Live data from Hacker News

Phpfog "Down for maintenance"

phpfogsucks.com

11–20 of 125 posts

Re: Phpfog "Down for maintenance"

#11
post #7

What a dick move. Did these idiots actually publish their names in relation to this? Coming from "security experts" this is the most unprofessional thing I've ever seen.

Absolutely. Especially taking over phpfog.com and their twitter account. All of the folks on that list (http://elliotspeck.com/, http://johnduhart.me/) seem to be just teenagers though.

Re: Phpfog "Down for maintenance"

#12
post #7

What a dick move. Did these idiots actually publish their names in relation to this? Coming from "security experts" this is the most unprofessional thing I've ever seen.

A mirror of the code dump (referred to in a tweet linked in this discussion) is hosted on a 16 webdev from Australia...

Atleast they were kind enough to remove all API keys and passwords from the code dump.

Re: Phpfog "Down for maintenance"

#13
post #7

What a dick move. Did these idiots actually publish their names in relation to this? Coming from "security experts" this is the most unprofessional thing I've ever seen.

From their bios, they appear to be sixteen-year-olds.

Re: Phpfog "Down for maintenance"

#15
post #9

Earlier quoted context omitted.

Depends on the type of instance they spin up, but I would definitely tend to agree with you! Security in shared hosting is extremely hard (I used to be a sys admin for a hosting company in a prior life), especially since there is no good way to separate everyone from each other without making performance suck completely, FreeBSD jails alleviate some of it, but you start having scalability issues, PHP running in php-f…

Heroku has done it reasonably well too and they seem to do it only with POSIX permissions for the most part.

That is definitely interesting, although for Ruby that is slightly simpler because there is no real way like PHP to have a single instance of Ruby deal with all of the requests (talking about mod_php and PHP-fastcgi, not php-cgi which spawns a process per request).

Re: Phpfog "Down for maintenance"

#16
post #7

What a dick move. Did these idiots actually publish their names in relation to this? Coming from "security experts" this is the most unprofessional thing I've ever seen.

A mirror of the code dump (referred to in a tweet linked in this discussion) is hosted on a 16 webdev from Australia... Atleast they were kind enough to remove all API keys and passwords from the code dump.

Actually, I don't know if they did. If you check the config dump, there are some passwords left.

This can't be legal.

Re: Phpfog "Down for maintenance"

#20
post #7

What a dick move. Did these idiots actually publish their names in relation to this? Coming from "security experts" this is the most unprofessional thing I've ever seen.

A mirror of the code dump (referred to in a tweet linked in this discussion) is hosted on a 16 webdev from Australia... Atleast they were kind enough to remove all API keys and passwords from the code dump.

the dumps are no longer available in their site
Post reply on HN