Probably better to let Tumblr know first, then us. Edit: just confirmed that it works. Basically let's you search users by id or email then give you ability to change their email/reset password.
I just shot them a mail to let them know. Ironically they don't obey one of the primary rules of usability for websites: have a link to contact info on the front page.
Tumblr security hole (the gaping kind)
61–70 of 85 posts
Re: Tumblr security hole (the gaping kind)
#62Chalk one up for PHP!
Re: Tumblr security hole (the gaping kind)
#63Re: Tumblr security hole (the gaping kind)
#64Re: Tumblr security hole (the gaping kind)
#65Re: Tumblr security hole (the gaping kind)
#66Re: Tumblr security hole (the gaping kind)
#67Re: Tumblr security hole (the gaping kind)
#68Earlier quoted context omitted.
Yes, Errare human est. I guess natural selection will take care of companies like this. If the developer is the CEO, then the investors should be concerned.
To err is human, but to really foul things up, you need a computer for that.
Re: Tumblr security hole (the gaping kind)
#69Earlier quoted context omitted.
No, it was only open and public for an hour. It could have been open for months, maybe longer.
It was the result of a change today, right before it hit Hacker News (so sayeth Marco of tumblr in the #tumblrs irc channel, anyway; I believe him).
Re: Tumblr security hole (the gaping kind)
#70I think it's a great lesson so I think I'll make my startup's vital information globally accessible (admin functions, source code, even my billing info for the ISP) and trust to my fellow human beings' goodwill.
I love you guys!!