Live data from Hacker News

Tell HN: Fiverr left customer files public and searchable

news.ycombinator.com

91–100 of 252 posts

Re: Tell HN: Fiverr left customer files public and searchable

#91

I wrote to security@fiverr.com and they just replied: "You’re the second person to flag this issue to us Please note that our records show no contact with Fiverr security regarding this matter ~40 days ago unlike the poster claims. We are currently working to resolve the situation"

I have uploaded the email here: https://gist.github.com/aidanbh/3da7cecb3e2496e5c5110b88f21b... (technically, I guess that doesn't prove anything other than it is in my Sent folder? it has a message ID but I guess only the purelymail admin could confirm that) In any event, this should never have required an outside reminder. The indexing issue may be something non obvious. But the core decision not to use signed/expi…

I wouldn't be surprised if their email blocks all unusual TLDs like your .dev.

Re: Tell HN: Fiverr left customer files public and searchable

#92
post #81
post #51

Earlier quoted context omitted.

Nothing- they are just hoping this will blow over.

Do I have to start emailing the people in the leaked documents with screenshots?

Leaving a paper trail of you having accessed unauthorized private info is a bad idea, some crazy lawyer could decide to include you in a suit. Just not worth the hassle. Email a tip line about the general situation.

Re: Tell HN: Fiverr left customer files public and searchable

#93
post #70

Extremely bad stuff here. Can't believe it's been 7 hours now and you can still pull up people's complete prepared tax returns right from a Google search. This should be a business-ending breach of trust and good practices, but I worry there's probably a lack of regulatory might or will to make anything happen.

It's very unfortunate but a significant amount of the most damaging stuff in this is from the underprivileged and those with minimal means who were trying to find help they could afford. Non-profits trying to get website help, confidential reports for charities trying to get translations, children seeking therapy (fiverr has a therapy category!?) for some truly dark stuff.

Utterly inexcusable that this is still up after so many hours.

Re: Tell HN: Fiverr left customer files public and searchable

#95
post #3

Wow, surprised this isn't blowing up more. Leaking form 1040s is egregious, let alone getting them indexed by Google...

I want to believe that it's people keeping mum until it's fixed so that the leaked PII isn't spread more widely, minimize the risk of bad actors scraping it all.

Once the leak is plugged, I would hope that Fiverr gets absolutely raked over the coals, this is egregious.

Re: Tell HN: Fiverr left customer files public and searchable

#97

Software development jobs are too accessible. Jobs with access to/control over millions of people's data should require some kind of genuine software engineering certification, and there should be business-cratering fines for something as egregious as completely ignoring security reports. It is ridiculous how we've completely normalised leaks like this on a weekly or almost-daily basis.

They may be part of it, but as a publicly traded company, there's got to be a at least a few people there with a fancy pedigree (not that that actually means they are good at their job or care). But if such a test existed, they presumably would have passed it. They also have an ISO 27001 certificate (they try to claim a bunch of AWSs certs by proxy on their security page, which is ironic as they say AWS stores most o…

> But if such a test existed, they presumably would have passed it

Sure, and now they could have their credentials revoked, potential be legally liable, and never find work in this field again which would prevent them from cocking up another company this way

Re: Tell HN: Fiverr left customer files public and searchable

#98
post #67

There are health stuff too... and they are not even paying attention to this matter https://fiverr-res.cloudinary.com/image/upload/f_pdf,q_auto/...

Someone got an antivaxx certificate from Fiverr, not sure if that counts as delicate health information

Re: Tell HN: Fiverr left customer files public and searchable

#99

Earlier quoted context omitted.

I have uploaded the email here: https://gist.github.com/aidanbh/3da7cecb3e2496e5c5110b88f21b... (technically, I guess that doesn't prove anything other than it is in my Sent folder? it has a message ID but I guess only the purelymail admin could confirm that) In any event, this should never have required an outside reminder. The indexing issue may be something non obvious. But the core decision not to use signed/expi…

I wouldn't be surprised if their email blocks all unusual TLDs like your .dev.

Sounds like a really bad strategy for a security email address...

Re: Tell HN: Fiverr left customer files public and searchable

#100

Software development jobs are too accessible. Jobs with access to/control over millions of people's data should require some kind of genuine software engineering certification, and there should be business-cratering fines for something as egregious as completely ignoring security reports. It is ridiculous how we've completely normalised leaks like this on a weekly or almost-daily basis.

> should require some kind of genuine software engineering certification Wouldn't change a thing, other than add another hassle you have to pay for to do your job. This is the result of carelessness, not someone who didn't know that private data should be private because they weren't certified.

>Wouldn't change a thing..

That's exactly what certification or licensure does; it imposes financial, civil, and criminal penalties for malpractice.

The liability of incurring penalties quickly outweigh the benefit of arbitraging costs with an unqualified practitioner.

Post reply on HN