Live data from Hacker News

Tumblr security hole (the gaping kind)

news.ycombinator.com

71–80 of 85 posts

Re: Tumblr security hole (the gaping kind)

#72
does anyone else find it ironic that in apologizing for their SNAFU they list the full name of the one person effected most by the incident?

"We’d also like to make a special apology to Julia Allison, whose account was temporarily affected by our mistake."

Re: Tumblr security hole (the gaping kind)

#73
post #29
post #27

What the hell is Tumblr? And what happened to vowels?

Tumblr is an awesome blogging platform that's dead simple and has some Twitteresque social features (ie following) built in. Also has a great bookmarklet and a neat api.

And a non-existant QA department apparently?

Re: Tumblr security hole (the gaping kind)

#74
post #8

Did you or your friend happen to report this to them before posting it here?

yeah he said he told them. I would have more sympathy if it was an obscure hole, but something this big is just disrespectful to their users.

Disrespectful to their users? Tumblr is free. I don't think they owe their users absolute iron clad security.

Re: Tumblr security hole (the gaping kind)

#75
post #11
post #9

Earlier quoted context omitted.

a little harsh maybe....developers make mistakes...probably just forgot about it while trying to get the initial release out the door.... its not like tumblr is a bank or the DoD

ok, maybe :) But forgeting to secure your admin area deserves more than a simple warning. Can you imagine if the person that discovered the vulnerability decided to delete all the user accounts?

Or try out the usernames and passwords on say BofA?

Re: Tumblr security hole (the gaping kind)

#78
post #29

Earlier quoted context omitted.

Tumblr is an awesome blogging platform that's dead simple and has some Twitteresque social features (ie following) built in. Also has a great bookmarklet and a neat api.

And a non-existant QA department apparently?

QA departments are notorious for not being very creative. You'd need a star QA department to find the /admin hole, I think.

Re: Tumblr security hole (the gaping kind)

#79
post #78

Earlier quoted context omitted.

And a non-existant QA department apparently?

QA departments are notorious for not being very creative. You'd need a star QA department to find the /admin hole, I think.

No, you just need functional tests. Having these kind of bugs in a spare time project is fine, but if you call yourself a startup and ask customers to trust you with data, you need to seriously consider security issues.

Re: Tumblr security hole (the gaping kind)

#80
post #48

Earlier quoted context omitted.

Interestingly, I've looked at your comment about 10 times and just now noticed that you transposed the 'm' and 'b' in Tumblr. :)

Whoops. Well they've done studies to show common typos don't affect the meaning too much. I've updated it though - "Aoccdrnig to a rscheearch at Cmabrigde Uinervtisy, it deosn't mttaer in waht oredr the ltteers in a wrod are, the olny iprmoetnt tihng is taht the frist and lsat ltteer be at the rghit pclae. The rset can be a toatl mses and you can sitll raed it wouthit porbelm. Tihs is bcuseae the huamn mnid deos not…

lmao
Post reply on HN