If that's true, the lead developer should be fired on the spot. They use that "good" old "security by obscurity". I thought this technique was dead long ago....
a little harsh maybe....developers make mistakes...probably just forgot about it while trying to get the initial release out the door.... its not like tumblr is a bank or the DoD
Tumblr security hole (the gaping kind)
11–20 of 85 posts
Re: Tumblr security hole (the gaping kind)
#12Did you or your friend happen to report this to them before posting it here?
yeah he said he told them. I would have more sympathy if it was an obscure hole, but something this big is just disrespectful to their users.
Re: Tumblr security hole (the gaping kind)
#13If that's true, the lead developer should be fired on the spot. They use that "good" old "security by obscurity". I thought this technique was dead long ago....
Errare humanum est.
Re: Tumblr security hole (the gaping kind)
#14Earlier quoted context omitted.
a little harsh maybe....developers make mistakes...probably just forgot about it while trying to get the initial release out the door.... its not like tumblr is a bank or the DoD
ok, maybe :) But forgeting to secure your admin area deserves more than a simple warning. Can you imagine if the person that discovered the vulnerability decided to delete all the user accounts?
Re: Tumblr security hole (the gaping kind)
#15Earlier quoted context omitted.
yeah he said he told them. I would have more sympathy if it was an obscure hole, but something this big is just disrespectful to their users.
This is a pretty critical exploit . . . you'd think they'd take the app down or at least change the admin URL while this is resolved. I shouldn't at this moment still be able to reset an arbitrary user's password by going to that URL.
Re: Tumblr security hole (the gaping kind)
#16Earlier quoted context omitted.
This is a pretty critical exploit . . . you'd think they'd take the app down or at least change the admin URL while this is resolved. I shouldn't at this moment still be able to reset an arbitrary user's password by going to that URL.
...and how many people have found it and not said anything? we've all used poorly secured admins here and there, but /admin seems particularly egregious.
Scary.
Re: Tumblr security hole (the gaping kind)
#17If that's true, the lead developer should be fired on the spot. They use that "good" old "security by obscurity". I thought this technique was dead long ago....
What if the lead developer is the CEO? What would you suggest then? Shut down the company? Errare humanum est.
Re: Tumblr security hole (the gaping kind)
#18If that's true, the lead developer should be fired on the spot. They use that "good" old "security by obscurity". I thought this technique was dead long ago....
a little harsh maybe....developers make mistakes...probably just forgot about it while trying to get the initial release out the door.... its not like tumblr is a bank or the DoD
Saying security is less important because it's not a bank doesn't make sense because it's issues like this that can cost a company it's existence.