Live data from Hacker News

How I "hacked" Dustin Curtis's Posterous.

news.ycombinator.com

81–90 of 123 posts

Re: How I "hacked" Dustin Curtis's Posterous.

#81

How does Posterous authenticate a message in the absence of DKIM or SPF records in DNS? The domain dustincurtis.com does not have an SPF record and DKIM is not supported by the mail host for dustincurtis.com(Google Apps for your Domain). I assumed that Posterous did something clever using the IP address of the SMTP peer or the headers in the message. Does Posterous fallback to just checking the sender email address?

> Does Posterous fallback to just checking the sender email address? Apparently so, I didn't even change my name.

Thanks for the bug report. This bug is now fixed.

Re: How I "hacked" Dustin Curtis's Posterous.

#82
Hey guys. I'm the cofounder of Posterous.

Yes, someone did figure out how to post to Dustin's site today. This security hole is now fixed.

We had a specific problem with the way we dealt with SPF records. Dustin didn't set any up, and there was a specific way that Robin Duckett's email server responded that caused us to flag it as a false negative for spoofing.

For the vast majority of users who use gmail, hotmail or other services, this was never an issue.

Since our launch on day one, we have taken email spoof detection very seriously. It's one of our core differentiators: to be able to securely post to your blog by emailing a single, easy to remember address. We don't want to do secret addresses or secret words.

Over the past 2 years, we've developed robust spoof detection ip and spend a ton of time trying to stay a step ahead of hackers. Fortunately, we've only had a few very specific, isolated cases where one of our sites was spoofed and each time we have improved our system.

Thanks for bringing this to our attention. We always need to be one step ahead of the hackers/spoofers, and we thank the Hacker News community for keeping us on our toes!

Re: How I "hacked" Dustin Curtis's Posterous.

#83

Earlier quoted context omitted.

That much is obvious, but what would cause the FBI to get involved and what would he be charged with?

jcromartie's premise was, "If Dustin were a major corporation or a politician..." IANAL, and it's not exactly the same circumstances, but when Sarah Palin's e-mail was hacked during the 2008 U.S. presidential campaign, the FBI and Secret Service both "got involved". According to Wikipedia the hacker in question was eventually found guilty of (1) felony obstruction of justice by destruction of records and (2) misdemea…

Basically what I am wondering is if he were to make a post to Pepsi's blog on Posterous, what would the federal crime be?

The parent has a lot of upvotes, so I really want to know why they agree he committed a crime, rather than found a bug.

Re: How I "hacked" Dustin Curtis's Posterous.

#84

Earlier quoted context omitted.

it's a hack in the Bruce Schneier "easiest way to steal pancakes has nothing to do with where money changes hands" sense... Our goal is to eat, without paying, at the local restaurant. And we've got a lot of options. We can eat and run. We can pay with a fake credit card, a fake check, or counterfiet cash. We can persuade another patron to leave the restraunt without eating and eat his food. We can impersonate (or ac…

You've made this celiac crave pancakes again. Bad.

You can't tolerate glutin and you've never tried buckwheat pancakes? I find them superior to normal wheat pancakes in every way.

Re: How I "hacked" Dustin Curtis's Posterous.

#85
post #71

Does Posterous filter SEO spam? Otherwise this loophole seems like a perfect opportunity for SEO spam to start filtering in on lapsed accounts that still have some PageRank...

We do kill it and we're building a comprehensive spam killing system too. SEO spam is not welcome on Posterous in the least.

Re: How I "hacked" Dustin Curtis's Posterous.

#86

Hey guys. I'm the cofounder of Posterous. Yes, someone did figure out how to post to Dustin's site today. This security hole is now fixed. We had a specific problem with the way we dealt with SPF records. Dustin didn't set any up, and there was a specific way that Robin Duckett's email server responded that caused us to flag it as a false negative for spoofing. For the vast majority of users who use gmail, hotmail or…

A quick response from Posterous. I'd expect nothing less.

Posterous:email spoof detection PayPal:credit card fraud detection

See the section in Founders at Work on the value that better fraud detection created for PayPal.

Re: How I "hacked" Dustin Curtis's Posterous.

#87

Earlier quoted context omitted.

it's a hack in the Bruce Schneier "easiest way to steal pancakes has nothing to do with where money changes hands" sense... Our goal is to eat, without paying, at the local restaurant. And we've got a lot of options. We can eat and run. We can pay with a fake credit card, a fake check, or counterfiet cash. We can persuade another patron to leave the restraunt without eating and eat his food. We can impersonate (or ac…

You've made this celiac crave pancakes again. Bad.

You can make decent pancakes with oat flour. Try http://www.recipefiles.org/view_recipe.php?id=548 out.

Re: How I "hacked" Dustin Curtis's Posterous.

#88
You could have told him instead of being a jerk - I know from experience that this doesn't work, say in the work place, where proving your point like this is vital if you want to be heard - but for regular people this is basically an attack. Worst of all you told everyone else how to do it...

Warning him would have been nice, this IS, by definition almost, malicious - regardless of how you chose to interpret the word yourself.

Re: How I "hacked" Dustin Curtis's Posterous.

#89
post #11

Earlier quoted context omitted.

or do what flickr does and give you a unique email address to send to that only you will know. you can add it to your address book so you won't have to remember it, and it's probably stronger than what most users would choose for a password.

Such considerations might be overkill for flickr/posterous but that does leave your "secret" email address in the logs of every smtp relay along the way. Its sort of equivalent to putting a password in a URL.

"smtp relay along the way"?

This isn't UUCP, the message will go from A to B across the internet backbone. There will only be SMTP relays along the way if either your email host or the receiver's email host has chosen to set things up that way. We'd have a much bigger problem with internet security if everyone's email was relayed through questionable servers as a matter of course.

Re: How I "hacked" Dustin Curtis's Posterous.

#90

Earlier quoted context omitted.

jcromartie's premise was, "If Dustin were a major corporation or a politician..." IANAL, and it's not exactly the same circumstances, but when Sarah Palin's e-mail was hacked during the 2008 U.S. presidential campaign, the FBI and Secret Service both "got involved". According to Wikipedia the hacker in question was eventually found guilty of (1) felony obstruction of justice by destruction of records and (2) misdemea…

Basically what I am wondering is if he were to make a post to Pepsi's blog on Posterous, what would the federal crime be? The parent has a lot of upvotes, so I really want to know why they agree he committed a crime, rather than found a bug.

Upvotes aren't for agreeing.
Post reply on HN