Wow, surprised this isn't blowing up more. Leaking form 1040s is egregious, let alone getting them indexed by Google...
I want to believe that it's people keeping mum until it's fixed so that the leaked PII isn't spread more widely, minimize the risk of bad actors scraping it all. Once the leak is plugged, I would hope that Fiverr gets absolutely raked over the coals, this is egregious.
Tell HN: Fiverr left customer files public and searchable
111–120 of 252 posts
Re: Tell HN: Fiverr left customer files public and searchable
#112It's been 10 hours and all the links in this comment section still work...
Re: Tell HN: Fiverr left customer files public and searchable
#113@dang example query feels incredibly doxxy, and feels bad form to link directly to full copies of people's [stuff] and [personal info] as seen on this page :/ I know this is all Fiverr's fault for allegedly missing the responsible disclosure but now is this the ideal way for us to discuss, with these particular examples? I ask not to spare Fiverr, but I would be so mad if I were first for the result in OP or my perso…
Re: Tell HN: Fiverr left customer files public and searchable
#114Re: Tell HN: Fiverr left customer files public and searchable
#115Earlier quoted context omitted.
it's worse than you think – it's an admin password to the ~whole site~
Oh my. I feel for the tech team at fiverr. I'm sure it's nasty in there. Sending virtual hugs.
Re: Tell HN: Fiverr left customer files public and searchable
#116Given the existing DMCA requests and the fact that Google has become way less aggressive about indexing this stuff, it's clear this has been going on for a while. My guess is they've gutted enough of their internal processes that they literally can't restrict access to these files without breaking their own platform. You really can't make this shit up: https://www.linkedin.com/feed/update/urn:li:activity:7445526... T…
No. Nobody will care.
Re: Tell HN: Fiverr left customer files public and searchable
#117Software development jobs are too accessible. Jobs with access to/control over millions of people's data should require some kind of genuine software engineering certification, and there should be business-cratering fines for something as egregious as completely ignoring security reports. It is ridiculous how we've completely normalised leaks like this on a weekly or almost-daily basis.
That only gives those in power another way to push people into toeing the line. There's enough corporate authoritarianism these days as it is already. Give Stallman's "Right to Read" a read. His dystopia is exactly where we're going to be headed quickly if we keep demanding someone to "do something".
"The optimal amount of fraud is nonzero."
"Those who give up freedom for security deserve neither."
Re: Tell HN: Fiverr left customer files public and searchable
#118Earlier quoted context omitted.
> should require some kind of genuine software engineering certification Wouldn't change a thing, other than add another hassle you have to pay for to do your job. This is the result of carelessness, not someone who didn't know that private data should be private because they weren't certified.
It's so much worse in the industry, the truth is that many people literally have no idea how to secure things, what to secure, why to secure it - they pay no attention and are plainly ignorant of the state of the world and oftentimes just stupid. I worked at a company where a customer called confused because when they googled our company as they did every day to login to their portal they found that drivers licenses…
Thats the problem right there. The company doesn't care. No amount of personal certifications is going to fix that.
It MUST be on the companies. They should be fined out of existence for such breaches and they would quickly change tune.
Re: Tell HN: Fiverr left customer files public and searchable
#119When I reported an issue and gotten no response, I sat on it for 6 years, reported it again and they took the whole site down without reaching out to me, never quite got it, but if people are doing this, it makes sense not to acknowledge any report and just play deaf.
Re: Tell HN: Fiverr left customer files public and searchable
#120Earlier quoted context omitted.
People at my company don't even lock their computer when they walk away from their desk. Which yeah it's in a controlled environment but still.
My work has a “donuts” slack channel for this. You find an unlocked computer you post “donuts on me!” Social pressure says they buy the office donuts. Still get a few a week, but at least it’s public and amusing.