Re: Online Service API keys



On Fri, 2015-10-09 at 17:41 +0300, Alberto Mardegan wrote:
Unless Yorba manifests some interest in getting the Facebook
integration 
fixed in Shotwell, would GNOME be willing to takeover the project,
and 
consequently the associated Facebook application key?

To be clear, Shotwell is a GNOME project since it was recently moved to
git.gnome.org. But it's clearly not being developed anymore, so I would
not expect to see any fixes for it unless someone volunteers to help
maintain it. I agree with Bastien, the solution to this problem is for
Shotwell to use gnome-online-accounts rather than a separate API key.

Be warned there is a serious security issue which I've been meaning to
fix but haven't managed to yet: it doesn't verify TLS certificates [1],
so it's easy to get your Facebook password and session cookies. So even
if someone does fix the Facebook integration, you really should not use
it.

Michael

[1] https://bugzilla.gnome.org/show_bug.cgi?id=754488


[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]