Probably better to let Tumblr know first, then us. Edit: just confirmed that it works. Basically let's you search users by id or email then give you ability to change their email/reset password.
Tumblr security hole (the gaping kind)
41–50 of 85 posts
Re: Tumblr security hole (the gaping kind)
#42Re: Tumblr security hole (the gaping kind)
#43Re: Tumblr security hole (the gaping kind)
#44Re: Tumblr security hole (the gaping kind)
#45Oh, by the way, if you can't code, have somebody look at your code.
Re: Tumblr security hole (the gaping kind)
#46Re: Tumblr security hole (the gaping kind)
#47Re: Tumblr security hole (the gaping kind)
#48Probably better to let Tumblr know first, then us. Edit: just confirmed that it works. Basically let's you search users by id or email then give you ability to change their email/reset password.
Re: Tumblr security hole (the gaping kind)
#49Earlier quoted context omitted.
What if the lead developer is the CEO? What would you suggest then? Shut down the company? Errare humanum est.
Yes, Errare human est. I guess natural selection will take care of companies like this. If the developer is the CEO, then the investors should be concerned.
Re: Tumblr security hole (the gaping kind)
#50I didn't know what Tumbler is and I created an account just to confirm the hack (the security hole is still there). But this got me thinking about another post at HN on how to market your site - I guess a blatant (fake?) security hole is one way to do it.
Tumblr has a great but small team, just like most of us on this site. As someone who makes mistakes, I offer them empathy and sympathy.