Live data from Hacker News

PeopleDAO “exploited” by Google Docs edit

twitter.com

71–80 of 87 posts

Re: PeopleDAO “exploited” by Google Docs edit

#71

Earlier quoted context omitted.

I used to joke about how I was going to make my own shitcoin that was literally just that you could paypal me $10 and I'd add your name to a publicly viewable Google Sheet with your "coin" being that you'd own the row number. I did not realize that was actually how this operated.

I hope you thought about calling it SheetCoin. Please make it. I want row A.

jokes on you, rows are numbers, columns are letters :)

Dibs on Row 13!

Re: PeopleDAO “exploited” by Google Docs edit

#72
post #4

I know this is a low value way of saying this, so, apologies up front but: Fucking lol at their bookkeeping and payout system just being a spreadsheet with no other comparison of truth before submission. We're on course for DAOs to rediscover the basic principles of our existing financial system within the decade.

Also this part:

> We offer the hacker a 10% white hat bounty if he/she would return the stolen fund in next 48 hrs.

I just can't, hahaha. You left your car unlocked with the keys on the dashboard. It's on a boat on its way to a 3rd world country with its plates removed and serial numbers ground off. Good luck.

Re: PeopleDAO “exploited” by Google Docs edit

#73
post #41

This is a beautiful example of the biggest current problem with DAOs and all (and I do mean ALL) crypto projects which aim to interface with the real world (i.e. all projects not doing with purely abstract stuff like DeFi-like tokens, and closed systems like "metaverses"): THEY CAN'T. They really cannot interface with the Real World, without leaking real-world problems into the "perfect" smart contract-driven crypto…

How can you fight fake news with the blockchain?

Re: PeopleDAO “exploited” by Google Docs edit

#74

Earlier quoted context omitted.

I used to joke about how I was going to make my own shitcoin that was literally just that you could paypal me $10 and I'd add your name to a publicly viewable Google Sheet with your "coin" being that you'd own the row number. I did not realize that was actually how this operated.

I hope you thought about calling it SheetCoin. Please make it. I want row A.

This has already been done https://github.com/nalinbhardwaj/shiit-coin

Re: PeopleDAO “exploited” by Google Docs edit

#75
just to be clear, the default permissions on Google Forms do not allow anyone to edit the form just by adding /edit to the URL. the owner of the form has to either (1) specifically add individuals via email address, or (2) change "general access" from 'Restricted' to 'Anyone with the link'. that is the only reason the "hacker" was able to edit the form.

TL;dr the owner of the form changed the permissions to be literally wide open.

you reap what you sow.

Re: PeopleDAO “exploited” by Google Docs edit

#76

Earlier quoted context omitted.

I used to joke about how I was going to make my own shitcoin that was literally just that you could paypal me $10 and I'd add your name to a publicly viewable Google Sheet with your "coin" being that you'd own the row number. I did not realize that was actually how this operated.

I hope you thought about calling it SheetCoin. Please make it. I want row A.

Dibs on rows ASS, GAY and SEX.

Re: PeopleDAO “exploited” by Google Docs edit

#77
post #2

Is clicking on a link really “hacking”? > The accounting lead mistakenly shared a link with edit access in a public channel in discord. The hacker gained edit role via the link.

I'm not sure if something like this also happened here, but I have sometimes a document shared with a few coworkers. While discussing it by email, I have to send them (again) the link because otherwise they can't find it.

Each time, gmail says that "John" will not be able to see the document and offers to make it readable/editable for anyone with a link. It appears in a modal window that blocks sending the message. I must read carefully the modal window to click the correct button. "John" can see the doc because he has a google account, but I'm sending the message to his yahoo email because it's his preferred email.

Anyway, I only have a draft of a math midterm for next week. If a hundred of thousands of dollars were in the line, I'd be very nervous.

Re: PeopleDAO “exploited” by Google Docs edit

#78

Earlier quoted context omitted.

Imagine the number of people who have ownership of business-critical documents in the cloud. Now imagine a venn diagram with the number of people who don't realize that granting any permission at all to "Anyone who has this link" is, in the end, security through obscurity.

If the super long string on a Google doc is “security through obscurity”, so are passwords, 2FA codes, and ssh keys.

A Google Doc ID (or Drive/Sheets/Slides) is a single identifier which denotes a resource in the cloud. It is a name; it is not intended as a secret. "Anyone with the Link" really means anyone. In fact, I would say that "Anyone with the Link" access modes are a hack and a workaround for people who do not have Google accounts. If you rely on privacy, use Google accounts.

So if you created a secret, clandestine, world-readable, anyone-comments, blog post with the slug "http://example.com/correct-horse-battery-staple/" would you really complain when someone brute-force or outright guessed your blog post?

YouTube has "unlisted" videos which are unsearchable and unreachable unless you've been shared a link, but do people freak out when someone stumbles across this shared by others?

Just because a Google Workspaces ID is a long, jumbled-up, base-64 string doesn't mean it is a password or a cryptographically secure secret. It's quite different. It's meant to be well-known by anyone who is intended to have access. The "Anyone with the Link" access simply relies on a circle of friends/colleagues keeping the URL to themselves.

Re: PeopleDAO “exploited” by Google Docs edit

#79
post #20

Earlier quoted context omitted.

> granting any permission at all to "Anyone who has this link" is, in the end, security through obscurity. That's like saying passwords are "security through obscurity" because they're also "obscure" random strings, just like URLs. To try and make my point more clear: Basic auth password url: https://username:randomSecurePassword@webpage.com Google docs edit url: https://docs.google.com/randomLongString/edit How are…

This is about Google docs. In Google docs access control means not just knowing password and username combo, it also means having the device to receive a time limited 2FA code etc. Plus the ability to revoke access. Very much not just obscurity.

Hi, let me introduce you to "Anyone with the link can edit".

Re: PeopleDAO “exploited” by Google Docs edit

#80

So people want to be progressive and use cryptocurrency that is not tied to a government. But when things go wrong they run to the FBI and FTC both run by the government.

People want their eggs and milk privately, but when the shopkeeper steals their money and runs away, they want the police and the courts. That's not really inconsistent.

But these are "don't tax my eggs and milk!" people, and "my shop is police-proof and sale receipts are the law" shopkeepers.
Post reply on HN