phpBB doesn't strip image metadata

About this bulletin board and the Pale Moon website

Moderators: satrow, Lootyhoof, FranklinDM

User avatar
F22 Simpilot
Lunatic
Lunatic
Posts: 432
Joined: 2019-01-06, 07:59
Location: From RLG fly heading 053 intercept 315 DVV look for the SAM

phpBB doesn't strip image metadata

Unread post by F22 Simpilot » 2019-11-07, 08:57

Also, phpBB doesn't strip metadata from images by default. Look in the phpbb folder/plupload/plupload.php file line 269. Add this:

Code: Select all

'resize: {width: %d, height: %d, quality: 85,preserve_headers: false},',
If you're that smart and act like a dork, then you're not that smart after all. :geek:

axlil://xagryje.vse/itwkphvv-322

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 24822
Joined: 2011-08-28, 17:27
Location: 58°2'16"N 14°58'31"E
Contact:

Re: Own a Fitbit?

Unread post by Moonchild » 2019-11-07, 09:20

F22 Simpilot wrote:
2019-11-07, 08:57
Also, phpBB doesn't strip metadata from images by default. Look in the phpbb folder/plupload/plupload.php file line 269. Add this:

Code: Select all

'resize: {width: %d, height: %d, quality: 85,preserve_headers: false},',
No. If you don't want metadata published then you should strip it before uploading.
I'm not having the board re-encoding images at an arbitrary quality factor either. That's just bad form, touching what people upload like that.
"If you want to build a better world for yourself, you have to be willing to build one for everybody." -- Coyote Osborne
Image

User avatar
F22 Simpilot
Lunatic
Lunatic
Posts: 432
Joined: 2019-01-06, 07:59
Location: From RLG fly heading 053 intercept 315 DVV look for the SAM

Re: Own a Fitbit?

Unread post by F22 Simpilot » 2019-11-07, 10:56

Then change the quality to 100. The main line here is the

Code: Select all

preserve_headers: false
It's a major security/privacy issue with metadata and many people may not know of this and willy nilly upload a smartphone pic with their GPS coordinates attached.

See here: https://www.phpbb.com/community/viewtop ... &t=2528176
If you're that smart and act like a dork, then you're not that smart after all. :geek:

axlil://xagryje.vse/itwkphvv-322

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 24822
Joined: 2011-08-28, 17:27
Location: 58°2'16"N 14°58'31"E
Contact:

Re: phpBB doesn't strip image metadata

Unread post by Moonchild » 2019-11-07, 14:27

F22 Simpilot wrote:
2019-11-07, 10:56
Then change the quality to 100.
No. It'd still be recoding the uploaded content; in addition, you'd run the risk of someone uploading a crafted image that will inflate something fierce when recoded to q=1.0, bypassing the normal upload size restrictions for uploads.

And I'm aware of the potential privacy issue with metadata (there is no security issue here, please don't lump the two together) but that is still up to the uploader to clear if they are concerned about it. Metadata is also used for more things than just GPS coordinates on smartphone-sourced pics, including important image data for e.g. print reproduction, color correction or copyright information, and I don't want to strip that either.
"If you want to build a better world for yourself, you have to be willing to build one for everybody." -- Coyote Osborne
Image

User avatar
Konrad
Moon lover
Moon lover
Posts: 91
Joined: 2018-11-17, 18:19

Re: Own a Fitbit?

Unread post by Konrad » 2019-11-07, 18:48

Moonchild wrote:
2019-11-07, 09:20
If you don't want metadata published then you should strip it before uploading.
I think it’s more than obvious even to unadvanced users like me.
And a website does not have to be a filter-of-all-faults.

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 24822
Joined: 2011-08-28, 17:27
Location: 58°2'16"N 14°58'31"E
Contact:

Re: phpBB doesn't strip image metadata

Unread post by Moonchild » 2019-11-07, 20:26

Anyway, thanks for drawing attention to this. Looks like phpBB has been stripping metadata unknowingly because of an undocumented update in one of the later phpBB 3.2 versions that would trigger a recode even if the original image didn't have to be recoded (size and resolution not exceeding max). That has now been fixed.
"If you want to build a better world for yourself, you have to be willing to build one for everybody." -- Coyote Osborne
Image

User avatar
F22 Simpilot
Lunatic
Lunatic
Posts: 432
Joined: 2019-01-06, 07:59
Location: From RLG fly heading 053 intercept 315 DVV look for the SAM

Re: phpBB doesn't strip image metadata

Unread post by F22 Simpilot » 2019-11-08, 22:15

Where is that Info. so I can have a look at it.
If you're that smart and act like a dork, then you're not that smart after all. :geek:

axlil://xagryje.vse/itwkphvv-322

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 24822
Joined: 2011-08-28, 17:27
Location: 58°2'16"N 14°58'31"E
Contact:

Re: phpBB doesn't strip image metadata

Unread post by Moonchild » 2019-11-08, 22:22

Where do you think? In the very thread on the phpBB forum you linked to.
"If you want to build a better world for yourself, you have to be willing to build one for everybody." -- Coyote Osborne
Image

User avatar
F22 Simpilot
Lunatic
Lunatic
Posts: 432
Joined: 2019-01-06, 07:59
Location: From RLG fly heading 053 intercept 315 DVV look for the SAM

Re: phpBB doesn't strip image metadata

Unread post by F22 Simpilot » 2019-11-08, 22:29

Odd, I don't recall reading that there. I'll go over it again. I tested with the upload of a photo from my phone to my own board and the metadata was intact. Using 3.2.8. I've since added that plupload code and that does strip the metadata.
If you're that smart and act like a dork, then you're not that smart after all. :geek:

axlil://xagryje.vse/itwkphvv-322

User avatar
F22 Simpilot
Lunatic
Lunatic
Posts: 432
Joined: 2019-01-06, 07:59
Location: From RLG fly heading 053 intercept 315 DVV look for the SAM

Re: Own a Fitbit?

Unread post by F22 Simpilot » 2019-11-08, 22:31

Konrad wrote:
2019-11-07, 18:48
Moonchild wrote:
2019-11-07, 09:20
If you don't want metadata published then you should strip it before uploading.
I think it’s more than obvious even to unadvanced users like me.
And a website does not have to be a filter-of-all-faults.
Social media now strips metadata due to this issue. Can you imagine if they left it intact? Like web stalkers and shit?
If you're that smart and act like a dork, then you're not that smart after all. :geek:

axlil://xagryje.vse/itwkphvv-322

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 24822
Joined: 2011-08-28, 17:27
Location: 58°2'16"N 14°58'31"E
Contact:

Re: phpBB doesn't strip image metadata

Unread post by Moonchild » 2019-11-09, 08:03

F22 Simpilot wrote:
2019-11-08, 22:31
Social media now strips metadata due to this issue.
Social media is used with direct sharing from mobile devices where stripping this data before upload is difficult; requirements are different there.
"If you want to build a better world for yourself, you have to be willing to build one for everybody." -- Coyote Osborne
Image

Post Reply