This post originated from an RSS feed registered with Java Buzz
by dion.
Original Post: Links for 2009-03-25 [del.icio.us]
Feed Title: techno.blog(Dion)
Feed URL: http://feeds.feedburner.com/dion
Feed Description: blogging about life the universe and everything tech
Amazon Wish Lists Are Dreadfully Insecure - kentbrewster.com
"Old friends may remember the How to Tell if a User is Signed In to Service X series, which ended last year around this time. As you can see from the comments in Patching Privacy Leaks, I advised users to sign out of Amazon.com on 17 October 2008, but did not say why.
Six months and multiple warnings later, nothing's been done. So here it is:
If you are signed in to the United States version of Amazon.com and have a wish list, the button should add an item."