Live data from Hacker News

Tumblr security hole (the gaping kind)

news.ycombinator.com

11–20 of 85 posts

Re: Tumblr security hole (the gaping kind)

#11
post #9
post #3

If that's true, the lead developer should be fired on the spot. They use that "good" old "security by obscurity". I thought this technique was dead long ago....

a little harsh maybe....developers make mistakes...probably just forgot about it while trying to get the initial release out the door.... its not like tumblr is a bank or the DoD

ok, maybe :) But forgeting to secure your admin area deserves more than a simple warning. Can you imagine if the person that discovered the vulnerability decided to delete all the user accounts?

Re: Tumblr security hole (the gaping kind)

#12
post #8

Did you or your friend happen to report this to them before posting it here?

yeah he said he told them. I would have more sympathy if it was an obscure hole, but something this big is just disrespectful to their users.

This is a pretty critical exploit . . . you'd think they'd take the app down or at least change the admin URL while this is resolved. I shouldn't at this moment still be able to reset an arbitrary user's password by going to that URL.

Re: Tumblr security hole (the gaping kind)

#13
post #3

If that's true, the lead developer should be fired on the spot. They use that "good" old "security by obscurity". I thought this technique was dead long ago....

What if the lead developer is the CEO? What would you suggest then? Shut down the company?

Errare humanum est.

Re: Tumblr security hole (the gaping kind)

#14
post #11
post #9

Earlier quoted context omitted.

a little harsh maybe....developers make mistakes...probably just forgot about it while trying to get the initial release out the door.... its not like tumblr is a bank or the DoD

ok, maybe :) But forgeting to secure your admin area deserves more than a simple warning. Can you imagine if the person that discovered the vulnerability decided to delete all the user accounts?

[deleted]

Re: Tumblr security hole (the gaping kind)

#15
post #12

Earlier quoted context omitted.

yeah he said he told them. I would have more sympathy if it was an obscure hole, but something this big is just disrespectful to their users.

This is a pretty critical exploit . . . you'd think they'd take the app down or at least change the admin URL while this is resolved. I shouldn't at this moment still be able to reset an arbitrary user's password by going to that URL.

...and how many people have found it and not said anything? we've all used poorly secured admins here and there, but /admin seems particularly egregious.

Re: Tumblr security hole (the gaping kind)

#16
post #12

Earlier quoted context omitted.

This is a pretty critical exploit . . . you'd think they'd take the app down or at least change the admin URL while this is resolved. I shouldn't at this moment still be able to reset an arbitrary user's password by going to that URL.

...and how many people have found it and not said anything? we've all used poorly secured admins here and there, but /admin seems particularly egregious.

...and how many people have found it and not said anything?

Scary.

Re: Tumblr security hole (the gaping kind)

#17
post #13
post #3

If that's true, the lead developer should be fired on the spot. They use that "good" old "security by obscurity". I thought this technique was dead long ago....

What if the lead developer is the CEO? What would you suggest then? Shut down the company? Errare humanum est.

Yes, Errare human est. I guess natural selection will take care of companies like this. If the developer is the CEO, then the investors should be concerned.

Re: Tumblr security hole (the gaping kind)

#18
post #9
post #3

If that's true, the lead developer should be fired on the spot. They use that "good" old "security by obscurity". I thought this technique was dead long ago....

a little harsh maybe....developers make mistakes...probably just forgot about it while trying to get the initial release out the door.... its not like tumblr is a bank or the DoD

Forgetting to secure the admin panel isn't a little mistake though and is easy enough to detect "Hey, I didn't have to log in to an admin account to use the admin panel thats weird".

Saying security is less important because it's not a bank doesn't make sense because it's issues like this that can cost a company it's existence.

Post reply on HN