Live data from Hacker News

How I "hacked" Dustin Curtis's Posterous.

news.ycombinator.com

51–60 of 123 posts

Re: How I "hacked" Dustin Curtis's Posterous.

#51

Earlier quoted context omitted.

What would the crime be?

Well, he's knowingly misrepresenting himself. He's sending email as Dustin, with the specific intent of gaining unauthorized access to a system. (and he knows he's not authorized to post on Dustin's posterous)

That much is obvious, but what would cause the FBI to get involved and what would he be charged with?

Re: How I "hacked" Dustin Curtis's Posterous.

#52
post #42
post #2

I agree with the conclusion. Posterous could fix this problem by implementing something like The Zucchini Method ( http://www.jgc.org/antispam/03152005-2150120647b00f4af9d3443... [PDF]). Basically, they could accept posts via email as long as the user included some hard to guess word (or other token) in the subject line.

They should just use SPF. This is what SPF is designed for, and it allows them to keep the user experience simple and straightforward. No weird passphrase to enter into the email, no weird random email address to email to, etc.

SPF only identifies the sending domain, not the sender himself.

If your address is gmail and my address is gmail, our mx domain has the same spf record and same IPs. Sure, some mail servers will prevent you from authenticating with one ID and sending as another, but many others will let that slide.

Re: How I "hacked" Dustin Curtis's Posterous.

#53
post #11
post #2

I agree with the conclusion. Posterous could fix this problem by implementing something like The Zucchini Method ( http://www.jgc.org/antispam/03152005-2150120647b00f4af9d3443... [PDF]). Basically, they could accept posts via email as long as the user included some hard to guess word (or other token) in the subject line.

or do what flickr does and give you a unique email address to send to that only you will know. you can add it to your address book so you won't have to remember it, and it's probably stronger than what most users would choose for a password.

Such considerations might be overkill for flickr/posterous but that does leave your "secret" email address in the logs of every smtp relay along the way. Its sort of equivalent to putting a password in a URL.

Re: How I "hacked" Dustin Curtis's Posterous.

#54
post #11
post #2

I agree with the conclusion. Posterous could fix this problem by implementing something like The Zucchini Method ( http://www.jgc.org/antispam/03152005-2150120647b00f4af9d3443... [PDF]). Basically, they could accept posts via email as long as the user included some hard to guess word (or other token) in the subject line.

or do what flickr does and give you a unique email address to send to that only you will know. you can add it to your address book so you won't have to remember it, and it's probably stronger than what most users would choose for a password.

[deleted]

Re: How I "hacked" Dustin Curtis's Posterous.

#55
post #11
post #2

I agree with the conclusion. Posterous could fix this problem by implementing something like The Zucchini Method ( http://www.jgc.org/antispam/03152005-2150120647b00f4af9d3443... [PDF]). Basically, they could accept posts via email as long as the user included some hard to guess word (or other token) in the subject line.

or do what flickr does and give you a unique email address to send to that only you will know. you can add it to your address book so you won't have to remember it, and it's probably stronger than what most users would choose for a password.

Exactly. This is what we do on CallTheWeb. Not only is it much safer, but it allows our users to contribute messages to multiple accounts (say, their personal account, as well as a company account). If you tie things to a single email address, you limit your power users.

Re: How I "hacked" Dustin Curtis's Posterous.

#56

Earlier quoted context omitted.

Well, he's knowingly misrepresenting himself. He's sending email as Dustin, with the specific intent of gaining unauthorized access to a system. (and he knows he's not authorized to post on Dustin's posterous)

That much is obvious, but what would cause the FBI to get involved and what would he be charged with?

Interstate something-or-other.

Re: How I "hacked" Dustin Curtis's Posterous.

#57
post #42

Earlier quoted context omitted.

They should just use SPF. This is what SPF is designed for, and it allows them to keep the user experience simple and straightforward. No weird passphrase to enter into the email, no weird random email address to email to, etc.

SPF only identifies the sending domain, not the sender himself. If your address is gmail and my address is gmail, our mx domain has the same spf record and same IPs. Sure, some mail servers will prevent you from authenticating with one ID and sending as another, but many others will let that slide.

Yes, but that's a fault of the mailserver on that domain. It shouldn't allow spoofed email to be sent from its own domain.

Re: How I "hacked" Dustin Curtis's Posterous.

#58
post #11

Earlier quoted context omitted.

or do what flickr does and give you a unique email address to send to that only you will know. you can add it to your address book so you won't have to remember it, and it's probably stronger than what most users would choose for a password.

Such considerations might be overkill for flickr/posterous but that does leave your "secret" email address in the logs of every smtp relay along the way. Its sort of equivalent to putting a password in a URL.

Yeah, we're not talking about credit card info. Why not have post@ plus a secret@ available in your options. The more technically inclined could easily use the second, most likely safe enough, system.

I really hope they don't complicate an otherwise zen-like experience.

Re: How I "hacked" Dustin Curtis's Posterous.

#59

Earlier quoted context omitted.

True, but opening an unlocked door is hardly breaking into a house, yet you'd still get in trouble for it.

Locked or not it's still trespass, which is illegal, in most places.

Not in some parts of Canada. Trespass is only once you've told someone to leave (or have a sign saying "no trespassing). Otherwise you are free to walk on anyone's property (this is Canada wide) and sometimes enter their house (this is specific to certain areas). If a door is locked then obviously you arn't allowed in, but in the North you are granted "implicit" permission to go into someone's house if you would be in pain or otherwise discomforted. In an emergency (threat of death, lifelong pain, bear/wolf/moose attack (seriously) you are allowed to break into a house and stay there until you can leave. You are supposed to get in touch with the owner as soon as you can find him, though, and replace food, windows, other damage. If you don't it is considered break and entering.

Re: How I "hacked" Dustin Curtis's Posterous.

#60
post #49
post #46

Earlier quoted context omitted.

> What's different between the way they did it and the way you did it? he was successful. seriously, though, the difference probably is that you put more time and effort into creating a posterous that was more secure. something as simple as "create it using a difficult email address" should cover most bases. something that most people likely don't do.

I put zero time into it. I created a brand new Posterous account, left everything as the default and posted the email address tied to the account here.

hm. well, if i had to venture a guess, i would say that it was because you used gmail exclusively, while mr curtis does not. probably easier to slide by if you're a poster who emails through various different clients over time.
Post reply on HN