Live data from Hacker News

Tumblr security hole (the gaping kind)

news.ycombinator.com

41–50 of 85 posts

Re: Tumblr security hole (the gaping kind)

#48

Probably better to let Tumblr know first, then us. Edit: just confirmed that it works. Basically let's you search users by id or email then give you ability to change their email/reset password.

Interestingly, I've looked at your comment about 10 times and just now noticed that you transposed the 'm' and 'b' in Tumblr. :)

Re: Tumblr security hole (the gaping kind)

#49
post #17
post #13

Earlier quoted context omitted.

What if the lead developer is the CEO? What would you suggest then? Shut down the company? Errare humanum est.

Yes, Errare human est. I guess natural selection will take care of companies like this. If the developer is the CEO, then the investors should be concerned.

To err is human, but to really foul things up, you need a computer for that.

Re: Tumblr security hole (the gaping kind)

#50
post #32

I didn't know what Tumbler is and I created an account just to confirm the hack (the security hole is still there). But this got me thinking about another post at HN on how to market your site - I guess a blatant (fake?) security hole is one way to do it.

Uh yeah. You must be part of the same marketing team that advises car manufacturers to stage huge vehicle safety recalls. That'll really get the customers knocking.

Tumblr has a great but small team, just like most of us on this site. As someone who makes mistakes, I offer them empathy and sympathy.

Post reply on HN