Live data from Hacker News

How I "hacked" Dustin Curtis's Posterous.

news.ycombinator.com

31–40 of 123 posts

Re: How I "hacked" Dustin Curtis's Posterous.

#31
> and they should not let you disable submission checking

I realize the security implications of all of the latest Posterous musings. But the fact is if Posterous didn't allow you to disable this I'd stop using their service. Posterous knows this.

My use case for Posterous is my phone. It has a nice 8 megapixel camera, and with literally two clicks I can have a picture sent to my Posterous blog. Is it secure? Not at all. Is it extremely convenient and productive? Absolutely.

Re: How I "hacked" Dustin Curtis's Posterous.

#32
post #2

I agree with the conclusion. Posterous could fix this problem by implementing something like The Zucchini Method ( http://www.jgc.org/antispam/03152005-2150120647b00f4af9d3443... [PDF]). Basically, they could accept posts via email as long as the user included some hard to guess word (or other token) in the subject line.

Other people replied about a randomized/hard to guess email address. Building on your idea of a "hard to guess word" or token in the subject, posterous could allow a user to upload their public key, and require that their posts be gpg/pgp signed with their key (obviously this would be something that users would have to opt into). The displayed post could simply strip out the signature as it would only be needed for authentication.

Re: How I "hacked" Dustin Curtis's Posterous.

#34

If Dustin were a major corporation or a politician, you'd be talking to the FBI and facing prosecution right now. Nice hack, BTW.

Hardly a hack!

True, but opening an unlocked door is hardly breaking into a house, yet you'd still get in trouble for it.

Re: How I "hacked" Dustin Curtis's Posterous.

#35

If Dustin were a major corporation or a politician, you'd be talking to the FBI and facing prosecution right now. Nice hack, BTW.

What would the crime be?

Well, he's knowingly misrepresenting himself. He's sending email as Dustin, with the specific intent of gaining unauthorized access to a system. (and he knows he's not authorized to post on Dustin's posterous)

Re: How I "hacked" Dustin Curtis's Posterous.

#36

Why on Earth would anyone use the confirmation skip? That's basically security through obscurity. Even less so if the email address you use is known by people.

Interesting point, because it suggests that an email address that was kept private and dedicated to Posterous posting could have prevented this attack. So, is this weak security on the part of Posterous, or excellent social engineering on the part of robinduckett? At the least, It's like he simply asked the target for a password; at the most, it's like he found the spare door key in the fake 7-Up can in the garden shed.

Note: Creating a "private" email address is beyond the capabilities of 75% of the people I know, who believe that email addresses are exclusively created and assigned by ISPs or employers. I doubt that Posterous will do anything to alienate this group, who appear to be an important target audience.

Re: How I "hacked" Dustin Curtis's Posterous.

#37

Earlier quoted context omitted.

Hardly a hack!

True, but opening an unlocked door is hardly breaking into a house, yet you'd still get in trouble for it.

Locked or not it's still trespass, which is illegal, in most places.

Re: How I "hacked" Dustin Curtis's Posterous.

#38
E-mail provides no security. An e-mail can be forged simply by using telnet to connect to and SMP server (usually your ISPs) and typing the appropriate message (see wikipedia SMTP. The easiest fix for this is PGP as mentionned in previous posts. This is, however, a horrible solution since it will alienate many users (think your mother). The simplest solution that will do a good enough job is to send back an e-mail to the user with a 'preview' of his post for him to OK it since receiving e-mails is more secure.

Re: How I "hacked" Dustin Curtis's Posterous.

#40

Earlier quoted context omitted.

Hardly a hack!

it's a hack in the Bruce Schneier "easiest way to steal pancakes has nothing to do with where money changes hands" sense... Our goal is to eat, without paying, at the local restaurant. And we've got a lot of options. We can eat and run. We can pay with a fake credit card, a fake check, or counterfiet cash. We can persuade another patron to leave the restraunt without eating and eat his food. We can impersonate (or ac…

You've made this celiac crave pancakes again. Bad.
Post reply on HN