I agree with the conclusion. Posterous could fix this problem by implementing something like The Zucchini Method ( http://www.jgc.org/antispam/03152005-2150120647b00f4af9d3443... [PDF]). Basically, they could accept posts via email as long as the user included some hard to guess word (or other token) in the subject line.
How I "hacked" Dustin Curtis's Posterous.
11–20 of 123 posts
Re: How I "hacked" Dustin Curtis's Posterous.
#12Hey, you left your door unlocked so I painted this sign on it to let everyone know.
Re: How I "hacked" Dustin Curtis's Posterous.
#13If Dustin were a major corporation or a politician, you'd be talking to the FBI and facing prosecution right now. Nice hack, BTW.
Hardly a hack!
Re: How I "hacked" Dustin Curtis's Posterous.
#14Why on Earth would anyone use the confirmation skip? That's basically security through obscurity. Even less so if the email address you use is known by people.
Same with privacy, see Facebook.
Re: How I "hacked" Dustin Curtis's Posterous.
#15SPF tells you that the email really came from my server. That the email really came from my server tells you that it's really me, as sending through my server requires a password.
Sadly SPF is grossly underused.
Re: How I "hacked" Dustin Curtis's Posterous.
#16Does Postereous not support SPF? SPF tells you that the email really came from my server. That the email really came from my server tells you that it's really me, as sending through my server requires a password. Sadly SPF is grossly underused.
B566EA61026F474BA8ADB877FF765087@postereous.com
If you're on another device just email whoami@postereous.com and it responds with with your GUID post address. Of course email is hardly confidential, and it would be sent in the clear, but it's a heck of a lot more powerful than simply looking at a from address.
Re: How I "hacked" Dustin Curtis's Posterous.
#17Does Postereous not support SPF? SPF tells you that the email really came from my server. That the email really came from my server tells you that it's really me, as sending through my server requires a password. Sadly SPF is grossly underused.
Re: How I "hacked" Dustin Curtis's Posterous.
#18Does Postereous not support SPF? SPF tells you that the email really came from my server. That the email really came from my server tells you that it's really me, as sending through my server requires a password. Sadly SPF is grossly underused.
As an aside, instead of post@, posterous should use a guid for each blog. e.g. B566EA61026F474BA8ADB877FF765087@postereous.com If you're on another device just email whoami@postereous.com and it responds with with your GUID post address. Of course email is hardly confidential, and it would be sent in the clear, but it's a heck of a lot more powerful than simply looking at a from address.
Re: How I "hacked" Dustin Curtis's Posterous.
#19I assumed that Posterous did something clever using the IP address of the SMTP peer or the headers in the message. Does Posterous fallback to just checking the sender email address?
Re: How I "hacked" Dustin Curtis's Posterous.
#20Earlier quoted context omitted.
As an aside, instead of post@, posterous should use a guid for each blog. e.g. B566EA61026F474BA8ADB877FF765087@postereous.com If you're on another device just email whoami@postereous.com and it responds with with your GUID post address. Of course email is hardly confidential, and it would be sent in the clear, but it's a heck of a lot more powerful than simply looking at a from address.
[deleted]