information with a third party. As long as that third party does what they say they will, I'm not sure where the issue is.
Ideally, webmail providers would get together with the folks who impliment these sorts of features, and make some sort of easy way to generate a one time use password that can only be used by an IP assigned to the domain that is supposed to use it. Then, you could impliment this sort of thing without needing as much trust. Then, the next time you login to your webmail, it pops up a message saying that "XYZ domain used the one time key you generated on X date to attempt the following actions. Please look over this log and make sure it is what you wanted them to do and click approve or deny."
But, the security issue doesn't even seem to be the main complaint of the article. It's just all huffy about them doing what they say they will, and declaring it deceptive.
Parent
Re: (Score:2)
Re: (Score:2)
Sure there is a different security issue regarding providing login information to 3rd parties... a quite serious problem I agree, but that's not the point of the article. That they missed the much more credible and important argument on security policy speaks volumes. Cynical perhaps, but security articles don't bring in nearly as many readers as "OMG SPAMMER!@!!!one!1"
I'll point out again t
Some crazy man's "great business idea" (Score:5, Interesting)
And so it came to be. It's crazy not just because it's deceptive, but because it's a security nightmare. If you give your passwords to random sites even for the nicest purposes (which isn't even the case here) it's guaranteed they'll be leaked, and your accounts abused.
What's next: signing a warrant of attorney so the great Flixster, so they could send your buddies free gifts, funded by your bank accounts and credit cards? It's definitely in the same line of thought as this preposterous scheme here.
Re: (Score:2)
Really? Literally, actually hear them? Unless you work there, they must be screaming pretty loudly!
Seriously though, any developer should not be screaming about this - it's a functional issue with this site, not a technical one. Their boss might "insist" on this being implemented, because it was in the signed off functional spec. which the developer is paid to implement.
D.
Re: (Score:3, Insightful)
I was only doing my job M'Lud.
Now where have I heard that one before.
Plaxo, facebook, Taggedmail do it too (Score:2)
I'm just surprised how these guys get funded at all. Anyone will tell you that this practice is unsustainable, not to mention unethical.
Re: (Score:2)
Ethics and sustainability only serve to limit the return on the VC's investment.
Is this guy serious? (Score:2)
"We make it easy to invite your friends. Other sites don't provide good ways for people to spread the word."
What, like calling your friend and saying "Hey, this is a great site" or emailing them and saying "Hey, this is a great site" or texting them and saying "Hey, this is a great site" or walking up to them and saying "Hey, this is a great site"? (Did I make my point?)
From "Blaster.virus.com"- "Hey, we have a great site and we're going to check out you email address list and send ema
Maybe (Score:4, Interesting)
The page in question is formatted to resemble a login gateway page of the various providers (think Microsoft Passport and the like) using the domain part of your email address to decide which provider login to display. Even though I consider myself quite knowledgeable when it comes to security related issues and have done security consulting for various companies, I *might* have fallen for this since it admittedly lowered my suspicions. I doubt Joe Sixpack or even many above-average users would have questioned the purpose of this form.
Worth noting is their elaborate privacy policy [flixster.com] and the cute picture of a monkey in their terms of service [flixster.com]. Also, the footnote "Flixster does not store this information in any way" seems to have been added after the screen shots in TFA were taken and I could not find any information on how they connect to the email services (i.e. via a cryptographically safe link or plain text via a Win98 proxy server in Nigeria)
Phishing made easy (Score:5, Insightful)
As this practice gets more common, people will lower their guards (if they had them in the first place) and become conditioned to give out their password to anyone who asks.
I can already hear them say "... but the website asked me for it... was that wrong?" *sigh*
Re: (Score:2)
Re: (Score:2)
Several swimming pools near my home will give out locker keys but require your car keys as security. Whenever I go along I have this huge argument about it. I will happily give them a fifty dollar note as security. The car is worth a lot more than that to me and a replacement locker key is perhaps 10 dollars. They should be happy with the 50.
But everbody else hands over their keys. Pool staff could be out on the roa
Some people will fill in anything on the web (Score:2)
So the next question would be; if they had a similar page with the Bank Of America/Barclays/whatever logo, would people be just as happy to give their details for them?
Either way, it's scary. Scary that Flixster thinks this is an acceptable way to market themselves, scary that people are letting them
FUD (Score:2, Informative)
Bullshit - this is plain vanilla misrepresentation (Score:2)
In this case it's certainly worth reading the Terms & Conditions - if that 'feature' isn't in there you ought to be able to sue the hell out of them.
Re: (Score:2)
I know of lots of websites that do something similar, but the important difference would be that;
- they only spoof your address, the email does not actually come from your email account
- they don't need your password
- you supply the addresses, they don't rifle your address book
Or so I thought, I'd never use such a thing. If the website was that good I'd tell my friends myself, not fire spam at them. Real friends don't spam you.
Re: (Score:2, Informative)
Marketing IS deception (Score:3, Funny)
Convenience, not abuse (Score:2)
I can't understand why this is a problem. You already trust these networking sites with pretty detailed information on your own preferences, tastes, friends, location etc., so your e-mail password is not much of an asset to them. Any abuse would obviously lead to people changing their passwords.
The feature is really useful, and presented properly it is not abusive at all. What it does, is log in to your e-mail account and grab your address book. Then you are able to check off people you want to invite and
Abuse, not Convenience (Score:3, Insightful)
But to give you the benefit of the doubt:
There is absolutely no reason, security or otherwise, for a user's password to be anywhere but between the user's ears or typed in to the one correct "password" box where it applies. Even the company who provides the password-protected service has no need of it, unless they have a severely damage
Here's how to stop these scams (Score:5, Insightful)
-Section 2. Personal Use: "The Service is made available to you for your personal use only."
I see two violations here. First of all, they are giving the use of the service to someone other than themselves, violating the word "your". Secondly, they violate the word "personal" - this is clearly a business application
-Section 3. Proper Use: "... Your use of the Service is subject to your acceptance of and compliance with the Agreement, including the Gmail Program Policies
Violations of the program policies include:
- "Generate or facilitate unsolicited commercial email ("spam"). Such activity includes, but is not limited to
-Additionally in Section 3: You shall not "(i) use the Service to upload, transmit or otherwise distribute any content that is unlawful, defamatory, harassing, abusive, fraudulent, obscene, contains viruses, or is otherwise objectionable as reasonably determined by Google;" Again, I find spam harassing.
Given these violation, Google would be well within their rights to terminate the accounts (actually, according to the Terms of Use, they can do that whenever they feel like it, but lets assume they don't want to look too evil). Alternatively, They could send out notices that they will terminate any accounts that have been violated if they don't change their password in the next 10 days. Since so many people would lose, or face impending loss of their email accounts, services such as Flixster would suddenly have to find a new business model.
While I didn't check, I would bet hotmail, yahoo mail etc. have similar terms of use.
Even if Flixster decided to keep being an ass and collect passwords anyways, that would just mean that people stupid enough to give out their passwords would no longer have email accounts. Either way, I see no loss. Get to it Google et al.
Re: (Score:3, Insightful)
Hilarious. (Score:2)
Why don't Gmail block them? (Score:3, Interesting)
Re: (Score:3, Insightful)
1) There's nothing to prevent Flixster from sending employees out to Internet cafés to send the mails, or getting them to do it from home, etc. Sure, it's an inconvenience, but if they're truly determined they could do it. Alternatively, just buy a bunch of modems and get some free dial-up accounts, or use proxies, etc.
2) My company, like probably the vast majority, NATs its LAN. To the outside world, almost every single desktop appears to be behind the same IP a
Re: (Score:3, Insightful)
Your idea will fail because:
most of the time it's the same password anyway (Score:2, Insightful)
This is just asking permission. Nine out of ten times, they've already got the information.
Still don't like it. The real solution is for the mail providers to provide a secondary authentication measure to provide information from a users' acco
Some are much worse (Score:3, Informative)
This is by far not as bad as what wayn.com does (or at least used to do). They were just sending out their spam through your account without your knowledge. See "WAYN - Where Are You Now? Warning [misterorange.com]" or Wayn.com : phishing alert, ne vous faites pas couillonner ! [pingouin.be] (the last one in French). (found these at the end of a French blog post about other deceptive practices of Wayn.com [alma.ch])
Re: (Score:2, Funny)
Unethical behavior = SUED FOR $$$?? (Score:2)
If you give a website your password to your email account, you are to blame. If the company is hacking into your accounts to send out its viral invites...that's when the crap needs to hit the fan.
The users are partly to blame for being stupid, but the use of the logos in the article's screenshots *could* reasonably be taken to imply Hotmail/AOL's endorsement. Even simply asking for an AOL/Hotmail password could lead some to assume that there's an association.
Yes, they shouldn't assume; but that's the way things normally work. Flickr asks for your Yahoo account, because they're associated, so this is the same thing? Wrong, of course.
But I think that this is a whole world of legal pain for Flixst