Smugmug Private Photos are for Anyone to See
Apparently the popular photo sharing site Smugmug has a huge security hole that could allow anyone with a bit of common sense to access private photos on Smugmug. The basic problem here is that Smugmug uses URL’s for public and private galleries in a way that can be easily guessed. And whats even more shameful is that the people behind the site are aware of this issue, but they seem to be too keen to say that this is intended behavior.
If seeing private photos via publicly accessible URL’s is what you call intended behavior then I have nothing else to say to the Smugmug team..
Let me take an example here, when I typed in http://www.smugmug.com/gallery/1021 into my browser, i was looking at a collection of photos that were perhaps not meant for people like you and me to have a peak at. Ofcourse Smugmug has other features like password protection, but I’m sure that most users would take password protection as an added trouble in making photos private. They probably think that by marking them as private, no one else except them could see it. But things don’t work that way at Smugmug.
Older
Facebook on Friday 