Live data from Hacker News

How I "hacked" Dustin Curtis's Posterous.

news.ycombinator.com

41–50 of 123 posts

Re: How I "hacked" Dustin Curtis's Posterous.

#41

This is a clear example of "good enough." Low security for low value targets -- if you need more you can get it. Setting a password, remembering a special email address, not posting via blackberry/mobile, all of these add friction. EDIT: Although it is fun to think of solutions ... Posterous could mail you back a link; when you hit the link the post goes live. Then you would clearly need control of the sending addres…

Measuring the danger of being impersonated is very difficult. It depends on how creative the attacker is and the social circumstances of the victim. Further, the victim can easily be unaware of the danger until they get bitten once.

This is going to be a serious issue for Posterous if they ever go mainstream. Opt-in authentication schemes won't be enough to prevent scores of naive people from being humiliated the first time, particularly teenagers.

Re: How I "hacked" Dustin Curtis's Posterous.

#42
post #2

I agree with the conclusion. Posterous could fix this problem by implementing something like The Zucchini Method ( http://www.jgc.org/antispam/03152005-2150120647b00f4af9d3443... [PDF]). Basically, they could accept posts via email as long as the user included some hard to guess word (or other token) in the subject line.

They should just use SPF. This is what SPF is designed for, and it allows them to keep the user experience simple and straightforward. No weird passphrase to enter into the email, no weird random email address to email to, etc.

Re: How I "hacked" Dustin Curtis's Posterous.

#43
post #32
post #2

I agree with the conclusion. Posterous could fix this problem by implementing something like The Zucchini Method ( http://www.jgc.org/antispam/03152005-2150120647b00f4af9d3443... [PDF]). Basically, they could accept posts via email as long as the user included some hard to guess word (or other token) in the subject line.

Other people replied about a randomized/hard to guess email address. Building on your idea of a "hard to guess word" or token in the subject, posterous could allow a user to upload their public key, and require that their posts be gpg/pgp signed with their key (obviously this would be something that users would have to opt into). The displayed post could simply strip out the signature as it would only be needed for a…

Only with that kind of thing, or even the Zucchini method mentioned above, they would kind of lose their tag line about the easiest way to update a blog (or whatever it is).

Re: How I "hacked" Dustin Curtis's Posterous.

#45
I feel like I'm missing something... Yesterday we were talking about the protections on Posterous and I posted an invitation to try to post to a Posterous I had set up (http://news.ycombinator.com/item?id=1439376). I got a bunch of emails from Posterous as a result of people trying to fake post to the account that I'd set up.

What's different between the way they did it and the way you did it? I'm assuming they also simply changed their email address in their mail client to try to send to my account.

Re: How I "hacked" Dustin Curtis's Posterous.

#46
post #45

I feel like I'm missing something... Yesterday we were talking about the protections on Posterous and I posted an invitation to try to post to a Posterous I had set up ( http://news.ycombinator.com/item?id=1439376 ). I got a bunch of emails from Posterous as a result of people trying to fake post to the account that I'd set up. What's different between the way they did it and the way you did it? I'm assuming they als…

> What's different between the way they did it and the way you did it?

he was successful.

seriously, though, the difference probably is that you put more time and effort into creating a posterous that was more secure. something as simple as "create it using a difficult email address" should cover most bases. something that most people likely don't do.

Re: How I "hacked" Dustin Curtis's Posterous.

#47
Heh. Back when alternate email protocols were still common, it was my job to help support the "smtp gateway" product for a large corporation. I got to the point where I could forge emails by typing in SMTP by hand.

This worked very well the day I played a prank on my boss - the boss had sent out an email forged to appear it came from a co-worker that was supposed to be funny but hurt the co-worker's feelings badly. Co-worker wanted revenge, so I created a "letter of resignation" that appeared to come from the boss and that appeared to have been sent to every member of our company - but was really only sent to the boss himself.

Co-worker later told me he saw the boss running from office to office trying to do "damage control" before he realized no one else had actually gotten the email.

Re: How I "hacked" Dustin Curtis's Posterous.

#49
post #46
post #45

I feel like I'm missing something... Yesterday we were talking about the protections on Posterous and I posted an invitation to try to post to a Posterous I had set up ( http://news.ycombinator.com/item?id=1439376 ). I got a bunch of emails from Posterous as a result of people trying to fake post to the account that I'd set up. What's different between the way they did it and the way you did it? I'm assuming they als…

> What's different between the way they did it and the way you did it? he was successful. seriously, though, the difference probably is that you put more time and effort into creating a posterous that was more secure. something as simple as "create it using a difficult email address" should cover most bases. something that most people likely don't do.

I put zero time into it. I created a brand new Posterous account, left everything as the default and posted the email address tied to the account here.

Re: How I "hacked" Dustin Curtis's Posterous.

#50

Earlier quoted context omitted.

True, but opening an unlocked door is hardly breaking into a house, yet you'd still get in trouble for it.

Locked or not it's still trespass, which is illegal, in most places.

Right, that's what I was going for.
Post reply on HN