Live data from Hacker News

Tumblr security hole (the gaping kind)

news.ycombinator.com

21–30 of 85 posts

Re: Tumblr security hole (the gaping kind)

#21
post #8

Did you or your friend happen to report this to them before posting it here?

yeah he said he told them. I would have more sympathy if it was an obscure hole, but something this big is just disrespectful to their users.

Cool just making sure because it is still up and you would assume something like this would be taken down immediately.

Re: Tumblr security hole (the gaping kind)

#22
post #9

Earlier quoted context omitted.

a little harsh maybe....developers make mistakes...probably just forgot about it while trying to get the initial release out the door.... its not like tumblr is a bank or the DoD

Forgetting to secure the admin panel isn't a little mistake though and is easy enough to detect "Hey, I didn't have to log in to an admin account to use the admin panel thats weird". Saying security is less important because it's not a bank doesn't make sense because it's issues like this that can cost a company it's existence.

This doesnt sound like the whole admin panel... its possible nobody has even used this panel since testing...

It is a problem, just saying that I vote the developer keeps his job cause i like tumblr

Re: Tumblr security hole (the gaping kind)

#24

I actually don't know what Tumblr is. Is it a twitter clone or something?

They were the first popular tumbleblogging platform. It's a really good service, this incident notwithstanding.

The perverse irony of all of this is that the incident reminded me that I've got a Tumblr account. Before today, I hadn't logged in for over a year!

Re: Tumblr security hole (the gaping kind)

#25
post #22

Earlier quoted context omitted.

Forgetting to secure the admin panel isn't a little mistake though and is easy enough to detect "Hey, I didn't have to log in to an admin account to use the admin panel thats weird". Saying security is less important because it's not a bank doesn't make sense because it's issues like this that can cost a company it's existence.

This doesnt sound like the whole admin panel... its possible nobody has even used this panel since testing... It is a problem, just saying that I vote the developer keeps his job cause i like tumblr

I'm not advocating firing the developer. If every developer got fired for every stupid silly mistake we'd have no working developers in the world. I was just clarifying the seriousness of this specific flaw. :)

Re: Tumblr security hole (the gaping kind)

#26
post #3

If that's true, the lead developer should be fired on the spot. They use that "good" old "security by obscurity". I thought this technique was dead long ago....

I can believe they stuck their admin at /admin, but it's hard to believe they didn't create an admin bit as part of the users table and check it to access /admin. That takes about 2 minutes if you do it when you create the system.

Oh well, everyone overlooks something that seems obvious to someone else, I guess.

Re: Tumblr security hole (the gaping kind)

#30

Probably better to let Tumblr know first, then us. Edit: just confirmed that it works. Basically let's you search users by id or email then give you ability to change their email/reset password.

For the curious, it looks like this:

Admin dashboard: http://img.skitch.com/20080415-ef6k9c8hpbasi9g137j6u4iqrs.jp...

Clicking "password": http://img.skitch.com/20080415-day5r87i8tbt9iaqrtf73tpnnd.jp...

Clicking "email": http://img.skitch.com/20080415-bg12j2y7wxmeqn44pmctcs69e3.jp...

And clicking "edit" tumblog: http://img.skitch.com/20080415-cg7iwrmc7gu2a58qkmcnfre6ka.jp...

Don't worry, I didn't do anything!

Post reply on HN