Martin, over at currybet.com, noticed that Bloglines will reveal feeds for other people’s GMail feed when you go to subscribe to your own. I’m sure you were wondering, just like I was, how he went about finding these:

I was astonished on Friday when I was looking at my Gmail account inbox, and accidently hit the ‘Subscribe with Bloglines’ bookmarklet on my Firefox links toolbar. Bloglines then dutifully put up on the screen a whole series of Atom feeds of other people’s Gmail accounts that I could subscribe too.

I was pretty shocked but then looking at the screenshot made me realize that the people in the list are people who have setup Feedburner to retrieve the feed from GMail. As you can tell from the screenshot above there is not a lot of information shown…unless you actually subscribe to the feed!

After subscribing to a few feeds he noticed that one of them almost revealed someone’s password but it was cutoff by the character limitation:

It isn’t really Google’s fault or Feedburner’s fault because users can choose to password protect a feed if they want, which is obviously something that should be done here. I took it a step further and turned up two results when searching Google for some other people that are doing the same thing. I expected to find more than that though.

  1. Wow, that is scary. Any idea how to turn off Gmail’s RSS?

  2. Radu CapanAll-StarOctober 2, 2006 at 3:50 pm

    I think the problem is only for those who burned their feed from GMail with FeedBurner. The clasic RSS feed from GMail is password protected, as far as I know. If so, stay calm. Anyone knows something else?

  3. Yes, all of the ones that I saw were from people using Feedburner so as long as you haven’t done that then you are OK.

  4. Dear Ryan:

    Please send me an invite for Okrut. I would greatly appreciate if you were not to forget about me. Thank you very much in advance.

    Wishing you all the best,

    Sam

    My email address is: sammy_nyc@hotmail.com