Live data from Hacker News

I found 39 Algolia admin keys exposed across open source documentation sites

benzimmermann.dev

41–50 of 62 posts

Re: I found 39 Algolia admin keys exposed across open source documentation sites

#42
post #28

the wildest part is algolia just not responding. you email them saying "hey 39 of your customers have admin keys in their frontend" and they ghost you? thats way worse than the keys themselves imo. like the whole point of docsearch is they manage the crawling FOR you, but then the "run your own crawler" docs basically hand you a footgun with zero guardrails. they could just... not issue admin-scoped keys through that…

Why contact Algolia when it is the users' responsibility to handle their keys? Contact all the users.

It is the users responsibility to operate foot guns responsibly.

Re: I found 39 Algolia admin keys exposed across open source documentation sites

#44
post #38

Twenty years ago every PHP website had search. We forgot how to do it.

Having a search and having a functional search are two very different things though. To this day, the search on many sites is so bad that it's actually better to use a search engine and scope by site rather than use the site search.

Re: I found 39 Algolia admin keys exposed across open source documentation sites

#45
post #28

the wildest part is algolia just not responding. you email them saying "hey 39 of your customers have admin keys in their frontend" and they ghost you? thats way worse than the keys themselves imo. like the whole point of docsearch is they manage the crawling FOR you, but then the "run your own crawler" docs basically hand you a footgun with zero guardrails. they could just... not issue admin-scoped keys through that…

Why contact Algolia when it is the users' responsibility to handle their keys? Contact all the users.

because if it's easy to dangerously use one's product that reflect poorly on the product. Algolia should help its clients from making silly mistakes.

Re: I found 39 Algolia admin keys exposed across open source documentation sites

#46
post #23

I have been developing an OpenClaw-like agent that automates exactly this type of attack.

Why? This is just regex search and there are plenty of tools that do this perfectly fine.

because the poster works for Accenture.

https://timesofindia.indiatimes.com/technology/tech-news/acc...

Re: I found 39 Algolia admin keys exposed across open source documentation sites

#48

Earlier quoted context omitted.

Yes, and in the real world where Grice's Maxim of Relevance is in force, then when the secrets issuer that is the subject of the discussion isn't one of those partners, then an informative "reminder" that GitHub "has a secret scanning program" with a bunch of other partners is not actually informative. It's as superfluous and unhelpful as calling to let someone know you're not interested in the item they've posted fo…

It's more useful than telling someone that their statement is a tautology in formal logic.

No it's not.

Re: I found 39 Algolia admin keys exposed across open source documentation sites

#49
post #28

the wildest part is algolia just not responding. you email them saying "hey 39 of your customers have admin keys in their frontend" and they ghost you? thats way worse than the keys themselves imo. like the whole point of docsearch is they manage the crawling FOR you, but then the "run your own crawler" docs basically hand you a footgun with zero guardrails. they could just... not issue admin-scoped keys through that…

Why contact Algolia when it is the users' responsibility to handle their keys? Contact all the users.

The comment you're responding to is output of an LLM.

Re: I found 39 Algolia admin keys exposed across open source documentation sites

#50

Earlier quoted context omitted.

It's more useful than telling someone that their statement is a tautology in formal logic.

No it's not.

Yes it is. Reminding somebody of this feature is useful to somebody, even if it's not completely relevant to the topic being discussed. Calling out a supposed tautology is the opposite of useful: it helps nobody and just clutters things up.
Post reply on HN