Earlier quoted context omitted.
Click on 'current usage' in your account and it takes you to your current invoice, which is accessible via the URL that he mentions. It appears to be only the current months usage / invoice that is vulnerable.
EDIT: removing URLs because it's the right thing to do.
Heroku Invoice Security Issue - You can see anyone's invoice
21–27 of 27 posts
Re: Heroku Invoice Security Issue - You can see anyone's invoice
#22Re: Heroku Invoice Security Issue - You can see anyone's invoice
#23Why do people use Heroku? I never understood the appeal. Oh.. because they have a good graphic designer. Lol. "Forget servers, instances, and VMs. Focus on processes." If that doesn't raise some red flags for you then you get what you deserve.
Yep, $212 million in value built in an extremely short time. Because of a good graphic designer, sure.
That's less then $100/GB/Month.
With low prices like that it must be hard for people to resist.
Re: Heroku Invoice Security Issue - You can see anyone's invoice
#24There's too much sensitive data here - it would be trivial to write a script that banked it all for later analysis.
Re: Heroku Invoice Security Issue - You can see anyone's invoice
#25Re: Heroku Invoice Security Issue - You can see anyone's invoice
#26Re: Heroku Invoice Security Issue - You can see anyone's invoice
#27I'm pretty appalled that you submitted this to, arguably, one of the most-visited sites for tech news, without at least giving them time to address the problem. This isn't a case of something small going unnoticed, resulting in a bit of a laugh and giggle. This is people's billing details, and you've just explained how to exploit the bug in complete detail. I'm really unhappy that this sort of thing even crossed your…
This is the sort of thing that I, as a Heroku customer, really want to no about. Not because my personal information is at risk - no credit card #'s or anything are accessible - but because it changes my perspective on Heroku. This vulnerability is just plain sloppy on their part - I really though that the folks at Heroku were smarter than this.
If this leak provided access to any more sensitive data, like credit card #'s or SSN's I would 100% agree with you - notify Heroku and let them fix it first. But the only real harm I see coming from this being posted pre-fix is embarrassment for Heroku.