<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Internet Business &#38; Marketing Strategy - Andy Beard &#187; yahoo contact api</title>
	<atom:link href="http://andybeard.eu/tag/yahoo-contact-api/feed" rel="self" type="application/rss+xml" />
	<link>http://andybeard.eu</link>
	<description>Internet Marketing, Lead Acquisition, Online Business Strategy and Social Media with Original Opinion and Loads of Attitude</description>
	<lastBuildDate>Sun, 12 Feb 2012 06:16:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Opt-in Accelerator Warning &#8211; Security Risk &#8211; Read This First!</title>
		<link>http://andybeard.eu/1472/opt-in-accelerator-warning-security-risk-read-this-first.html</link>
		<comments>http://andybeard.eu/1472/opt-in-accelerator-warning-security-risk-read-this-first.html#comments</comments>
		<pubDate>Mon, 23 Jun 2008 12:00:55 +0000</pubDate>
		<dc:creator>Andy Beard</dc:creator>
				<category><![CDATA[blogging tips]]></category>
		<category><![CDATA[marketing]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[google contacts api]]></category>
		<category><![CDATA[oath]]></category>
		<category><![CDATA[optin accelerator]]></category>
		<category><![CDATA[plurk]]></category>
		<category><![CDATA[tell-a-friend]]></category>
		<category><![CDATA[tellafriend]]></category>
		<category><![CDATA[TrafficXplode]]></category>
		<category><![CDATA[viral inviter]]></category>
		<category><![CDATA[viral optin generator]]></category>
		<category><![CDATA[windows live connect api]]></category>
		<category><![CDATA[yahoo contact api]]></category>
		<category><![CDATA[yahoo mail]]></category>
		<category><![CDATA[ymail]]></category>

		<guid isPermaLink="false">http://andybeard.eu/2008/06/opt-in-accelerator-warning-security-risk-read-this-first.html</guid>
		<description><![CDATA[Optin Accelerator is a massive security risk for your customers - rather than fix the security problems, the new version just adds fluff without addressing core issues.

Anyone can make a mistake, release a product without considering all the possible ramifications, but to release Opt-in Accelerator again without major changes is irresponsible.

<h3>The Irresponsible Viral Tell-A-Friend Trio</h3>

So far there have been 3 such scripts I have written about, and there is a 4th "coming soon"
<ul>
	<li>My first coverage of <a href="http://andybeard.eu/2008/04/optin-accelerator-closed-too-risky.html">Opt-in Accelerator</a></li>
	<li>Then there was <a href="http://andybeard.eu/2008/04/viral-optin-generator-warning.html">Viral Optin Generator</a> which may well have been a private label or resale rights product</li>
	<li><a href="http://andybeard.eu/2008/06/how-to-screw-up-your-internet-business.html">Viral Inviter</a> is launching soon - last I saw of this script installed "out in the wild" it was a security risk</li>
	<li>There is another one I know about, TrafficXplode 2.0 which also features the same security risks</li>
</ul>]]></description>
			<content:encoded><![CDATA[
<p>Optin Accelerator is a massive security risk for your customers &#8211; rather than fix the security problems, the new version just adds fluff without addressing core issues.</p>
<p>Anyone can make a mistake, release a product without considering all the possible ramifications, but to release Opt-in Accelerator again without major changes is irresponsible.</p>
<h3>The Irresponsible Viral Tell-A-Friend Trio</h3>
<p>So far there have been 3 such scripts I have written about, and there is a 4th &#8220;coming soon&#8221;</p>
<ul>
<li>My first coverage of <a href="http://andybeard.eu/2008/04/optin-accelerator-closed-too-risky.html">Opt-in Accelerator</a></li>
<li>Then there was <a href="http://andybeard.eu/2008/04/viral-optin-generator-warning.html">Viral Optin Generator</a> which may well have been a private label or resale rights product</li>
<li><a href="http://andybeard.eu/2008/06/how-to-screw-up-your-internet-business.html">Viral Inviter</a> is launching soon &#8211; last I saw of this script installed &#8220;out in the wild&#8221; it was a security risk</li>
<li>There is another one I know about, TrafficXplode 2.0 which also features the same security risks</li>
</ul>
<h3>Relook @ Opt-In Accelerator</h3>
<p><img src='http://cdn5.andybeard.name/wp-content/uploads/optin-accelerator.jpg' alt='Opt-in Accelerator' /></p>
<p>You see that big red circle I added?</p>
<p>That is the key to unlocking:-</p>
<ul>
<li>Your Email</li>
<li>Your Google Adsense Account</li>
<li>Your Google Adwords Account</li>
<li>Google Analytics</li>
<li>Google Website Optimizer</li>
<li>Your PayPal Account</li>
<li>Affiliate program passwords</li>
<li>Access Your Blogger account</li>
<li>Access any scripts that allow you to resend or reset passwords</li>
<li>Open any social media profile that used that email address</li>
<li>Did you use that address for domain records? Wave goodbye to your domains</li>
</ul>
<p>I am not claiming that anyone creating such as script is dishonest, or even the people who might use them, but it takes a huge investment of manpower and financial muscle to keep personal data secure, and those are things most internet marketers don&#8217;t have.</p>
<p>All it takes is a script kiddie to come along and compromise the script running on your server, and then rather than acting as an &#8220;innocent&#8221; tell-a-friend script to boost your email subscribers, it would collect login and password information and forward it to an anonymous server.</p>
<p><b>All it would take is 2 lines of additional code</b></p>
<p>We will ignore many of the other potential problems with scraping the email services <a href="http://www.robertplank.com/optin-accelerator/#comment-625">against their terms of service</a>, potentially breaking the terms of the autoresponder service you use, or totally trashing your email deliverability as 100s of people flag your messages as spam.</p>
<p>I think Robert Plank covered <a href="http://www.robertplank.com/optin-accelerator/">that aspect of Opt-in Accelerator</a> quite adequately.</p>
<h3>Solutions</h3>
<p>Password data should never be entered in an insecure form hosted by someone without exceptional security in place.</p>
<h3>Very Simple Mail To:</h3>
<p>This example from Plurk (they also use the insecure method, and have been accused of spam with their Facebook implementation)</p>
<pre class="brush: plain; title: ; notranslate">

http://mail.google.com/mail/?view=cm&#038;cmid=0&#038;fs=1&#038;su=Invitation+to+Plurk.com&#038;body=I+have+been+using+Plurk+and+I+think+you+should+check+it+out%21%0A%0AAccept+my+invitation+by+going+to%3A%0Ahttp%3A%2F%2Fplurk.com%2FredeemByURL%3Ffrom_uid%3D15547%26check%3D-1998160234%26s%3D2%0A%0ACheck+out+my+profile+at%3A%0Ahttp%3A%2F%2Fwww.plurk.com%2Fuser%2Fandybeard%0A%0APlurk.com+-+Your+life%2C+on+the+line&#038;tearoff=1&#038;shva=1&#038;ui=1

http://compose.mail.yahoo.com/?Subj=Invitation+to+Plurk.com&#038;Body=I+have+been+using+Plurk+and+I+think+you+should+check+it+out%21+Accept+my+invitation+by+going+to%3A+http%3A%2F%2Fplurk.com%2FredeemByURL%3Ffrom_uid%3D15547%26check%3D-1998160234%26s%3D2.+Check+out+my+profile+by+going+to%3A+http%3A%2F%2Fwww.plurk.com%2Fuser%2Fandybeard

http://www.hotmail.msn.com/secure/start?action=compose&#038;subject=Invitation+to+Plurk.com&#038;body=I+have+been+using+Plurk+and+I+think+you+should+check+it+out%21%0A%0AAccept+my+invitation+by+going+to%3A%0Ahttp%3A%2F%2Fplurk.com%2FredeemByURL%3Ffrom_uid%3D15547%26check%3D-1998160234%26s%3D2%0A%0ACheck+out+my+profile+at%3A%0Ahttp%3A%2F%2Fwww.plurk.com%2Fuser%2Fandybeard%0A%0APlurk.com+-+Your+life%2C+on+the+line
</pre>
<p>This code is wonderful because people use their own email server to send the emails, no strain on your servers, so it could be used on any server, even a shared account which has limitations on how many emails you can send per hour.</p>
<h3>Existing APIs</h3>
<p>Google Yahoo and Microsoft also have APIs for this kind of stuff which can also be used for finding friends.</p>
<p><a href="http://code.google.com/apis/contacts/">Google Contacts API</a><br />
<a href="http://developer.yahoo.com/addressbook/">Yahoo! Contact API</a><br />
<a href="http://msdn.microsoft.com/en-us/library/bb463989.aspx">Windows Live Contact API</a></p>
<p>I should also mention the <a href="http://blog.oauth.net/2008/06/05/an-opportunity-for-oauth-jeff-codinghorror-atwood-highlights-the-password-anti-pattern/">ongoing Oath efforts</a> being made to create a unified interface for retrieving contact and other personal information with permission.</p>
<p>To be fair, I am going to give Jason a link with some <a href="http://www.bigmarketingonline.com/optin-accelerator-controversy.html">partial counter arguments</a>. He seems to think it is worth the risk.</p>
<p>The problem with that argument is that there is no need for this to be a security risk. It is just <a href="http://www.codinghorror.com/blog/archives/001128.html">junk programming</a>.</p>
<div class="topsy_widget_data topsy_theme_brick-red" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fandybeard.eu%252F1472%252Fopt-in-accelerator-warning-security-risk-read-this-first.html%22%2C%20%22style%22%3A%20%22small%22%2C%20%22title%22%3A%20%22Opt-in%20Accelerator%20Warning%20-%20Security%20Risk%20-%20Read%20This%20First%21%22%20%7D);"></div>


	Tags: <a href="http://andybeard.eu/tag/google" title="Google" rel="tag">Google</a>, <a href="http://andybeard.eu/tag/google-contacts-api" title="google contacts api" rel="tag">google contacts api</a>, <a href="http://andybeard.eu/tag/oath" title="oath" rel="tag">oath</a>, <a href="http://andybeard.eu/tag/optin-accelerator" title="optin accelerator" rel="tag">optin accelerator</a>, <a href="http://andybeard.eu/tag/plurk" title="plurk" rel="tag">plurk</a>, <a href="http://andybeard.eu/tag/tell-a-friend" title="tell-a-friend" rel="tag">tell-a-friend</a>, <a href="http://andybeard.eu/tag/tellafriend" title="tellafriend" rel="tag">tellafriend</a>, <a href="http://andybeard.eu/tag/trafficxplode" title="TrafficXplode" rel="tag">TrafficXplode</a>, <a href="http://andybeard.eu/tag/viral-inviter" title="viral inviter" rel="tag">viral inviter</a>, <a href="http://andybeard.eu/tag/viral-optin-generator" title="viral optin generator" rel="tag">viral optin generator</a>, <a href="http://andybeard.eu/tag/windows-live-connect-api" title="windows live connect api" rel="tag">windows live connect api</a>, <a href="http://andybeard.eu/tag/yahoo-contact-api" title="yahoo contact api" rel="tag">yahoo contact api</a>, <a href="http://andybeard.eu/tag/yahoo-mail" title="yahoo mail" rel="tag">yahoo mail</a>, <a href="http://andybeard.eu/tag/ymail" title="ymail" rel="tag">ymail</a><br />
]]></content:encoded>
			<wfw:commentRss>http://andybeard.eu/1472/opt-in-accelerator-warning-security-risk-read-this-first.html/feed</wfw:commentRss>
		<slash:comments>63</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using disk: basic
Database Caching 30/43 queries in 0.008 seconds using disk: basic
Object Caching 670/698 objects using disk: basic
Content Delivery Network via cdn5.andybeard.name

Served from: andybeard.eu @ 2012-02-13 07:11:44 -->
