Earlier quoted context omitted.
Do I have to start emailing the people in the leaked documents with screenshots?
Leaving a paper trail of you having accessed unauthorized private info is a bad idea, some crazy lawyer could decide to include you in a suit. Just not worth the hassle. Email a tip line about the general situation.
Tell HN: Fiverr left customer files public and searchable
121–130 of 252 posts
Re: Tell HN: Fiverr left customer files public and searchable
#122Software development jobs are too accessible. Jobs with access to/control over millions of people's data should require some kind of genuine software engineering certification, and there should be business-cratering fines for something as egregious as completely ignoring security reports. It is ridiculous how we've completely normalised leaks like this on a weekly or almost-daily basis.
Re: Tell HN: Fiverr left customer files public and searchable
#123Earlier quoted context omitted.
Normalize "vibe-plumbing"
Both plumbing and wiring are “easier” in a way than programming-as they’ll violently and potentially explosively let you know if you messed up; whereas programming lets you be blissfully unaware until you see your data plastered across the nightly news.
Re: Tell HN: Fiverr left customer files public and searchable
#124Earlier quoted context omitted.
I want to believe that it's people keeping mum until it's fixed so that the leaked PII isn't spread more widely, minimize the risk of bad actors scraping it all. Once the leak is plugged, I would hope that Fiverr gets absolutely raked over the coals, this is egregious.
I wouldn’t be surprised if someone wrote a script to pull all the sensitive PII and it’s already on the dark net hacking forums for identity thieves. Freeze your credit at all bureaus if you ever used this site.
People should always have their credit frozen no matter what. It's free and only takes a few minutes to unfreeze when you need to apply for credit
Yes it's a little bit inconvenient but so is suddenly having a car, insurance, and several iPhones in your name when somebody steals your identity...
Re: Tell HN: Fiverr left customer files public and searchable
#125it's been 5 hours. even manual action to take down the most sensitive files should have completed about 3 hours ago at most. what is happening.
I've never been in the position that I've had to deal with this. Is the best you can do in this situation to pull the files and optionally republish them to a robots.txt'd path (with authn/z, too)? I can't imagine you can get it pulled from search engines very quickly...
Re: Tell HN: Fiverr left customer files public and searchable
#126Earlier quoted context omitted.
https://fiverr-res.cloudinary.com/image/upload/f_pdf,q_auto/... This is too funny
Personally, this is the funniest one to me. It turns out Fiverr uses cloudinary for their internal documents as well. (Note: this one is not confidential and is public information) https://fiverr-res.cloudinary.com/image/upload/f_pdf,q_auto/...
Re: Tell HN: Fiverr left customer files public and searchable
#127Earlier quoted context omitted.
> should require some kind of genuine software engineering certification Wouldn't change a thing, other than add another hassle you have to pay for to do your job. This is the result of carelessness, not someone who didn't know that private data should be private because they weren't certified.
>Wouldn't change a thing.. That's exactly what certification or licensure does; it imposes financial, civil, and criminal penalties for malpractice. The liability of incurring penalties quickly outweigh the benefit of arbitraging costs with an unqualified practitioner.
If everyone knows that messing up security gets you in real trouble and the company loses real money, and it happens all the time, and it's not just "Facebook fined $x million for doing shady stuff", then I think the industry will adapt.
Like when GDPR got released and no matter if I thought we are or are not handling PII, I had to read up and double-check my assumptions just because it was being talked about all over the place and it would be embarrassing to be caught with your pants down when you didn't actually intend to do a shady thing.
Re: Tell HN: Fiverr left customer files public and searchable
#128@dang example query feels incredibly doxxy, and feels bad form to link directly to full copies of people's [stuff] and [personal info] as seen on this page :/ I know this is all Fiverr's fault for allegedly missing the responsible disclosure but now is this the ideal way for us to discuss, with these particular examples? I ask not to spare Fiverr, but I would be so mad if I were first for the result in OP or my perso…
Re: Tell HN: Fiverr left customer files public and searchable
#129Edit: I'm beginning to wonder if they might be locked out of their own site at this point. How hard could it be to just shut down the asset server until they get it sorted?
Re: Tell HN: Fiverr left customer files public and searchable
#130@dang example query feels incredibly doxxy, and feels bad form to link directly to full copies of people's [stuff] and [personal info] as seen on this page :/ I know this is all Fiverr's fault for allegedly missing the responsible disclosure but now is this the ideal way for us to discuss, with these particular examples? I ask not to spare Fiverr, but I would be so mad if I were first for the result in OP or my perso…
@dang doesn't work write an email if you mean your comment in a non performative way.