people page 8 - Dave's Blog

Search
My timeline on Mastodon

Beach View

2009 May 22, 12:10

sequelguy posted a photo:

Beach View

PermalinkComments

Sanctuary Beach Resort

2009 May 22, 12:10

sequelguy posted a photo:

Sanctuary Beach Resort

PermalinkCommentscalifornia hotel

Sanctuary Beach Resort

2009 May 22, 12:10

sequelguy posted a photo:

Sanctuary Beach Resort

PermalinkCommentscalifornia hotel

The Clement Hotel, Monterey

2009 May 22, 12:10

sequelguy posted a photo:

The Clement Hotel, Monterey

PermalinkCommentscalifornia hotel monterey

The Clement Hotel, Monterey

2009 May 22, 12:10

sequelguy posted a photo:

The Clement Hotel, Monterey

PermalinkCommentscalifornia hotel monterey

Highlands Inn, Carmel

2009 May 22, 12:10

sequelguy posted a photo:

Highlands Inn, Carmel

PermalinkCommentscalifornia hotel carmel highlandsinn

Highlands Inn, Carmel

2009 May 22, 12:09

sequelguy posted a photo:

Highlands Inn, Carmel

PermalinkCommentscalifornia hotel carmel highlandsinn

New House Looking Out At Driveway

2009 May 22, 11:26

sequelguy posted a photo:

New House Looking Out At Driveway

PermalinkCommentshouse window washington driveway redmond

New House Exterior

2009 May 22, 11:26

sequelguy posted a photo:

New House Exterior

PermalinkCommentstrees house home washington redmond

Netflix CSRF - Stolen Thoughts

2009 May 3, 10:36

Looking at the HTTP traffic of Netflix under Fiddler I could see the HTTP request that added a movie to my queue and didn't see anything obvious that would prevent a CSRF. Sure enough its pretty easy to create a page that, if the user has set Netflix to auto-login, will add movies to the user's queue without their knowledge. I thought this was pretty neat, because I could finally get people to watch Primer. However, when I searched for Netflix CSRF I found that this issue has been known and reported to Netflix since 2006. Again my thoughts stolen from me and the theif doesn't even have the common decency to let me have the thought first!

With this issue known for nearly three years its hard to continue calling it an issue. Really they should just document it in their API docs and be done with it. Who knows what Netflix based web sites and services they'll break if they try to change this behavior? For instance, follow this link to add my Netflix recommended movies to your queue.

PermalinkCommentstechnical stolen-thoughts csrf netflix security

Red Tulips and School Bus

2009 May 2, 8:43

sequelguy posted a photo:

Red Tulips and School Bus

PermalinkCommentsflower bus washington tulip schoolbus

Purple Tulips

2009 May 2, 8:42

sequelguy posted a photo:

Purple Tulips

PermalinkCommentsflower washington tulip

Purple Tulip

2009 May 2, 8:42

sequelguy posted a photo:

Purple Tulip

PermalinkCommentsflower washington tulip

Tulips and Crates

2009 May 2, 8:41

sequelguy posted a photo:

Tulips and Crates

PermalinkCommentsflower washington tulip crate

Ladybug

2009 May 2, 8:41

sequelguy posted a photo:

Ladybug

PermalinkCommentswashington ladybug

Sarah and Tulips

2009 May 2, 8:41

sequelguy posted a photo:

Sarah and Tulips

PermalinkCommentsflower sarah washington tulip

Super Pose in Front of Tulips

2009 May 2, 8:40

sequelguy posted a photo:

Super Pose in Front of Tulips

PermalinkCommentsflower me washington tulip

Red Tulip

2009 May 2, 8:40

sequelguy posted a photo:

Red Tulip

PermalinkCommentsred flower washington tulip

Red Tulips

2009 May 2, 1:43

sequelguy posted a photo:

Red Tulips

PermalinkCommentsflower washington tulip

1240086067925

2009 Apr 23, 10:33

sequelguy posted a photo:

1240086067925

PermalinkCommentscalifornia napa
Older EntriesNewer Entries Creative Commons License Some rights reserved.