Live data from Hacker News

Tell HN: Fiverr left customer files public and searchable

news.ycombinator.com

161–170 of 252 posts

Re: Tell HN: Fiverr left customer files public and searchable

#161

Earlier quoted context omitted.

It kind of is, though. Google doesn't randomly try to visit every URL on the internet. It follows links. Therefore, for these files to be indexed by Google, they need to be linked to from somewhere.

> Therefore, for these files to be indexed by Google, they need to be linked to from somewhere. So? That’s indeed how Google works. Google does not work how OP describes it. I’ve investigated similar incidents in the past on other platforms, it was always user error causing links to be public.

The only thing that's user error here is the developers of Fiverr exposing files without proper session authentication.

Re: Tell HN: Fiverr left customer files public and searchable

#162

Earlier quoted context omitted.

> Therefore, for these files to be indexed by Google, they need to be linked to from somewhere. So? That’s indeed how Google works. Google does not work how OP describes it. I’ve investigated similar incidents in the past on other platforms, it was always user error causing links to be public.

The only thing that's user error here is the developers of Fiverr exposing files without proper session authentication.

That’s very often a deliberate design decision.

It’s bizarre UX if you link a file to someone and the link doesn’t work.

Re: Tell HN: Fiverr left customer files public and searchable

#163

I don't get why disclosing is considered acceptable, it seems like racketeering to me, "pay up or else I'll make this hypothetical issue an actual issue for you" When I reported an issue and gotten no response, I sat on it for 6 years, reported it again and they took the whole site down without reaching out to me, never quite got it, but if people are doing this, it makes sense not to acknowledge any report and just…

Huh? I didn't ask for any money here or in the original email. (not that I couldn't use some, as I only have $1000 and four heavy suitcases right now, but anyway...)

I did include "bug bounty" in the email subject since they claimed to have a private program. Other than that, no mention of any kind of compensation. It probably doesn't even have any kind of resume value since it's not an actual code flaw/CVE, just an "unlocked door."

Re: Tell HN: Fiverr left customer files public and searchable

#164
I was scammed on Fiverr myself, so I may be biased, but this feels consistent with the platform incentives I saw firsthand. The dispute process did not seem designed to deal well with coordinated abuse, and weak controls around sensitive files would point to the same broader issue: user safety and data handling do not appear to be high priorities.

Re: Tell HN: Fiverr left customer files public and searchable

#167
post #118

Earlier quoted context omitted.

It's so much worse in the industry, the truth is that many people literally have no idea how to secure things, what to secure, why to secure it - they pay no attention and are plainly ignorant of the state of the world and oftentimes just stupid. I worked at a company where a customer called confused because when they googled our company as they did every day to login to their portal they found that drivers licenses…

> they were just the cheapest labor the company could find who could do the thing. Thats the problem right there. The company doesn't care . No amount of personal certifications is going to fix that. It MUST be on the companies. They should be fined out of existence for such breaches and they would quickly change tune.

> They should be fined out of existence for such breaches and they would quickly change tune.

Looks like this is a great opportunity for an object lesson. Let’s see how it goes…

As far as certification stuff…

Civil engineering has had licensing forever. That’s because Bad Things Happen, when they make mistakes.

I do think that it would be a good idea to score/certify critical infrastructure stuff. That might involve certification of the people that make it, but it should certainly involve penalties for the people responsible. That might include the authors, but it should probably also include the folks that decide to use the bad code.

I know that ISO 9000 is an attempt to address this kind of thing. In my opinion, it’s kind of a mess. I’ve worked in ISO 9000 shops, and it’s not much fun. The thing you learn, pretty quickly, is how to end-run the process, as it’s so heavy, that it basically stops all forward progress. It doesn’t have to, but often does.

Mistakes get made. If you design carefully, these mistakes won’t cause real damage.

I just figured out that an app I wrote, that’s been out for two years, has an embarrassing bug (mea culpa). I’ll get it fixed today.

Because I’m pretty careful, it doesn’t affect stuff like user privacy. It just introduces performance overhead, in one operation, so the fix will mean that the app will suddenly speed up.

I’m not sure that certification would have solved it. My security mindset is why user privacy wasn’t affected, and that comes from experience.

> Good judgment comes from experience. Experience comes from bad judgement.

Re: Tell HN: Fiverr left customer files public and searchable

#169
post #46

Wow, the other comments weren't exaggerating. This is really bad. If my tax returns or other data were part of this, I might consider legal action. I wonder if somewhere like Wired/Ars Technica/404media might pick this up?

I saw that this was also reported on r/Fiverr[0]. It looks like an almost verbatim copy of this. I don’t see much discussion (so far).

[0] https://www.reddit.com/r/Fiverr/comments/1slzoey/other_atten...

Re: Tell HN: Fiverr left customer files public and searchable

#170

Earlier quoted context omitted.

I have uploaded the email here: https://gist.github.com/aidanbh/3da7cecb3e2496e5c5110b88f21b... (technically, I guess that doesn't prove anything other than it is in my Sent folder? it has a message ID but I guess only the purelymail admin could confirm that) In any event, this should never have required an outside reminder. The indexing issue may be something non obvious. But the core decision not to use signed/expi…

I've contacted fiverr before about obvious fraud being conducted through their platform, and they just sent me in endless loops of "open a ticket". "No, e-mail us about it." "No, e-mail us at our security contact about it." Crickets, and then a response saying to please open a ticket. Basically, they aren't set up for anyone to actually contact them and expect a resolution.

oh I got that too, Sent an email, "Open a ticket" . Then I see in the support page that the email opened a ticket and it was marked as solved.

For sure their internal metrics are all green and solved tickets are on the rise.

Post reply on HN