Go Back   English Forum Switzerland > Help & tips > TV/internet/telephone
Reply
 
Thread Tools Display Modes
  #1  
Old 12.05.2015, 16:13
mirfield's Avatar
Moddy McModface
 
Join Date: Apr 2007
Location: Basel
Posts: 8,188
Groaned at 50 Times in 44 Posts
Thanked 8,034 Times in 2,942 Posts
mirfield has a reputation beyond reputemirfield has a reputation beyond reputemirfield has a reputation beyond reputemirfield has a reputation beyond reputemirfield has a reputation beyond reputemirfield has a reputation beyond repute
How Secure is a Random URL?

I have a few documents that I like to keep available so I can download them quickly and easily from various places.

They're not for public consumption, though not earth shatteringly private but they'd probably be useful for a bit of identity theft - my photo, my CV, scans of my professional certificates, that sort of thing (I keep all my really private stuff on Post-It notes).

I appreciate that security by obscurity isn't a great solution, but if I save them to a server with a random directory name (e.g. "englishforum.ch/hha8jsjnjb1sb"), how likely are they to be found by someone trawling the internet?

The parent directory has a blank index.htm, so there is no directory listing and there is nothing that links to the directory, but is there another way to find the directory structure of a site?

I know there's ftp and similar apps, but I want to keep it as simple as possible so that I can retrieve the documents from wherever I am and on whatever device. And it seems to me, that even with FTP, it'd still be unencrypted in an otherwise accessible folder.

Essentially, I just want confirmation that it's a terrible idea to encourage me to stop being lazy and do a proper job.
Reply With Quote
  #2  
Old 12.05.2015, 16:14
adrianlondon's Avatar
Forum Legend
 
Join Date: Nov 2009
Location: Basel
Posts: 8,792
Groaned at 189 Times in 172 Posts
Thanked 24,223 Times in 6,523 Posts
adrianlondon has a reputation beyond reputeadrianlondon has a reputation beyond reputeadrianlondon has a reputation beyond reputeadrianlondon has a reputation beyond reputeadrianlondon has a reputation beyond reputeadrianlondon has a reputation beyond repute
Re: How Secure is a Random URL?

Stick it in your own webspace with a user/password (.htaccess)?
Reply With Quote
The following 2 users would like to thank adrianlondon for this useful post:
  #3  
Old 12.05.2015, 16:25
aSwissInTheUS's Avatar
Forum Legend
 
Join Date: Nov 2007
Location: Zurich area
Posts: 5,028
Groaned at 40 Times in 38 Posts
Thanked 7,070 Times in 3,215 Posts
aSwissInTheUS has a reputation beyond reputeaSwissInTheUS has a reputation beyond reputeaSwissInTheUS has a reputation beyond reputeaSwissInTheUS has a reputation beyond reputeaSwissInTheUS has a reputation beyond reputeaSwissInTheUS has a reputation beyond repute
Re: How Secure is a Random URL?

Put it in a securely encrypted container.
Reply With Quote
The following 2 users would like to thank aSwissInTheUS for this useful post:
  #4  
Old 12.05.2015, 16:29
adrianlondon's Avatar
Forum Legend
 
Join Date: Nov 2009
Location: Basel
Posts: 8,792
Groaned at 189 Times in 172 Posts
Thanked 24,223 Times in 6,523 Posts
adrianlondon has a reputation beyond reputeadrianlondon has a reputation beyond reputeadrianlondon has a reputation beyond reputeadrianlondon has a reputation beyond reputeadrianlondon has a reputation beyond reputeadrianlondon has a reputation beyond repute
Re: How Secure is a Random URL?

Upload it to the "Swiss news by The Local" forum; no-one will read it.
Reply With Quote
The following 5 users would like to thank adrianlondon for this useful post:
  #5  
Old 12.05.2015, 16:33
mirfield's Avatar
Moddy McModface
 
Join Date: Apr 2007
Location: Basel
Posts: 8,188
Groaned at 50 Times in 44 Posts
Thanked 8,034 Times in 2,942 Posts
mirfield has a reputation beyond reputemirfield has a reputation beyond reputemirfield has a reputation beyond reputemirfield has a reputation beyond reputemirfield has a reputation beyond reputemirfield has a reputation beyond repute
Re: How Secure is a Random URL?

Quote:
View Post
Stick it in your own webspace with a user/password (.htaccess)?
That's essentially what I've done, but without the .htaccess. But that's a good idea, ta.
Reply With Quote
  #6  
Old 12.05.2015, 16:41
Forum Veteran
 
Join Date: May 2013
Location: Nyon
Posts: 1,823
Groaned at 61 Times in 33 Posts
Thanked 2,118 Times in 831 Posts
John_H has a reputation beyond reputeJohn_H has a reputation beyond reputeJohn_H has a reputation beyond reputeJohn_H has a reputation beyond reputeJohn_H has a reputation beyond repute
Re: How Secure is a Random URL?

Security by obscurity is fine as long as your directories can't be indexed.. Stick them in a zip file with a password even.

If somebody gets as far as finding the zip, they will (well i would) look inside and see some crap called CV.doc, MyPhoto.jpg etc and probably not spend any more time or energy decrypting the zip .

Loads of options but yours is an easy one if you already have the hosting - which is probably not blocked in most workplaces too, unlike google docs etc.
Reply With Quote
This user would like to thank John_H for this useful post:
  #7  
Old 12.05.2015, 16:58
Sean Connery's Avatar
Forum Legend
 
Join Date: Nov 2011
Location: Zurich
Posts: 4,924
Groaned at 75 Times in 70 Posts
Thanked 6,395 Times in 2,931 Posts
Sean Connery has a reputation beyond reputeSean Connery has a reputation beyond reputeSean Connery has a reputation beyond reputeSean Connery has a reputation beyond reputeSean Connery has a reputation beyond reputeSean Connery has a reputation beyond repute
Re: How Secure is a Random URL?

I have software that pretty much will scan a website and find every single folder and try to access them. It's part of my pentesting toolkit.

So another vote for strong encryption and a strong passphrase And use TLS for the connection of course so nobody can sniff the GET and nobody can adjust the data en route.
Reply With Quote
The following 2 users would like to thank Sean Connery for this useful post:
  #8  
Old 12.05.2015, 17:25
Junior Member
 
Join Date: Oct 2013
Location: Wallisellen
Posts: 37
Groaned at 0 Times in 0 Posts
Thanked 31 Times in 12 Posts
shailuwap has earned some respectshailuwap has earned some respect
Re: How Secure is a Random URL?

Isn't a private dropbox folder the simplest of all? Or am I missing something?
Reply With Quote
  #9  
Old 12.05.2015, 17:30
me.anon's Avatar
Forum Veteran
 
Join Date: Jan 2012
Location: thun
Posts: 1,452
Groaned at 22 Times in 16 Posts
Thanked 1,763 Times in 869 Posts
me.anon has a reputation beyond reputeme.anon has a reputation beyond reputeme.anon has a reputation beyond reputeme.anon has a reputation beyond reputeme.anon has a reputation beyond repute
Re: How Secure is a Random URL?

You may also want to use a robots.txt file https://support.google.com/webmaster...c=6061961&rd=1 to request that (well behaved) search engines do not scan your files. Otherwise, there is a risk that your contnet ends up as searchable through Google etc.
Reply With Quote
  #10  
Old 12.05.2015, 17:41
lost_inbroad's Avatar
Unbridled Mod
 
Join Date: Dec 2009
Location: KY
Posts: 9,954
Groaned at 563 Times in 363 Posts
Thanked 12,574 Times in 5,007 Posts
lost_inbroad has a reputation beyond reputelost_inbroad has a reputation beyond reputelost_inbroad has a reputation beyond reputelost_inbroad has a reputation beyond reputelost_inbroad has a reputation beyond reputelost_inbroad has a reputation beyond repute
Re: How Secure is a Random URL?

Just email them to yourself and save the email in a separate folder.
Reply With Quote
The following 2 users would like to thank lost_inbroad for this useful post:
  #11  
Old 12.05.2015, 17:52
mirfield's Avatar
Moddy McModface
 
Join Date: Apr 2007
Location: Basel
Posts: 8,188
Groaned at 50 Times in 44 Posts
Thanked 8,034 Times in 2,942 Posts
mirfield has a reputation beyond reputemirfield has a reputation beyond reputemirfield has a reputation beyond reputemirfield has a reputation beyond reputemirfield has a reputation beyond reputemirfield has a reputation beyond repute
Re: How Secure is a Random URL?

Quote:
View Post
So another vote for strong encryption and a strong passphrase And use TLS for the connection of course so nobody can sniff the GET and nobody can adjust the data en route.
Quote:
View Post
Isn't a private dropbox folder the simplest of all? Or am I missing something?
Quote:
View Post
Just email them to yourself and save the email in a separate folder.
These work, but fail the "available from anywhere" criteria. I want availability from a basic browser (and with locked down PCs that don't allow dropbox, webmail, etc.)

Even zipping them will cut some options out.

Maybe I'm going to have to compromise on that.

Thanks for the ideas though.
Reply With Quote
  #12  
Old 12.05.2015, 17:58
Member
 
Join Date: Jul 2014
Location: GE
Posts: 140
Groaned at 13 Times in 4 Posts
Thanked 137 Times in 57 Posts
bugger is considered knowledgeablebugger is considered knowledgeablebugger is considered knowledgeable
Re: How Secure is a Random URL?

How basic are we talking? Any current browser can access the web based google drive no?
Reply With Quote
This user would like to thank bugger for this useful post:
  #13  
Old 12.05.2015, 18:03
mirfield's Avatar
Moddy McModface
 
Join Date: Apr 2007
Location: Basel
Posts: 8,188
Groaned at 50 Times in 44 Posts
Thanked 8,034 Times in 2,942 Posts
mirfield has a reputation beyond reputemirfield has a reputation beyond reputemirfield has a reputation beyond reputemirfield has a reputation beyond reputemirfield has a reputation beyond reputemirfield has a reputation beyond repute
Re: How Secure is a Random URL?

Quote:
View Post
How basic are we talking? Any current browser can access the web based google drive no?
Ah, but I trust google with my data less than I trust random hackers.

But it's probably an option.
Reply With Quote
  #14  
Old 12.05.2015, 18:06
dodgyken's Avatar
Forum Legend
 
Join Date: Apr 2010
Location: Democratic Republic Kenistan
Posts: 9,783
Groaned at 340 Times in 276 Posts
Thanked 17,381 Times in 6,645 Posts
dodgyken has a reputation beyond reputedodgyken has a reputation beyond reputedodgyken has a reputation beyond reputedodgyken has a reputation beyond reputedodgyken has a reputation beyond reputedodgyken has a reputation beyond repute
Re: How Secure is a Random URL?

I will email stuff to myself and then open it on the phone and file it so that is definitely available on a device while away.

There are other ways of doing it, and of course my phone could be stolen - but everything else seems to be a little less KISS
Reply With Quote
This user would like to thank dodgyken for this useful post:
  #15  
Old 12.05.2015, 18:17
newtoswitz's Avatar
Forum Veteran
 
Join Date: Jan 2010
Location: Rapperswil
Posts: 1,158
Groaned at 15 Times in 13 Posts
Thanked 1,310 Times in 596 Posts
newtoswitz has a reputation beyond reputenewtoswitz has a reputation beyond reputenewtoswitz has a reputation beyond reputenewtoswitz has a reputation beyond repute
Re: How Secure is a Random URL?

There's no way to find the structure of a site if you don't serve it. This is probably more secure than putting them in an obvious place (e.g. website root) with a username & password, since any attack needs to know they are there to even start.

However without SSL everything is in the clear, so it depends how sensitive it may be to anything on the route (access points, network providers, firewall/routers).

You could also encrypt the stuff you've stored (e.g. zip), to get two levels of protection and also protect it on the wire.

Also don't serve a blank page, it shows you've done something. Ideally close the connection, or return a 500 server error, or serve a "New website welcome page" from a good web server - looks more like there's really nothing there
Reply With Quote
The following 2 users would like to thank newtoswitz for this useful post:
  #16  
Old 12.05.2015, 18:25
Phil_MCR's Avatar
Forum Legend
 
Join Date: Oct 2009
Location: Basel
Posts: 11,472
Groaned at 246 Times in 157 Posts
Thanked 13,326 Times in 5,676 Posts
Phil_MCR has a reputation beyond reputePhil_MCR has a reputation beyond reputePhil_MCR has a reputation beyond reputePhil_MCR has a reputation beyond reputePhil_MCR has a reputation beyond reputePhil_MCR has a reputation beyond repute
Re: How Secure is a Random URL?

there's a radical new invention which allows storage of gigabytes: the usb stick.

add one onto your keychain.

https://www.digitec.ch/en/s1/product...-stick-3230158
Reply With Quote
  #17  
Old 12.05.2015, 18:43
newtoswitz's Avatar
Forum Veteran
 
Join Date: Jan 2010
Location: Rapperswil
Posts: 1,158
Groaned at 15 Times in 13 Posts
Thanked 1,310 Times in 596 Posts
newtoswitz has a reputation beyond reputenewtoswitz has a reputation beyond reputenewtoswitz has a reputation beyond reputenewtoswitz has a reputation beyond repute
Re: How Secure is a Random URL?

Just also read the bit about not wanting zip - in that case use an encrypted PDF, it's pretty global.

The disadvantage is it's a pain to extract something if you want to send it to someone - e.g. you need a scan of your driving license, it's much easier to forward as a JPG.

I also use 1Password - password store that syncs across devices, but it also supports attachments

Last edited by newtoswitz; 12.05.2015 at 18:45. Reason: 1Password added
Reply With Quote
This user would like to thank newtoswitz for this useful post:
  #18  
Old 12.05.2015, 19:49
NotAllThere's Avatar
Forum Legend
 
Join Date: Oct 2008
Location: Baselland
Posts: 8,967
Groaned at 140 Times in 122 Posts
Thanked 12,243 Times in 5,007 Posts
NotAllThere has a reputation beyond reputeNotAllThere has a reputation beyond reputeNotAllThere has a reputation beyond reputeNotAllThere has a reputation beyond reputeNotAllThere has a reputation beyond reputeNotAllThere has a reputation beyond repute
Re: How Secure is a Random URL?

Quote:
View Post
Just email them to yourself and save the email in a separate folder.
With unencrypted email, assume it can be read by anyone who wants to.

I'd use something like this: http://www.securesafe.com/assets/onl...cument+Storage
Reply With Quote
  #19  
Old 12.05.2015, 20:25
Jim2007's Avatar
Forum Veteran
 
Join Date: Jun 2006
Location: Kt. Bern
Posts: 2,086
Groaned at 34 Times in 32 Posts
Thanked 2,065 Times in 1,054 Posts
Jim2007 has a reputation beyond reputeJim2007 has a reputation beyond reputeJim2007 has a reputation beyond reputeJim2007 has a reputation beyond reputeJim2007 has a reputation beyond repute
Re: How Secure is a Random URL?

Quote:
View Post
Isn't a private dropbox folder the simplest of all? Or am I missing something?
Probably not, but then some people like to make life more complicated that it needs to be...
Reply With Quote
  #20  
Old 18.05.2015, 12:41
Junior Member
 
Join Date: Jan 2013
Location: Zürich
Posts: 61
Groaned at 6 Times in 1 Post
Thanked 19 Times in 15 Posts
Flatrate has no particular reputation at present
Re: How Secure is a Random URL?

Dropbox link will work from any web browser which can download a file. I guess you need that for your homebrewed solution too.

Here is an example of a troll face I uploaded.

https://dl.dropboxusercontent.com/s/...troll-face.png
Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
How secure is a CDI ( contract indeterminé ) in Switzerland? Glaceir1 Employment 8 16.03.2012 12:58
Zugites in Lucerne - random night of random shape cutting hackster Social events 0 18.09.2009 21:57
How long does it take for employer to secure permit? bozothedeathmachine Permits/visas/government 8 27.05.2007 05:46


All times are GMT +2. The time now is 18:22.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2016, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.1.0