Software development jobs are too accessible. Jobs with access to/control over millions of people's data should require some kind of genuine software engineering certification, and there should be business-cratering fines for something as egregious as completely ignoring security reports. It is ridiculous how we've completely normalised leaks like this on a weekly or almost-daily basis.
Tell HN: Fiverr left customer files public and searchable
71–80 of 252 posts
Re: Tell HN: Fiverr left customer files public and searchable
#72Earlier quoted context omitted.
We're going the other way: now any random vibe coded slop is the norm.
Normalize "vibe-plumbing"
Re: Tell HN: Fiverr left customer files public and searchable
#73Software development jobs are too accessible. Jobs with access to/control over millions of people's data should require some kind of genuine software engineering certification, and there should be business-cratering fines for something as egregious as completely ignoring security reports. It is ridiculous how we've completely normalised leaks like this on a weekly or almost-daily basis.
People at my company don't even lock their computer when they walk away from their desk. Which yeah it's in a controlled environment but still.
Still get a few a week, but at least it’s public and amusing.
Re: Tell HN: Fiverr left customer files public and searchable
#74Earlier quoted context omitted.
> should require some kind of genuine software engineering certification Wouldn't change a thing, other than add another hassle you have to pay for to do your job. This is the result of carelessness, not someone who didn't know that private data should be private because they weren't certified.
This is the result of somebody who has no idea how the fuck the tech they're using works. They surely knew it should be private, but they did not know that they were making it publicly available because they were blindly fumbling their way around in a job beyond their competence level. There is a 0% chance this was ordinary carelessness, in the form of "I know better but don't care enough", this is so clearly a case…
Would the certification require someone to take an official certification test for the framework used?
And therefore we’re only allowed to use frameworks which have certification tests available?
If you want to write some new software, do you have to generate a certification for it and get that approved so people are allowed to use it?
Sounds like a great way to force us all to use Big Company approved software because they’re the only ones with pockets deep enough to play all of the certification games
Re: Tell HN: Fiverr left customer files public and searchable
#75Re: Tell HN: Fiverr left customer files public and searchable
#76I know this is all Fiverr's fault for allegedly missing the responsible disclosure but now is this the ideal way for us to discuss, with these particular examples? I ask not to spare Fiverr, but I would be so mad if I were first for the result in OP or my personal info linked directly...
Re: Tell HN: Fiverr left customer files public and searchable
#77Software development jobs are too accessible. Jobs with access to/control over millions of people's data should require some kind of genuine software engineering certification, and there should be business-cratering fines for something as egregious as completely ignoring security reports. It is ridiculous how we've completely normalised leaks like this on a weekly or almost-daily basis.
Re: Tell HN: Fiverr left customer files public and searchable
#78Re: Tell HN: Fiverr left customer files public and searchable
#79[flagged]
It kind of is, though. Google doesn't randomly try to visit every URL on the internet. It follows links. Therefore, for these files to be indexed by Google, they need to be linked to from somewhere.
Today, a photo file might be hosted at:
photos.fife.usercontent.google.com/pw/[snip]=w[####]-h[####]-s-no-gm?authuser=0
But it used to be a little closer to: ...[google_site].com/[superLongAlphanumeric].jpg
And no auth required, URL only!