Live data from Hacker News

Tumblr security hole (the gaping kind)

news.ycombinator.com

61–70 of 85 posts

Re: Tumblr security hole (the gaping kind)

#61
post #33

Probably better to let Tumblr know first, then us. Edit: just confirmed that it works. Basically let's you search users by id or email then give you ability to change their email/reset password.

I just shot them a mail to let them know. Ironically they don't obey one of the primary rules of usability for websites: have a link to contact info on the front page.

I've complained about it before. Not only is it not on the front page, for a long time it just did not exist.

Re: Tumblr security hole (the gaping kind)

#67
post #63

Earlier quoted context omitted.

More like a bad and/or careless programmer...

More like platforms that pride themselves on always leaving security entirely up to the programmer...

This is the dumbest comment I've ever read on here.

Re: Tumblr security hole (the gaping kind)

#68
post #49
post #17

Earlier quoted context omitted.

Yes, Errare human est. I guess natural selection will take care of companies like this. If the developer is the CEO, then the investors should be concerned.

To err is human, but to really foul things up, you need a computer for that.

That reminds me of Arthur C. Clarke's 1953 science fiction short story "The Nine Billion Names of God".

http://en.wikipedia.org/wiki/The_Nine_Billion_Names_of_God

Re: Tumblr security hole (the gaping kind)

#69
post #58
post #56

Earlier quoted context omitted.

No, it was only open and public for an hour. It could have been open for months, maybe longer.

It was the result of a change today, right before it hit Hacker News (so sayeth Marco of tumblr in the #tumblrs irc channel, anyway; I believe him).

As we know, hackers regularly turn random door knobs to see which doors open. Logs i can see show more black hat attempts than white hat, so either OldGregg's friend got lucky or a few exploits might have already been made.

Re: Tumblr security hole (the gaping kind)

#70
The MIT computer lab used to forgo passwords. If you wanted to dick with the system you could, so it removed the thrill of "breaking in". You could mess with other people's accounts but they could mess with yours, too. Kind of like how everyone in Texas carries guns starting in kindergarten and so everyone is really polite.

I think it's a great lesson so I think I'll make my startup's vital information globally accessible (admin functions, source code, even my billing info for the ISP) and trust to my fellow human beings' goodwill.

I love you guys!!

Post reply on HN