I wrote to security@fiverr.com and they just replied: "You’re the second person to flag this issue to us Please note that our records show no contact with Fiverr security regarding this matter ~40 days ago unlike the poster claims. We are currently working to resolve the situation"
I have uploaded the email here: https://gist.github.com/aidanbh/3da7cecb3e2496e5c5110b88f21b... (technically, I guess that doesn't prove anything other than it is in my Sent folder? it has a message ID but I guess only the purelymail admin could confirm that) In any event, this should never have required an outside reminder. The indexing issue may be something non obvious. But the core decision not to use signed/expi…
Tell HN: Fiverr left customer files public and searchable
91–100 of 252 posts
Re: Tell HN: Fiverr left customer files public and searchable
#92Earlier quoted context omitted.
Nothing- they are just hoping this will blow over.
Do I have to start emailing the people in the leaked documents with screenshots?
Re: Tell HN: Fiverr left customer files public and searchable
#93Extremely bad stuff here. Can't believe it's been 7 hours now and you can still pull up people's complete prepared tax returns right from a Google search. This should be a business-ending breach of trust and good practices, but I worry there's probably a lack of regulatory might or will to make anything happen.
Utterly inexcusable that this is still up after so many hours.
Re: Tell HN: Fiverr left customer files public and searchable
#94Re: Tell HN: Fiverr left customer files public and searchable
#95Wow, surprised this isn't blowing up more. Leaking form 1040s is egregious, let alone getting them indexed by Google...
Once the leak is plugged, I would hope that Fiverr gets absolutely raked over the coals, this is egregious.
Re: Tell HN: Fiverr left customer files public and searchable
#96Re: Tell HN: Fiverr left customer files public and searchable
#97Software development jobs are too accessible. Jobs with access to/control over millions of people's data should require some kind of genuine software engineering certification, and there should be business-cratering fines for something as egregious as completely ignoring security reports. It is ridiculous how we've completely normalised leaks like this on a weekly or almost-daily basis.
They may be part of it, but as a publicly traded company, there's got to be a at least a few people there with a fancy pedigree (not that that actually means they are good at their job or care). But if such a test existed, they presumably would have passed it. They also have an ISO 27001 certificate (they try to claim a bunch of AWSs certs by proxy on their security page, which is ironic as they say AWS stores most o…
Sure, and now they could have their credentials revoked, potential be legally liable, and never find work in this field again which would prevent them from cocking up another company this way
Re: Tell HN: Fiverr left customer files public and searchable
#98There are health stuff too... and they are not even paying attention to this matter https://fiverr-res.cloudinary.com/image/upload/f_pdf,q_auto/...
Re: Tell HN: Fiverr left customer files public and searchable
#99Earlier quoted context omitted.
I have uploaded the email here: https://gist.github.com/aidanbh/3da7cecb3e2496e5c5110b88f21b... (technically, I guess that doesn't prove anything other than it is in my Sent folder? it has a message ID but I guess only the purelymail admin could confirm that) In any event, this should never have required an outside reminder. The indexing issue may be something non obvious. But the core decision not to use signed/expi…
I wouldn't be surprised if their email blocks all unusual TLDs like your .dev.
Re: Tell HN: Fiverr left customer files public and searchable
#100Software development jobs are too accessible. Jobs with access to/control over millions of people's data should require some kind of genuine software engineering certification, and there should be business-cratering fines for something as egregious as completely ignoring security reports. It is ridiculous how we've completely normalised leaks like this on a weekly or almost-daily basis.
> should require some kind of genuine software engineering certification Wouldn't change a thing, other than add another hassle you have to pay for to do your job. This is the result of carelessness, not someone who didn't know that private data should be private because they weren't certified.
That's exactly what certification or licensure does; it imposes financial, civil, and criminal penalties for malpractice.
The liability of incurring penalties quickly outweigh the benefit of arbitraging costs with an unqualified practitioner.