Live data from Hacker News

Tell HN: Fiverr left customer files public and searchable

news.ycombinator.com

81–90 of 252 posts

Re: Tell HN: Fiverr left customer files public and searchable

#81
post #51

it's been 5 hours. even manual action to take down the most sensitive files should have completed about 3 hours ago at most. what is happening.

Nothing- they are just hoping this will blow over.

Do I have to start emailing the people in the leaked documents with screenshots?

Re: Tell HN: Fiverr left customer files public and searchable

#83
post #46

Wow, the other comments weren't exaggerating. This is really bad. If my tax returns or other data were part of this, I might consider legal action. I wonder if somewhere like Wired/Ars Technica/404media might pick this up?

Thanks, tip lines were a good idea

Re: Tell HN: Fiverr left customer files public and searchable

#84
post #64

Earlier quoted context omitted.

it's worse than you think – it's an admin password to the ~whole site~

How does an admin password to the whole site end up on Fiverr?

There are lots of passwords there (though one wonder if they were rotated). Basically, the people doing the hiring are sending PDFs with their credentials to the contractors to do the job.

Re: Tell HN: Fiverr left customer files public and searchable

#85

Earlier quoted context omitted.

This is the result of somebody who has no idea how the fuck the tech they're using works. They surely knew it should be private, but they did not know that they were making it publicly available because they were blindly fumbling their way around in a job beyond their competence level. There is a 0% chance this was ordinary carelessness, in the form of "I know better but don't care enough", this is so clearly a case…

Any time someone tries to suggest certification as a solution I ask the same question: How would it have solved this problem? Would the certification require someone to take an official certification test for the framework used? And therefore we’re only allowed to use frameworks which have certification tests available? If you want to write some new software, do you have to generate a certification for it and get tha…

The fact that you're thinking purely in frameworks is the exact problem that plagues the software industry. Framework-focused development is why we're in this mess; frameworks make it easy for people who don't understand how to program to publish shitty software by copying-and-pasting code and fudging around a few strings or variables to match their use case. That kind of accessibility is great for low-stakes software, letting anyone make interesting toys, but should be completely unacceptable in a professional environment with, for example, people's fucking tax documentation at stake.

If I had my way, the certification process starts at the bottom of the stack, ie. you should be expected to have a functional knowledge of assembly instructions, memory management, registers, the call stack, and build up from there. Not that we need to write assembly on a daily basis, but all of the abstractions are built on top of that, and you cannot realistically engineer secure software if you don't understand what is being abstracted away. If you do understand the things being abstracted away, you have the fundamentals necessary to do good work with any programming language or framework. Throw in another certification starting from networking fundamentals if your job involves that. 30 years ago, most professional programmers had this level of understanding as table stakes, so we can hardly say it's an unrealistic burden that's impossible to meet.

Would it be a higher barrier to entry that massively cuts the size of the field working on sensitive software and slows software development down, yes. That is exactly what we need. There was a time when people built bridges that collapsed, then we implemented standards and expected engineers to do real work to make sure that didn't happen. Is that work expensive and expertise-intensive, yes, do bridges still collapse, only very rarely. We are witnessing software bridge collapses on a weekly basis, which should be seen as completely unacceptable. The harm is less obvious than when everyone on a bridge dies, but I do think that routinely leaking millions of people's sensitive data is causing serious harm and likely does lead to people dying in second-order effects.

Re: Tell HN: Fiverr left customer files public and searchable

#86
post #46

Wow, the other comments weren't exaggerating. This is really bad. If my tax returns or other data were part of this, I might consider legal action. I wonder if somewhere like Wired/Ars Technica/404media might pick this up?

https://fiverr-res.cloudinary.com/image/upload/f_pdf,q_auto/...

This is too funny

Re: Tell HN: Fiverr left customer files public and searchable

#87
Given the existing DMCA requests and the fact that Google has become way less aggressive about indexing this stuff, it's clear this has been going on for a while. My guess is they've gutted enough of their internal processes that they literally can't restrict access to these files without breaking their own platform.

You really can't make this shit up: https://www.linkedin.com/feed/update/urn:li:activity:7445526...

The real question is: will Fiverr be the first company to truly crash and burn from an "AI-first" approach? Go LLM, go mayhem!

Re: Tell HN: Fiverr left customer files public and searchable

#88
post #71

Software development jobs are too accessible. Jobs with access to/control over millions of people's data should require some kind of genuine software engineering certification, and there should be business-cratering fines for something as egregious as completely ignoring security reports. It is ridiculous how we've completely normalised leaks like this on a weekly or almost-daily basis.

People at my company don't even lock their computer when they walk away from their desk. Which yeah it's in a controlled environment but still.

We used to flip display upside down in display options, which also reverses the mouse. We'd then lock the PC and disconnect the keyboard. After they figured out the keyboard had been pulled they often couldn't work out why their screen was upside down...

Re: Tell HN: Fiverr left customer files public and searchable

#89
post #46

Wow, the other comments weren't exaggerating. This is really bad. If my tax returns or other data were part of this, I might consider legal action. I wonder if somewhere like Wired/Ars Technica/404media might pick this up?

https://fiverr-res.cloudinary.com/image/upload/f_pdf,q_auto/... This is too funny

Personally, this is the funniest one to me. It turns out Fiverr uses cloudinary for their internal documents as well. (Note: this one is not confidential and is public information)

https://fiverr-res.cloudinary.com/image/upload/f_pdf,q_auto/...

Post reply on HN