Live data from Hacker News

Tell HN: Fiverr left customer files public and searchable

news.ycombinator.com

31–40 of 252 posts

Re: Tell HN: Fiverr left customer files public and searchable

#31

This is crazy! So many tax and other financial forms out in the open. But the most interesting file I’ve seen so far seems to be a book draft titled “HOOD NIGGA AFFIRMATIONS: A Collection of Affirming Anecdotes for Hood Niggas Everywhere”. I made it to page 27 out of 63.

I found someone's manuscript, at first I thought it would be scandalous to find it ghost written, but it actually is just annotations and someone proof reading it, the annotations come up in the PDF

I found the author on Amazon and the book still hasn't been released

this is sad

Re: Tell HN: Fiverr left customer files public and searchable

#32

This is crazy! So many tax and other financial forms out in the open. But the most interesting file I’ve seen so far seems to be a book draft titled “HOOD NIGGA AFFIRMATIONS: A Collection of Affirming Anecdotes for Hood Niggas Everywhere”. I made it to page 27 out of 63.

Link please :pray:

[flagged]

Re: Tell HN: Fiverr left customer files public and searchable

#33
I wrote to security@fiverr.com and they just replied:

"You’re the second person to flag this issue to us

Please note that our records show no contact with Fiverr security regarding this matter ~40 days ago unlike the poster claims. We are currently working to resolve the situation"

Re: Tell HN: Fiverr left customer files public and searchable

#34

Software development jobs are too accessible. Jobs with access to/control over millions of people's data should require some kind of genuine software engineering certification, and there should be business-cratering fines for something as egregious as completely ignoring security reports. It is ridiculous how we've completely normalised leaks like this on a weekly or almost-daily basis.

At least I'm sure LLM tools deploying code to production won't result in this happening more frequently. "Make sure it's secure. Make no mistakes."

Re: Tell HN: Fiverr left customer files public and searchable

#35

I wrote to security@fiverr.com and they just replied: "You’re the second person to flag this issue to us Please note that our records show no contact with Fiverr security regarding this matter ~40 days ago unlike the poster claims. We are currently working to resolve the situation"

So who has more incentive to lie, fiverr or OP?

Re: Tell HN: Fiverr left customer files public and searchable

#36

Software development jobs are too accessible. Jobs with access to/control over millions of people's data should require some kind of genuine software engineering certification, and there should be business-cratering fines for something as egregious as completely ignoring security reports. It is ridiculous how we've completely normalised leaks like this on a weekly or almost-daily basis.

Teachers have to be licensed and keep up on licensing.

Plumbers. Electricians. Lawyers. Doctors. Hell, I have to get a license to run my own business.

Why shouldn't software come with a branch for licenses if you're working with sensitive data?

Re: Tell HN: Fiverr left customer files public and searchable

#38

I wrote to security@fiverr.com and they just replied: "You’re the second person to flag this issue to us Please note that our records show no contact with Fiverr security regarding this matter ~40 days ago unlike the poster claims. We are currently working to resolve the situation"

I have uploaded the email here: https://gist.github.com/aidanbh/3da7cecb3e2496e5c5110b88f21b...

(technically, I guess that doesn't prove anything other than it is in my Sent folder? it has a message ID but I guess only the purelymail admin could confirm that)

In any event, this should never have required an outside reminder. The indexing issue may be something non obvious. But the core decision not to use signed/expiring URLs is nothing less than good old security by obscurity.

Re: Tell HN: Fiverr left customer files public and searchable

#39
post #35

I wrote to security@fiverr.com and they just replied: "You’re the second person to flag this issue to us Please note that our records show no contact with Fiverr security regarding this matter ~40 days ago unlike the poster claims. We are currently working to resolve the situation"

So who has more incentive to lie, fiverr or OP?

Is this even a question? Obviously, the company that has publicly posted people's tax forms on the internet is very trustworthy and we should eagerly believe everything they say.

I don't think it even comes down to "lying". It's possible that they genuinely believe they didn't receive contact, but given that they are verifiably completely and totally incompetent and have no right to be employed in their current role, they've earned exactly zero benefit of doubt.

Re: Tell HN: Fiverr left customer files public and searchable

#40
post #35

Earlier quoted context omitted.

So who has more incentive to lie, fiverr or OP?

Is this even a question? Obviously, the company that has publicly posted people's tax forms on the internet is very trustworthy and we should eagerly believe everything they say. I don't think it even comes down to "lying". It's possible that they genuinely believe they didn't receive contact, but given that they are verifiably completely and totally incompetent and have no right to be employed in their current role,…

(weird to share any details about this incident to uninvolved parties via email anyway)
Post reply on HN