Search the web
Sign In
New User? Sign Up
aggregators
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Show off your group to the world. Share a photo of your group with us.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Slightly OT: Ask Yahoo to enable RSS authentication for groups   Message List  
Reply | Forward Message #809 of 818 |
Re: Slightly OT: Ask Yahoo to enable RSS authentication for groups

Jeremy Zawodny is asking for suggestions on how to bring Yahoo Groups
up to date on his blog.
http://jeremy.zawodny.com/blog/archives/006541.html

--- In aggregators@yahoogroups.com, "Bill Kearney" <ml_yahoo@...>
wrote:
>
> > I've reached the conclusion that "private" RSS feeds that require
> > authentication is a bad idea.
>
> I disagree.
>
> > The problem is that RSS is frequently
> > consumed by spiders, robots and other automated apps and then
> > re-purposed.
>
> Automated apps wouldn't have the auth keys. Thus the feed would
never get
> seen by them.
>
> > This re-purposing often results in the items then appearing
> > in a public feed with no authentication. So even though you serve
up the
> > feed securely you really have no idea what happens to it later. An
> > example of this was a feed that was dropped into Newsgator by a
user. it
> > later turned up in Newsgator's public search. This is not a
refelection
> > on Newsgator necessarily and I know they do try and keep HTTP-Auth
> > protected feeds out of their public database.
>
> The existance of the RSS feed URL can't be assumed to stay
private. That
> something else might possess the URL doesn't compromise the
contents.
>
> > In theory this should be no different from HTTP-AUTH protected web
> > pages. But in practice the RSS community is much less careful
about
> > respecting privacy than the relatively smaller community of
people that
> > write automated apps to access html pages.
>
> I don't think this is any different than any other computer program.
> E-mail, for example, does nothing to prevent simple forwarding, let
along
> cut/paste. Nor do web pages. Feeds aren't any more or
less 'respecting' in
> this regard.
>
> > The point here is that if we write aggregators we should try to be
> > careful about respecting feeds that should be private. In
practice, this
> > can be hard. And as a feed provider you shouldn't assume that your
> > private feed will stay private.
>
> If it's behind an http auth you've reason to assume that unless the
user
> also republishes their username/password combo it'll remain safe
for the
> first pass.
>
> > Which is all a long winded way of saying that if you want a feed
from a
> > Yahoogroup, then make the group open. What is the group owner
trying to
> > hide anyway?
>
> I likewise disagree on this point. It's tragically disappointing
that yahoo
> has not come to grips with this problem. That they cannot offer
their list
> members the option of using RSS for their lists shows they really
don't get
> RSS.
>
> -Bill Kearney
>







Fri Mar 31, 2006 7:24 pm

nsputnik
Offline Offline
Send Email Send Email

Forward
Message #809 of 818 |
Expand Messages Author Sort by Date

Sorry for the slight off-topic-ness of this post, but I'm trying to get Yahoo to enable RSS authentication so I can keep up with several yahoo groups (that...
sdorfman.rm
Offline Send Email
Feb 28, 2006
8:04 am

Believe it or not, we got the message a while ago... But it's a non-trivial change to our infrastructure and one not to be taken lightly. Jeremy...
Jeremy Zawodny
jzawodn
Offline Send Email
Mar 1, 2006
6:51 am

... Thanks for replying, Jeremy. I'm glad the message got to the right people. Perhaps looking at the way livejournal has implemented RSS authentication would...
sdorfman.rm
Offline Send Email
Mar 2, 2006
5:43 pm

sdorfman.rm <sdorfman@...> Tue, 28 Feb 2006 06:34:43 ... I've reached the conclusion that "private" RSS feeds that require authentication is a bad...
Julian Bond
jbond23uk
Offline Send Email
Mar 6, 2006
12:57 pm

... I disagree. ... Automated apps wouldn't have the auth keys. Thus the feed would never get seen by them. ... The existance of the RSS feed URL can't be...
Bill Kearney
wkearney99
Offline Send Email
Mar 11, 2006
12:39 pm

Jeremy Zawodny is asking for suggestions on how to bring Yahoo Groups up to date on his blog. http://jeremy.zawodny.com/blog/archives/006541.html ... never get...
Nick Dynice
nsputnik
Offline Send Email
Mar 31, 2006
7:25 pm
Advanced

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help