Live data from Hacker News

How I "hacked" Dustin Curtis's Posterous.

news.ycombinator.com

91–100 of 123 posts

Re: How I "hacked" Dustin Curtis's Posterous.

#91

Earlier quoted context omitted.

Such considerations might be overkill for flickr/posterous but that does leave your "secret" email address in the logs of every smtp relay along the way. Its sort of equivalent to putting a password in a URL.

"smtp relay along the way"? This isn't UUCP, the message will go from A to B across the internet backbone. There will only be SMTP relays along the way if either your email host or the receiver's email host has chosen to set things up that way. We'd have a much bigger problem with internet security if everyone's email was relayed through questionable servers as a matter of course.

Most residential DSL and cable users are prohibited from connecting to port 25, except on a special "smarthost". This machine, and anyone reading its logs, will learn your blog password.

More secure than no password, but not secure.

Re: How I "hacked" Dustin Curtis's Posterous.

#92

Earlier quoted context omitted.

Yeah, we're not talking about credit card info. Why not have post@ plus a secret@ available in your options. The more technically inclined could easily use the second, most likely safe enough, system. I really hope they don't complicate an otherwise zen-like experience.

Security shouldn't be optional. And this wouldn't fix the issue at all... I bet that 80%+ of users would leave the default post@ submission address.

The cost -- if someone successfully manages to spoof their way into your posterous blog -- isn't very high. You'll probably notice fairly quickly, it's hard for "the bad guy" to use for actual gain, and there's no money involved either way.

I use a service called Postful to send snail mail via email, that has security along these lines -- I email them a PDF with a mailing address in the subject line, and they post a letter and charge me a buck. They give security options (in my case, I include a "secret" word in the subject line, and there's a confirmation link that's emailed to me), but if I wanted, I could even let anyway send email to a given postful.com address, and it would mail a letter on my dime with no confirmation.

I haven't heard about any abuses.

Re: How I "hacked" Dustin Curtis's Posterous.

#94
post #86

Hey guys. I'm the cofounder of Posterous. Yes, someone did figure out how to post to Dustin's site today. This security hole is now fixed. We had a specific problem with the way we dealt with SPF records. Dustin didn't set any up, and there was a specific way that Robin Duckett's email server responded that caused us to flag it as a false negative for spoofing. For the vast majority of users who use gmail, hotmail or…

A quick response from Posterous. I'd expect nothing less. Posterous:email spoof detection PayPal:credit card fraud detection See the section in Founders at Work on the value that better fraud detection created for PayPal.

[deleted]

Re: How I "hacked" Dustin Curtis's Posterous.

#95
post #15

Does Postereous not support SPF? SPF tells you that the email really came from my server. That the email really came from my server tells you that it's really me, as sending through my server requires a password. Sadly SPF is grossly underused.

SPF doesn't verify the sender, it only tells you if the server is allowed to send mail from a domain. You can still use the password for your account to forge the sending address of another user in the domain. Besides, the fact that your domain requires a password is only meaningful to you; it has no value to the outside world in terms of identity assurance.

Re: How I "hacked" Dustin Curtis's Posterous.

#96

Hey guys. I'm the cofounder of Posterous. Yes, someone did figure out how to post to Dustin's site today. This security hole is now fixed. We had a specific problem with the way we dealt with SPF records. Dustin didn't set any up, and there was a specific way that Robin Duckett's email server responded that caused us to flag it as a false negative for spoofing. For the vast majority of users who use gmail, hotmail or…

Odd, the other Posterous threads are getting buried so quickly. When a new comment is posted in any thread it appears at the top, except for these Posterous threads. Is this damage control on the part of YC?

The only other person so far to comment under the co-founder on this thread (at time of writing) is jseeba, who has had very little activity and one of the few comments he's ever made was in a thread called "Ask YC: Your favorite startups" where he said "Posterous. It just works." So jseeba doesn't do much around here in the 2 or so years he's been a member but made time to chime in for Posterous again.

Re: How I "hacked" Dustin Curtis's Posterous.

#97
post #2

I agree with the conclusion. Posterous could fix this problem by implementing something like The Zucchini Method ( http://www.jgc.org/antispam/03152005-2150120647b00f4af9d3443... [PDF]). Basically, they could accept posts via email as long as the user included some hard to guess word (or other token) in the subject line.

The subject line is the title of the the post at Posterous... though I suppose the could strip it out... i.e. "subj: Blog Post Title Goes here #sekretpassword". Certainly not ideal. Typos would confuse matters and the idea of secret word authentication is not exactly common/obvious for the masses.

That would also require sending #sekretpasword in plaintext, also not ideal.

Re: How I "hacked" Dustin Curtis's Posterous.

#98

Hey guys. I'm the cofounder of Posterous. Yes, someone did figure out how to post to Dustin's site today. This security hole is now fixed. We had a specific problem with the way we dealt with SPF records. Dustin didn't set any up, and there was a specific way that Robin Duckett's email server responded that caused us to flag it as a false negative for spoofing. For the vast majority of users who use gmail, hotmail or…

Odd, the other Posterous threads are getting buried so quickly. When a new comment is posted in any thread it appears at the top, except for these Posterous threads. Is this damage control on the part of YC? The only other person so far to comment under the co-founder on this thread (at time of writing) is jseeba, who has had very little activity and one of the few comments he's ever made was in a thread called "Ask…

[deleted]

Re: How I "hacked" Dustin Curtis's Posterous.

#99

Earlier quoted context omitted.

"smtp relay along the way"? This isn't UUCP, the message will go from A to B across the internet backbone. There will only be SMTP relays along the way if either your email host or the receiver's email host has chosen to set things up that way. We'd have a much bigger problem with internet security if everyone's email was relayed through questionable servers as a matter of course.

Most residential DSL and cable users are prohibited from connecting to port 25, except on a special "smarthost". This machine, and anyone reading its logs, will learn your blog password. More secure than no password, but not secure.

[citation needed]

More to the point, what you are saying is that your ISP can read your unencrypted internet traffic. This is not news.

Re: How I "hacked" Dustin Curtis's Posterous.

#100
post #36

Why on Earth would anyone use the confirmation skip? That's basically security through obscurity. Even less so if the email address you use is known by people.

Interesting point, because it suggests that an email address that was kept private and dedicated to Posterous posting could have prevented this attack. So, is this weak security on the part of Posterous, or excellent social engineering on the part of robinduckett? At the least, It's like he simply asked the target for a password; at the most, it's like he found the spare door key in the fake 7-Up can in the garden sh…

Actually it was a bug, and its now fixed.
Post reply on HN