Live data from Hacker News

Tell HN: Fiverr left customer files public and searchable

news.ycombinator.com

71–80 of 252 posts

Re: Tell HN: Fiverr left customer files public and searchable

#71

Software development jobs are too accessible. Jobs with access to/control over millions of people's data should require some kind of genuine software engineering certification, and there should be business-cratering fines for something as egregious as completely ignoring security reports. It is ridiculous how we've completely normalised leaks like this on a weekly or almost-daily basis.

People at my company don't even lock their computer when they walk away from their desk. Which yeah it's in a controlled environment but still.

Re: Tell HN: Fiverr left customer files public and searchable

#72
post #44

Earlier quoted context omitted.

We're going the other way: now any random vibe coded slop is the norm.

Normalize "vibe-plumbing"

It is, it just usually results in immediate calls to actual plumbers without anyone else finding out. Or it’s hidden behind some new drywall and paint until a different occupant finds out.

Re: Tell HN: Fiverr left customer files public and searchable

#73
post #71

Software development jobs are too accessible. Jobs with access to/control over millions of people's data should require some kind of genuine software engineering certification, and there should be business-cratering fines for something as egregious as completely ignoring security reports. It is ridiculous how we've completely normalised leaks like this on a weekly or almost-daily basis.

People at my company don't even lock their computer when they walk away from their desk. Which yeah it's in a controlled environment but still.

My work has a “donuts” slack channel for this. You find an unlocked computer you post “donuts on me!” Social pressure says they buy the office donuts.

Still get a few a week, but at least it’s public and amusing.

Re: Tell HN: Fiverr left customer files public and searchable

#74

Earlier quoted context omitted.

> should require some kind of genuine software engineering certification Wouldn't change a thing, other than add another hassle you have to pay for to do your job. This is the result of carelessness, not someone who didn't know that private data should be private because they weren't certified.

This is the result of somebody who has no idea how the fuck the tech they're using works. They surely knew it should be private, but they did not know that they were making it publicly available because they were blindly fumbling their way around in a job beyond their competence level. There is a 0% chance this was ordinary carelessness, in the form of "I know better but don't care enough", this is so clearly a case…

Any time someone tries to suggest certification as a solution I ask the same question: How would it have solved this problem?

Would the certification require someone to take an official certification test for the framework used?

And therefore we’re only allowed to use frameworks which have certification tests available?

If you want to write some new software, do you have to generate a certification for it and get that approved so people are allowed to use it?

Sounds like a great way to force us all to use Big Company approved software because they’re the only ones with pockets deep enough to play all of the certification games

Re: Tell HN: Fiverr left customer files public and searchable

#76
@dang example query feels incredibly doxxy, and feels bad form to link directly to full copies of people's [stuff] and [personal info] as seen on this page :/

I know this is all Fiverr's fault for allegedly missing the responsible disclosure but now is this the ideal way for us to discuss, with these particular examples? I ask not to spare Fiverr, but I would be so mad if I were first for the result in OP or my personal info linked directly...

Re: Tell HN: Fiverr left customer files public and searchable

#77

Software development jobs are too accessible. Jobs with access to/control over millions of people's data should require some kind of genuine software engineering certification, and there should be business-cratering fines for something as egregious as completely ignoring security reports. It is ridiculous how we've completely normalised leaks like this on a weekly or almost-daily basis.

good thing it's getting easier to code - nothing bad can come of this :-)

Re: Tell HN: Fiverr left customer files public and searchable

#79

[flagged]

It kind of is, though. Google doesn't randomly try to visit every URL on the internet. It follows links. Therefore, for these files to be indexed by Google, they need to be linked to from somewhere.

Good thing, otherwise they would have exposed countless photos via Google Photos.

Today, a photo file might be hosted at:

  photos.fife.usercontent.google.com/pw/[snip]=w[####]-h[####]-s-no-gm?authuser=0
But it used to be a little closer to:

  ...[google_site].com/[superLongAlphanumeric].jpg
And no auth required, URL only!
Post reply on HN