> No, it is not only with root access. It is with user access. Permission 
> is irrelevant to the problem. Most of these removable media come 
> straight out of digital cameras that use FAT.

The FS of the source is irrelevant.

And it *is* only you or root who can access these thumbnails. Otherwise,
your $HOME's permissions are either borked or set explicitly and

> The problem in the first place is the creation of thumbnails in any 
> other place than the same folder (with the same permissions, if 
> applicable) as the originals.
> What happens if ten users access the same images from a network drive? 
> Just another consequence...
> The right design is to keep the thumbs on the same media where the 
> originals are (and if applicable with same permissions as far as 
> user/root access is concerned).

No. Random application (let's assume a default Win XP) does not know
about the location of these thumbnails. It will not care about them. It
will not remove them along with the originals. Tada -- you got your
privacy concerned images saved as thumbnails for the unforeseeable
future on the media, readable by *everyone* who gets access to that
media after the user believed the images to have been removed.

Now *this* is a privacy nightmare. My $HOME is not.


