<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Forgetful Flickr</title>
	<atom:link href="http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/feed/" rel="self" type="application/rss+xml" />
	<link>http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/</link>
	<description>Things that Eric A. Meyer, CSS expert, writes about on his personal Web site; it&#039;s largely Web standards and Web technology, but also various bits of culture, politics, personal observations, and other miscellaneous stuff</description>
	<lastBuildDate>Fri, 19 Mar 2010 00:27:46 -0400</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Eric Meyer</title>
		<link>http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-42432</link>
		<dc:creator>Eric Meyer</dc:creator>
		<pubDate>Fri, 11 Aug 2006 07:40:20 +0000</pubDate>
		<guid isPermaLink="false">http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-42432</guid>
		<description>Derek:  Wait, so you&#039;re telling me that this behavior a core feature of Flickr, and not just a limitation born of not having worked on authenticated RSS feeds?  Because it seems very strange that photos I can see on a web page don&#039;t show up in an RSS feed of what&#039;s on that page.  (And when the wise man posted that, he was talking about core features of a system.)

Okay, so I get that there are extra security concerns with feeds than there are with viewing pages, but I still don&#039;t see how that can be regarded as a &quot;feature&quot;.  Unless it&#039;s a feature to force users to the Flickr site every now and again, just to see if there&#039;s something their RSS feed has failed to inform them they can see.

Could the feed at least say that there&#039;s a private photo available, without including said image the actual feed, so that we know when to go look?</description>
		<content:encoded><![CDATA[<p>Derek:  Wait, so you&#8217;re telling me that this behavior a core feature of Flickr, and not just a limitation born of not having worked on authenticated RSS feeds?  Because it seems very strange that photos I can see on a web page don&#8217;t show up in an RSS feed of what&#8217;s on that page.  (And when the wise man posted that, he was talking about core features of a system.)</p>
<p>Okay, so I get that there are extra security concerns with feeds than there are with viewing pages, but I still don&#8217;t see how that can be regarded as a &#8220;feature&#8221;.  Unless it&#8217;s a feature to force users to the Flickr site every now and again, just to see if there&#8217;s something their RSS feed has failed to inform them they can see.</p>
<p>Could the feed at least say that there&#8217;s a private photo available, without including said image the actual feed, so that we know when to go look?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Derek Powazek</title>
		<link>http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-42411</link>
		<dc:creator>Derek Powazek</dc:creator>
		<pubDate>Fri, 11 Aug 2006 01:25:44 +0000</pubDate>
		<guid isPermaLink="false">http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-42411</guid>
		<description>Making photos private means keeping them out of public view. As a wise man recently posted: &quot;Accept it and move on, or reject it and walk away, but don&quot;t waste your time complaining about it.&quot;

I consider having my private photos kept out of RSS a feature, not a bug.</description>
		<content:encoded><![CDATA[<p>Making photos private means keeping them out of public view. As a wise man recently posted: &#8220;Accept it and move on, or reject it and walk away, but don&#8221;t waste your time complaining about it.&#8221;</p>
<p>I consider having my private photos kept out of RSS a feature, not a bug.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Meriblog: Meri Williams&#8217; Weblog &#187; links for 2006-08-02</title>
		<link>http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-41291</link>
		<dc:creator>Meriblog: Meri Williams&#8217; Weblog &#187; links for 2006-08-02</dc:creator>
		<pubDate>Thu, 03 Aug 2006 08:07:41 +0000</pubDate>
		<guid isPermaLink="false">http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-41291</guid>
		<description>[...] Bloglines &#124; News Cool &#8212; looks like Bloglines are taking on feed access control head-on, which I&#8217;m sure Eric might be pleased to here. Now we just need the Flickr guys to make the same change (tags: flickr rss privacy photos) [...]</description>
		<content:encoded><![CDATA[<p>[...] Bloglines | News Cool &#8212; looks like Bloglines are taking on feed access control head-on, which I&#8217;m sure Eric might be pleased to here. Now we just need the Flickr guys to make the same change (tags: flickr rss privacy photos) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric Meyer</title>
		<link>http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-38711</link>
		<dc:creator>Eric Meyer</dc:creator>
		<pubDate>Thu, 06 Jul 2006 15:29:00 +0000</pubDate>
		<guid isPermaLink="false">http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-38711</guid>
		<description>I &lt;strong&gt;never&lt;/strong&gt; said that I don&#039;t really care about privacy.  I said that I understand that placing photos on a server is already a privacy risk, and using a random-token obscurity approach didn&#039;t seem a huge additional risk.  However, Drew pointed out something I hadn&#039;t considered regarding multi-user aggregators, so I have a different point of view now.

I&#039;m totally happy with an https solution.  Many RSS clients support username/password combinations over https connections, so it&#039;s something Flickr could offer-- in other words, the part of the problem that Flickr can resolve hasn&#039;t been resolved, whereas the other half has been.</description>
		<content:encoded><![CDATA[<p>I <strong>never</strong> said that I don&#8217;t really care about privacy.  I said that I understand that placing photos on a server is already a privacy risk, and using a random-token obscurity approach didn&#8217;t seem a huge additional risk.  However, Drew pointed out something I hadn&#8217;t considered regarding multi-user aggregators, so I have a different point of view now.</p>
<p>I&#8217;m totally happy with an https solution.  Many RSS clients support username/password combinations over https connections, so it&#8217;s something Flickr could offer&#8211; in other words, the part of the problem that Flickr can resolve hasn&#8217;t been resolved, whereas the other half has been.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Isaac Lin</title>
		<link>http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-38710</link>
		<dc:creator>Isaac Lin</dc:creator>
		<pubDate>Thu, 06 Jul 2006 15:17:12 +0000</pubDate>
		<guid isPermaLink="false">http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-38710</guid>
		<description>It would be misleading for Flickr to provide a half-baked privacy solution, so I disagree with just using randomly generated URLs as a &quot;security through obscurity&quot; solution.

If you don&#039;t really care about privacy, then wouldn&#039;t it be sufficient to leave the photos as public, but to tag it with some kind of FamilyAndFriends tag? (Flickr could help automate the application of this tag.)

Both your and Jeffrey&#039;s suggestions about having private information available through an RSS feed falls into the trap of thinking of RSS as a push delivery method. With its current design, though, the RSS clients would have to support authentication (say, an HTTPS connection with your Flickr password stored in the RSS client). So it isn&#039;t something solely under the control of Flickr to resolve.</description>
		<content:encoded><![CDATA[<p>It would be misleading for Flickr to provide a half-baked privacy solution, so I disagree with just using randomly generated URLs as a &#8220;security through obscurity&#8221; solution.</p>
<p>If you don&#8217;t really care about privacy, then wouldn&#8217;t it be sufficient to leave the photos as public, but to tag it with some kind of FamilyAndFriends tag? (Flickr could help automate the application of this tag.)</p>
<p>Both your and Jeffrey&#8217;s suggestions about having private information available through an RSS feed falls into the trap of thinking of RSS as a push delivery method. With its current design, though, the RSS clients would have to support authentication (say, an HTTPS connection with your Flickr password stored in the RSS client). So it isn&#8217;t something solely under the control of Flickr to resolve.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Drew McLellan</title>
		<link>http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-38568</link>
		<dc:creator>Drew McLellan</dc:creator>
		<pubDate>Tue, 04 Jul 2006 11:48:43 +0000</pubDate>
		<guid isPermaLink="false">http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-38568</guid>
		<description>One issue with using unguessable tokens in the URL is that multi-user aggregators often share feeds amongst their users in order to prevent multiple fetches of the same content. Therefore its possible that a &#039;secret&#039; feed is presented as an option to users for whom it was never intended. 

Plus, ultimately any URL that you&#039;re requesting once an hour and is being sent clear over the wire and logged in dozens of log files along the way is no secret at all.</description>
		<content:encoded><![CDATA[<p>One issue with using unguessable tokens in the URL is that multi-user aggregators often share feeds amongst their users in order to prevent multiple fetches of the same content. Therefore its possible that a &#8217;secret&#8217; feed is presented as an option to users for whom it was never intended. </p>
<p>Plus, ultimately any URL that you&#8217;re requesting once an hour and is being sent clear over the wire and logged in dozens of log files along the way is no secret at all.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: outbreak &#187; The little bumps of the first time user (written on July 3rd, 2006 by Marko Mrdjenovic)</title>
		<link>http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-38437</link>
		<dc:creator>outbreak &#187; The little bumps of the first time user (written on July 3rd, 2006 by Marko Mrdjenovic)</dc:creator>
		<pubDate>Sun, 02 Jul 2006 22:23:17 +0000</pubDate>
		<guid isPermaLink="false">http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-38437</guid>
		<description>[...] On a side note, there seems to be a lot going on about Flickr. I haven&#8217;t really used it ever, but I&#8217;m doing it while writing this - I&#8217;ve been trying to get around to posting my pics from @media for some time now. [...]</description>
		<content:encoded><![CDATA[<p>[...] On a side note, there seems to be a lot going on about Flickr. I haven&#8217;t really used it ever, but I&#8217;m doing it while writing this &#8211; I&#8217;ve been trying to get around to posting my pics from @media for some time now. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Meriblog: Meri Williams&#8217; Weblog &#187; links for 2006-06-29</title>
		<link>http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-38230</link>
		<dc:creator>Meriblog: Meri Williams&#8217; Weblog &#187; links for 2006-06-29</dc:creator>
		<pubDate>Fri, 30 Jun 2006 08:01:21 +0000</pubDate>
		<guid isPermaLink="false">http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-38230</guid>
		<description>[...] Eric&#8217;s Archived Thoughts: Forgetful Flickr Wouldn&#8217;t it be wonderful if just the simple desire to be able to see friend&#8217;s and families&#8217; photos in Flickr RSS feeds stimulated the Flickr team (who we all know design shit-hot stuff) to solve the problem of secure syndication? (tags: rss flickr design webdevelopment webapplications) [...]</description>
		<content:encoded><![CDATA[<p>[...] Eric&#8217;s Archived Thoughts: Forgetful Flickr Wouldn&#8217;t it be wonderful if just the simple desire to be able to see friend&#8217;s and families&#8217; photos in Flickr RSS feeds stimulated the Flickr team (who we all know design shit-hot stuff) to solve the problem of secure syndication? (tags: rss flickr design webdevelopment webapplications) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aristotle Pagaltzis</title>
		<link>http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-38170</link>
		<dc:creator>Aristotle Pagaltzis</dc:creator>
		<pubDate>Thu, 29 Jun 2006 03:02:16 +0000</pubDate>
		<guid isPermaLink="false">http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-38170</guid>
		<description>LiveJournal already does this well. If you subscribe to an LJ feed, you get only the person&quot;s public posts. But you can subscribe to a feed with &lt;code&gt;?auth=digest&lt;/code&gt; added to the URL, which requires you to supply an LJ account and password as HTTP credentials. When you poll such a feed it will contains all the items you could see if you visited the associated journal while logged into the account whose details you&quot;ve provided.

It&quot;s a no-brainer, really.</description>
		<content:encoded><![CDATA[<p>LiveJournal already does this well. If you subscribe to an LJ feed, you get only the person&#8221;s public posts. But you can subscribe to a feed with <code>?auth=digest</code> added to the URL, which requires you to supply an LJ account and password as HTTP credentials. When you poll such a feed it will contains all the items you could see if you visited the associated journal while logged into the account whose details you&#8221;ve provided.</p>
<p>It&#8221;s a no-brainer, really.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BenJ</title>
		<link>http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-38169</link>
		<dc:creator>BenJ</dc:creator>
		<pubDate>Thu, 29 Jun 2006 03:02:02 +0000</pubDate>
		<guid isPermaLink="false">http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-38169</guid>
		<description>Another solution might be separate feeds (or the same feed, for that matter) that provide a notice of private activity, letting you click through to authenticate and see whatever it is. Not quite as nice as the actual content, but better than nothing.</description>
		<content:encoded><![CDATA[<p>Another solution might be separate feeds (or the same feed, for that matter) that provide a notice of private activity, letting you click through to authenticate and see whatever it is. Not quite as nice as the actual content, but better than nothing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Porter</title>
		<link>http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-38155</link>
		<dc:creator>Porter</dc:creator>
		<pubDate>Wed, 28 Jun 2006 21:33:04 +0000</pubDate>
		<guid isPermaLink="false">http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-38155</guid>
		<description>This has bothered me, too, but authentication is indeed the problem, as Dave points out. A possible solution would be to allow friends &amp; family to see a different RSS URL that contained an &quot;unguessable&quot; token, which is good enough security for posting photos via email (&lt;a href=&quot;http://www.flickr.com/photos/adactio/122923214/&quot; rel=&quot;nofollow&quot;&gt;unless you&#039;re Jeremy&lt;/a&gt;).

But of course, that doesn&#039;t address handling people who you revoke &quot;friendship&quot; for still being subscribed to your secret feed, so you&#039;d need a different token for each person that could be revoked if you changed their contact status...</description>
		<content:encoded><![CDATA[<p>This has bothered me, too, but authentication is indeed the problem, as Dave points out. A possible solution would be to allow friends &amp; family to see a different RSS URL that contained an &#8220;unguessable&#8221; token, which is good enough security for posting photos via email (<a href="http://www.flickr.com/photos/adactio/122923214/" rel="nofollow">unless you&#8217;re Jeremy</a>).</p>
<p>But of course, that doesn&#8217;t address handling people who you revoke &#8220;friendship&#8221; for still being subscribed to your secret feed, so you&#8217;d need a different token for each person that could be revoked if you changed their contact status&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Edward</title>
		<link>http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-38154</link>
		<dc:creator>Edward</dc:creator>
		<pubDate>Wed, 28 Jun 2006 21:29:37 +0000</pubDate>
		<guid isPermaLink="false">http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-38154</guid>
		<description>As Dave has already said, RSS security isn&#039;t particularly, well, existent.  You can actually grab RSS feeds for anybody you want by checking out their ID in their Photostream feed and plugging that into the structure for the Recent Activity/Comments Made feed.

I&#039;ve actually appreciated that Flickr doesn&#039;t put those into the feeds.

Right on with the added tag thing, though.  That&#039;s something which would be nice to be able to keep a track of.</description>
		<content:encoded><![CDATA[<p>As Dave has already said, RSS security isn&#8217;t particularly, well, existent.  You can actually grab RSS feeds for anybody you want by checking out their ID in their Photostream feed and plugging that into the structure for the Recent Activity/Comments Made feed.</p>
<p>I&#8217;ve actually appreciated that Flickr doesn&#8217;t put those into the feeds.</p>
<p>Right on with the added tag thing, though.  That&#8217;s something which would be nice to be able to keep a track of.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave S.</title>
		<link>http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-38150</link>
		<dc:creator>Dave S.</dc:creator>
		<pubDate>Wed, 28 Jun 2006 20:41:50 +0000</pubDate>
		<guid isPermaLink="false">http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comment-38150</guid>
		<description>I don&#039;t know about you, but if I mark a photo friends or contacts only, I don&#039;t want the rest of the world to see it. On-site authentication prevents that from happening, but as far as I know, RSS security is still an oxymoron. 

Above and beyond HTTPS authentication -- which doesn&#039;t work universally amongst RSS readers -- the only other method of actually keeping a feed private is a unique, non-guessable URL. But that smacks of security through obscurity, and I&#039;m not inclined to trust private photos and comments to a method like that.

So, I agree with their current practice, at least in relation to RSS.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t know about you, but if I mark a photo friends or contacts only, I don&#8217;t want the rest of the world to see it. On-site authentication prevents that from happening, but as far as I know, RSS security is still an oxymoron. </p>
<p>Above and beyond HTTPS authentication &#8212; which doesn&#8217;t work universally amongst RSS readers &#8212; the only other method of actually keeping a feed private is a unique, non-guessable URL. But that smacks of security through obscurity, and I&#8217;m not inclined to trust private photos and comments to a method like that.</p>
<p>So, I agree with their current practice, at least in relation to RSS.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
        "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head profile="http://gmpg.org/xfn/1">
<title>meyerweb.com</title>
<link rel="openid.server" href="http://www.myopenid.com/server">
<link rel="openid.delegate" href="http://emeyer.myopenid.com/">
<meta http-equiv="Content-Type" content="text/html; charset=utf-8"><link rel="shortcut icon" href="/favicon.ico"><link rel="home" href="http://meyerweb.com/" title="Home" ><link rel="stylesheet" href="http://meyerweb.com/ui/meyerweb.css" type="text/css" media="screen, projection"><link rel="stylesheet" href="http://meyerweb.com/ui/theme.css" type="text/css" media="screen, projection" id="themeLink"><link rel="stylesheet" href="http://meyerweb.com/ui/print.css" type="text/css" media="print"><script src="http://meyerweb.com/ui/addresses.js" type="text/javascript"></script><link rel="stylesheet" href="/ui/wordpress.css" type="text/css" media="screen">
<link rel="stylesheet" href="/ui/tfe.css" type="text/css" media="screen">
<link rel="stylesheet" href="/ui/home.css" type="text/css" media="screen">
<link rel="alternate" type="application/rss+xml" title="Thoughts From Eric" href="/eric/thoughts/rss2/full" />
<link rel="alternate" type="application/rss+xml" title="Thoughts From Eric (only technical posts)" href="/eric/thoughts/category/tech/rss2/full" />
<link rel="alternate" type="application/rss+xml" title="Thoughts From Eric (only personal posts)" href="/eric/thoughts/category/personal/rss2/full" />
<link rel="alternate" type="application/rss+xml" title="Distractions" href="/eric/thoughts/recent-links/rss2" />
<link rel="alternate" type="application/rss+xml" title="Excuse of the Day" href="/feeds/excuse/rss20.xml" />
</head>
<body id="www-meyerweb-com" class="hpg">

<div id="sitemast"><h1><a href="/"><span>meyerweb</span>.com</a></h1></div><div id="search"><h4>Exploration</h4><!-- SiteSearch Google --><form method="get" action="http://www.google.com/custom" target="_top"><div><input type="hidden" name="domains" value="meyerweb.com"></input><label for="sbb" style="display: none">Submit search form</label><input type="submit" name="sa" value="Google Search" id="sbb"></input><label for="sbi" style="display: none">Enter your search terms</label><input type="text" name="q" size="31" maxlength="255" value="" id="sbi"></input><p><input type="radio" name="sitesearch" value="meyerweb.com" checked id="ss1"></input><label for="ss1" title="Search meyerweb.com">meyerweb.com</label><input type="radio" name="sitesearch" value="" id="ss0"></input><label for="ss0" title="Search the Web">Web</label></p><input type="hidden" name="client" value="pub-3772084027748653"></input><input type="hidden" name="forid" value="1"></input><input type="hidden" name="ie" value="ISO-8859-1"></input><input type="hidden" name="oe" value="ISO-8859-1"></input><input type="hidden" name="safe" value="active"></input><input type="hidden" name="cof" value="GALT:#008000;GL:1;DIV:#336699;VLC:663399;AH:center;BGC:FFFFFF;LBGC:336699;ALC:0000FF;LC:0000FF;T:000000;GFNT:0000FF;GIMP:0000FF;FORID:1"></input><input type="hidden" name="hl" value="en"></input></div></form><!-- SiteSearch Google --><!-- <form method="get" action="http://www.google.com/custom"><div><input type="submit" name="sa" value="Search"><input type="text" name="q" size="20" maxlength="255" value=""><input type="hidden" name="sitesearch" value="meyerweb.com"></div></form><small><a href="http://www.google.com/search">Powered by Google</a></small> --></div><div id="main"><div class="skipper">Skip to: <a href="#extra">site navigation/presentation</a></div><div class="skipper">Skip to: <a href="#thoughts">Thoughts From Eric</a></div>
<div id="thoughts">


<div class="entry">
<h3><a href="http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/" rel="bookmark" title="Permanent Link: Forgetful Flickr">Forgetful Flickr</a></h3>
<ul class="meta">
<li class="date">Wed 28 Jun 2006</li>
<li class="time">1618</li>
<li class="cat"><a href="http://meyerweb.com/eric/thoughts/category/tech/web/" title="View all posts in Web" rel="category tag">Web</a></li>
<li class="cmt"><a href="http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comments">13 responses</a></li>
<li></li><li></li></ul>

<div class="text">
<p>
<a href="http://zeldman.com/" rel="friend colleague met">Jeffrey</a> <a href="http://www.zeldman.com/2006/06/27/flickd-away/">wrote yesterday</a> about some <a href="http://flickr.com/">Flickr</a> problems he&#8217;s having, and while he&#8217;s found resolution, his post brought to my forebrain some problems I&#8217;ve been having with Flickr.  So I&#8217;ll record them here.  Wooo!  Flickr pile-on!
</p>
<p>
Actually, I really only have one problem, but it manifests itself in multiple ways.  The problem is this: any photo with a privacy setting other than &#8220;Public&#8221; doesn&#8217;t ever show up in Flickr RSS feeds.
</p>
<p>
Here&#8217;s why that&#8217;s a problem, instead of a good thing:
</p>

<ul>
<li>
<p>
If one of my contacts has marked me as a Friend, and they post a photo that&#8217;s visible only to Friends &amp; Family, that photo <strong>does not</strong> appear in my RSS feed of photos from my friends and family.  These same pictures show up if I go to the &#8220;Photos from your Contacts&#8221; page on the Flickr site.  In the feed, they&#8217;re entirely absent.
</p>
</li>
<li>
<p>
If I post a photo that&#8217;s visible only to Friends &amp; Family, any comments made on that photo <strong>do not</strong> appear in my &#8220;Comments on your photos and/or sets&#8221; feed.  So I don&#8217;t know what anyone&#8217;s saying about pictures of my wife and child unless I go to the &#8220;Recent activity on your photos&#8221; page on the Flickr site.
</p>
</li>
<li>
<p>
Bonus related limitation: only comments appear in my recent activity feed; things like added tags and favorite-photo designations don&#8217;t show up in the feeds either.  In fact, the feed link on the Flickr site says &#8220;Subscribe to recent activity on your photos&#8221; but the only activity shown in the feed is comments on public photos.
</p>
</li>
</ul>

<p>
There may be other, even more subtle hindrances in that vein, but those are the ones that have annoyed me the most.
</p>
<p>
So why is it that stuff I want to know about&#8212;in fact, the stuff that I probably want <em>most</em> to know about&#8212;is only available on the actual web site, and not in the RSS feeds?  Flickr knows exactly what it can show me and what it can&#8217;t when I visit the site, but when viewed through the lens of RSS, it suddenly forgets what non-public access I&#8217;m allowed to have.  To steal a perfectly appropriate line from Jeffrey&#8217;s post:
</p>

<blockquote>
<p>
A user experience mistake like this feels quadruply wrong precisely because user experience is what Flickr typically gets so right.
</p>
</blockquote>

<p>
<strong>Update:</strong> it seems to be a security thing, as a few people have already <a href="http://meyerweb.com/eric/thoughts/2006/06/28/forgetful-flickr/#comments">commented</a>.  I guess I understand the concern, but it&#8217;s hard for me to give it a whole lot of credit: if I were <em>that</em> paranoid about people seeing photos I consider truly private, I wouldn&#8217;t put them on a central server that anyone can visit in the first place.  Yes, I&#8217;ve withheld some photos from being fully public, but that privacy effort is one security breach or late-night coding goof away from total failure.  (Remember when Amazon accidentally showed the real names of reviewers instead of their account names, thus exposing some authors as having slammed books competing with their own?)  So if my personal &#8220;recent activity on your pictures&#8221; and &#8220;photos from your contacts&#8221; feeds were based on long randomly generated tokens, and not the discoverable user IDs, that would seem to be private enough&#8212;for me, anyway.  Your paranoia may vary.
</p></div>

</div>

</div>
<p style="font-size: 90%; text-align: right; margin-top: 0.5em; padding-top: 0;">(If you care, there's even an <a href="/eric/thoughts/page/2/">archive of previous thoughts</a>...)</p>

</div><div id="extra"><div class="panel" id="archipelago"><h4>Identity Archipelago</h4><ul><li><a href="http://flickr.com/photos/meyerweb/" rel="me">Flickr</a></li><li><a href="http://twitter.com/meyerweb/" rel="me">Twitter</a></li><li><a href="http://dopplr.com/traveller/meyerweb">Dopplr</a></li><li><a href="http://www.linkedin.com/in/meyerweb" rel="me">LinkedIn</a></li><li><a href="http://technorati.com/profile/emeyer" rel="me">Technorati</a></li></ul></div><div class="panel" id="pointers"><h4>Projects Elsewhere</h4><ul><li><a href="http://aneventapart.com/">An Event Apart</a></li><li><a href="http://complexspiral.com/">Complex Spiral Consulting</a></li><li><a href="http://www.webassist.com/go/css/emeyer/">CSS Sculptor</a></li><li><a href="http://css-discuss.org/">css-discuss</a></li><li><a href="http://microformats.org/">Microformats</a></li><li><a href="http://s5project.org/">S5</a></li></ul></div><div class="panel" id="tour"><ul><li><a href="http://fray.com/issue3/"><img src="http://fray.com/images/i3c.gif" alt="Fray Contributor (Issue 3: Sex &amp; Death)" /></a></li><!-- <li><a href="http://www.webassist.com/go/css/emeyer/"><img src="/pix/CS_ad_180x109.jpg" alt="CSS Sculptor for Dreamweaver" style="max-width: 100%;" /></a></li> --></ul></div><div class="panel">
<h4>Recently Tweeted</h4>
<p class="more"><a href="http://twitter.com/meyerweb">see more</a></p>
<p>Coffee shop hacking—using a stir-stick to spread cream cheese on my bagel. <small>&#8211;tweeted 7 hours, 28 minutes ago</small></p>
</div><div id="sideblog" class="panel">
<h4>Distractions</h4>
<p class="more">
<a href="/eric/thoughts/recent-links/">archive</a>
</p>
<ul>
<li><a href="http://tweetagewasteland.com/2010/03/my-head-is-in-the-cloud/" title="March 18 | &#8220;I sense that my addiction to the realtime stream is only making room for the consumption of a faster stream.&#8221;">My Head is in the Cloud</a> <small>[via <a href="http://daringfireball.net/">John</a>]</small></li>
<li><a href="http://8bitnyc.com/" title="March 17 | All of a sudden I want to establish a mission in Central Park and negotiate with the natives for gold and food.">8-Bit NYC</a></li>
<li><a href="http://www.youtube.com/watch?v=nFicqklGuB0&amp;feature=player_embedded" title="March 12 | Wry comment expressing my appreciation of the creative derivativeness of this video and its uncanny accuracy in mocking common tropes.">Academy Award Winning Movie Trailer</a></li>
<li><a href="http://www.youtube.com/watch?v=414TmP12WAU" title="March 9 | &#8220;Apple juice&#8230; for half price!&#8221;  More like twice PRICELESS.  (Note: If you&#8217;re at work, don your headphones.)">Happy in Paraguay</a> <small>[via <a href="http://unstoppablerobotninja.com/">Ethan</a>]</small></li>
<li><a href="http://www.youtube.com/watch?v=9V5ubAOeOBk&amp;feature=player_embedded" title="February 10 | This is approximately the best thing ever.">U900 -Walk Don&#8217;t Run (Isogabamaware)</a></li>
<li><a href="http://www.456bereastreet.com/archive/201002/sifr_default_css_hides_content_from_at_least_one_screen_reader/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A 456bereastreet %28456 Berea Street%29" title="February 8 | -9999px comes through again, but I really wish we were beyond that kind of thing.">sIFR default CSS hides content from at least one screen reader</a></li>
<li><a href="http://www.macosxhints.com/article.php?story=20100117064356428" title="February 8 | Storing this for future use.">Take a picture with the iSight camera when a folder is opened</a></li>
<li><a href="http://mingle2.com/blog/view/web-developer-mind" title="February 4 | Mostly valid.  (SEE WHAT I DID THERE?)">The Mind of a Web Developer: An Illustrated Diagram</a></li>
<li><a href="http://www.theonion.com/content/news/science_channel_refuses_to_dumb" title="January 28 | &#8220;Punkin Chunkin, for Christ&#8217;s sake&#8230; What more do you people want?&#8221;">Science Channel Refuses To Dumb Down Science Any Further</a></li>
<li><a href="http://www.mailchimp.com/blog/project-omnivore-declassified/" title="January 27 | Sounds like quite a feat.  But I wonder how we&#8217;d feel if Microsoft or Google announced the same kind of thing on their e-mail services.">MailChimp&#8217;s Project Omnivore: Declassified</a></li>
<li><a href="http://www.politifact.com/truth-o-meter/statements/2010/jan/25/carolyn-maloney/congresswoman-says-democratic-presidents-create-mo/" title="January 26 | &#8220;Obviously, luck matters a lot, but when there is a consistent pattern over more than 60 years, it starts to look like more than just luck.&#8221;">Congresswoman says Democratic presidents create more private-sector jobs</a></li>
<li><a href="http://www.ted.com/talks/taylor_mali_what_teachers_make.html" title="January 25 | Truth.">Taylor Mali: What teachers make</a></li>
<li><a href="http://notebook.johnmartz.com/how-websites-work?c=1" title="January 22 | At last, the truth is out and I can stop pretending:  beatific monkeys are what makes it all go.">How websites work</a></li>
</ul>
</div>
<div class="panel" id="advisory">
<div class="guarded">
<a href="http://blogadvisorysystem.com/"><img src="/pix/bas/guarded.png" alt="Blog Advisory System Alert Level: Guarded"></a>
</div>
</div>

<div class="panel" id="excuse">
<h4>The <a href="/feeds/excuse/">excuse of the day</a> is</h4>
<p>neutrino interactions</p>
</div>

<div class="panel" id="extras">
<h4>Extras</h4>
<ul>
<li><a href="/feeds/">Feeds</a> &#8226;</li>
<li><a href="/eric/faq.html">FAQ</a> &#8226;</li>
<li><a href="/family.html">Family</a></li>
</ul>
</div>

</div>

<div id="navigate">
<h4>Navigation</h4>
<ul id="navlinks">
<li id="archLink"><a href="/eric/thoughts/">Archives</a></li>
<li id="cssLink"><a href="/eric/css/">CSS</a></li>
<li id="toolsLink"><a href="/eric/tools/">Toolbox</a></li>
<li id="writeLink"><a href="/eric/writing.html">Writing</a></li>
<li id="speakLink"><a href="/eric/talks/">Speaking</a></li>
<li id="otherLink"><a href="/other/">Leftovers</a></li>
<li id="aboutsite"><a href="/ui/about.html">About this site</a></li>
</ul>
</div>

<div id="footer">
<p class="sosumi">All contents of this site, unless otherwise noted, are &copy;1995-2008 <strong>Eric A. and Kathryn S. Meyer</strong>.  All Rights Reserved.</p>
<p>"<a href="/eric/thoughts/">Thoughts From Eric</a>" is powered by the &uuml;bercool <a href="http://wordpress.org/">WordPress</a></p>
</div>
</body>
</html>
