Live data from Hacker News

Tell HN: Fiverr left customer files public and searchable

news.ycombinator.com

121–130 of 252 posts

Re: Tell HN: Fiverr left customer files public and searchable

#121
post #92
post #81

Earlier quoted context omitted.

Do I have to start emailing the people in the leaked documents with screenshots?

Leaving a paper trail of you having accessed unauthorized private info is a bad idea, some crazy lawyer could decide to include you in a suit. Just not worth the hassle. Email a tip line about the general situation.

Not to forget some eager prosecutors. They can still try to prosecute for accessing material even if they end up losing. Lot of hassle there.

Re: Tell HN: Fiverr left customer files public and searchable

#122

Software development jobs are too accessible. Jobs with access to/control over millions of people's data should require some kind of genuine software engineering certification, and there should be business-cratering fines for something as egregious as completely ignoring security reports. It is ridiculous how we've completely normalised leaks like this on a weekly or almost-daily basis.

I once worked in a company and noticed that customer financial statements were publicly accessible. Ran into the software team. And got the reply that no one told them that it should be behind authentication. Some people really don't use their own brains.

Re: Tell HN: Fiverr left customer files public and searchable

#123
post #60

Earlier quoted context omitted.

Normalize "vibe-plumbing"

Both plumbing and wiring are “easier” in a way than programming-as they’ll violently and potentially explosively let you know if you messed up; whereas programming lets you be blissfully unaware until you see your data plastered across the nightly news.

Wiring mistakes can kill or burn down a house months or years after they have been done. You will not notice unconnected protective earth or badly dimensioned circuit breakers until something else breaks and the protective element is not there.

Re: Tell HN: Fiverr left customer files public and searchable

#124
post #111
post #95

Earlier quoted context omitted.

I want to believe that it's people keeping mum until it's fixed so that the leaked PII isn't spread more widely, minimize the risk of bad actors scraping it all. Once the leak is plugged, I would hope that Fiverr gets absolutely raked over the coals, this is egregious.

I wouldn’t be surprised if someone wrote a script to pull all the sensitive PII and it’s already on the dark net hacking forums for identity thieves. Freeze your credit at all bureaus if you ever used this site.

> Freeze your credit at all bureaus if you ever used this site.

People should always have their credit frozen no matter what. It's free and only takes a few minutes to unfreeze when you need to apply for credit

Yes it's a little bit inconvenient but so is suddenly having a car, insurance, and several iPhones in your name when somebody steals your identity...

Re: Tell HN: Fiverr left customer files public and searchable

#125
post #54

it's been 5 hours. even manual action to take down the most sensitive files should have completed about 3 hours ago at most. what is happening.

I've never been in the position that I've had to deal with this. Is the best you can do in this situation to pull the files and optionally republish them to a robots.txt'd path (with authn/z, too)? I can't imagine you can get it pulled from search engines very quickly...

There's a way to submit a request with Google ticket content taken down and then the easiest way would be probably to do a no index in the header response for future content

Re: Tell HN: Fiverr left customer files public and searchable

#126
post #89

Earlier quoted context omitted.

https://fiverr-res.cloudinary.com/image/upload/f_pdf,q_auto/... This is too funny

Personally, this is the funniest one to me. It turns out Fiverr uses cloudinary for their internal documents as well. (Note: this one is not confidential and is public information) https://fiverr-res.cloudinary.com/image/upload/f_pdf,q_auto/...

Clearly the real issue is their 27001 expired on 15/12/2025

Re: Tell HN: Fiverr left customer files public and searchable

#127

Earlier quoted context omitted.

> should require some kind of genuine software engineering certification Wouldn't change a thing, other than add another hassle you have to pay for to do your job. This is the result of carelessness, not someone who didn't know that private data should be private because they weren't certified.

>Wouldn't change a thing.. That's exactly what certification or licensure does; it imposes financial, civil, and criminal penalties for malpractice. The liability of incurring penalties quickly outweigh the benefit of arbitraging costs with an unqualified practitioner.

I think just putting it on the companies is enough. If the fines are serious and can put your company out of business, and are enforced, then the companies themselves will probably work out processes for not doing stupid stuff. Whether that be creating some sort of certifications that would be prized by the companies, knowing to hire a specialized team for a security review, or anything else.

If everyone knows that messing up security gets you in real trouble and the company loses real money, and it happens all the time, and it's not just "Facebook fined $x million for doing shady stuff", then I think the industry will adapt.

Like when GDPR got released and no matter if I thought we are or are not handling PII, I had to read up and double-check my assumptions just because it was being talked about all over the place and it would be embarrassing to be caught with your pants down when you didn't actually intend to do a shady thing.

Re: Tell HN: Fiverr left customer files public and searchable

#128
post #76

@dang example query feels incredibly doxxy, and feels bad form to link directly to full copies of people's [stuff] and [personal info] as seen on this page :/ I know this is all Fiverr's fault for allegedly missing the responsible disclosure but now is this the ideal way for us to discuss, with these particular examples? I ask not to spare Fiverr, but I would be so mad if I were first for the result in OP or my perso…

@dang doesn't work write an email if you mean your comment in a non performative way.

Re: Tell HN: Fiverr left customer files public and searchable

#129
I tried posting a warning to /r/fiverr but the admins removed the post. And the files are STILL public...how in the world is "sitting it out" their course of action?

Edit: I'm beginning to wonder if they might be locked out of their own site at this point. How hard could it be to just shut down the asset server until they get it sorted?

Re: Tell HN: Fiverr left customer files public and searchable

#130
post #76

@dang example query feels incredibly doxxy, and feels bad form to link directly to full copies of people's [stuff] and [personal info] as seen on this page :/ I know this is all Fiverr's fault for allegedly missing the responsible disclosure but now is this the ideal way for us to discuss, with these particular examples? I ask not to spare Fiverr, but I would be so mad if I were first for the result in OP or my perso…

@dang doesn't work write an email if you mean your comment in a non performative way.

Oh? I've seen him respond to that many times in the past...assumed he had some hook for those.
Post reply on HN