Live data from Hacker News

Tell HN: Fiverr left customer files public and searchable

news.ycombinator.com

181–190 of 252 posts

Re: Tell HN: Fiverr left customer files public and searchable

#181
post #118

Earlier quoted context omitted.

> they were just the cheapest labor the company could find who could do the thing. Thats the problem right there. The company doesn't care . No amount of personal certifications is going to fix that. It MUST be on the companies. They should be fined out of existence for such breaches and they would quickly change tune.

> They should be fined out of existence for such breaches and they would quickly change tune. Looks like this is a great opportunity for an object lesson. Let’s see how it goes… As far as certification stuff… Civil engineering has had licensing forever. That’s because Bad Things Happen, when they make mistakes. I do think that it would be a good idea to score/certify critical infrastructure stuff. That might involve…

Also if you are personally liable of gross negligence, you will:

1. Get paid more (as less fake "engineers" are available for the responsibility).

2. Push back harder (or at least document in detail) on malpractice during development. Manager did not listen to your warnings? Document it and when shit hits the fan, the manager gets the stick instead of you.

Hitting companies with monetary fines does not work. Hitting the employees with jail time will make sure they don't sign on dangerous or known problematic systems.

Manager not listening? Remind them they will face a trial if the issue does surface.

Re: Tell HN: Fiverr left customer files public and searchable

#182

Earlier quoted context omitted.

>Wouldn't change a thing.. That's exactly what certification or licensure does; it imposes financial, civil, and criminal penalties for malpractice. The liability of incurring penalties quickly outweigh the benefit of arbitraging costs with an unqualified practitioner.

I think just putting it on the companies is enough. If the fines are serious and can put your company out of business, and are enforced, then the companies themselves will probably work out processes for not doing stupid stuff. Whether that be creating some sort of certifications that would be prized by the companies, knowing to hire a specialized team for a security review, or anything else. If everyone knows that m…

> I think just putting it on the companies is enough. If the fines are serious and can put your company out of business

They don't care. It's either never enough to make them care, or the company can just bankrupt and you go do something else.

If you or your manager has the threat of jail in the back of their mind, it's no longer just someone else's money being lost, it's personal.

> If everyone knows that messing up security gets you in real trouble and the company loses real money

There's already huge fines on paper for this, but never ever are the fines enough. It's always factored in the "cost of doing business". Also it's still someone else's money, why would an engineer care?

Please show me a GDPR fine that hit hard enough to scare companies into not fucking up? Evidently here it was not enough for Fiverr.

Edit: Just to provide an example, Takata airbags have been recalled massively (if you don't know why, look it up) but the company is now bankrupted and who is footing the bill? Their customers.

You cannot impose a fine on them, as it's bankrupt (now, but it was always the plan). They deliberately sold dangerous airbags and now what can you do so it doesn't happen again? Fine them some more? or maybe throw a few execs in jail because they knew of the problem and continued as usual.

Re: Tell HN: Fiverr left customer files public and searchable

#184
post #70

Extremely bad stuff here. Can't believe it's been 7 hours now and you can still pull up people's complete prepared tax returns right from a Google search. This should be a business-ending breach of trust and good practices, but I worry there's probably a lack of regulatory might or will to make anything happen.

Technically, 40 days and 7 hours!

Re: Tell HN: Fiverr left customer files public and searchable

#186
post #111

Earlier quoted context omitted.

I wouldn’t be surprised if someone wrote a script to pull all the sensitive PII and it’s already on the dark net hacking forums for identity thieves. Freeze your credit at all bureaus if you ever used this site.

> Freeze your credit at all bureaus if you ever used this site. People should always have their credit frozen no matter what. It's free and only takes a few minutes to unfreeze when you need to apply for credit Yes it's a little bit inconvenient but so is suddenly having a car, insurance, and several iPhones in your name when somebody steals your identity...

My Experian score once took a substantial hit, dropping from ~800 to ~700 or something like that. Didn’t change elsewhere. I applied for the report and realized a quite significant debt appeared on my report, and it wasn’t even in my name! It was under someone else’s name that bore zero similarity to mine, or anyone in my family. Reported to Experian and it got fixed after a week or two. Zero explanation for how it happened. These credit reporting agencies are a joke.

Re: Tell HN: Fiverr left customer files public and searchable

#187

Files are now returning 404s as of right now, 0900 UTC 4/15. Would be interesting if someone with an account can check if they are visible to intended users or not, and if so, if their mitigation is robust (signed URLs?).

I have an account and I can confirm that the URL's of shared files are still publicly accessible. Google is giving 404's indeed.

Interesting. Did the URL scheme change with any expiry or signature params (like S3s X-Amz-Expires)?

Re: Tell HN: Fiverr left customer files public and searchable

#188
post #92

Earlier quoted context omitted.

Leaving a paper trail of you having accessed unauthorized private info is a bad idea, some crazy lawyer could decide to include you in a suit. Just not worth the hassle. Email a tip line about the general situation.

How is it unauthorised if it's freely available via a search without having to bypass any login? It'd be like putting up an advert and then trying to sue anyone who sees it.

Some crazy lawyer included my parents in a traffic death suit’s defendants while they were victims who had their car badly damaged when the reckless driver rammed into two cars (including my parents’) and two pedestrians. The question isn’t whether you’re at fault, it’s whether you want to risk getting a court summons.

Re: Tell HN: Fiverr left customer files public and searchable

#189

Earlier quoted context omitted.

The only thing that's user error here is the developers of Fiverr exposing files without proper session authentication.

That’s very often a deliberate design decision. It’s bizarre UX if you link a file to someone and the link doesn’t work.

It's actually very common to link a file hosted in the cloud to a coworker or partner and it requires login.

Re: Tell HN: Fiverr left customer files public and searchable

#190
post #113
post #76

@dang example query feels incredibly doxxy, and feels bad form to link directly to full copies of people's [stuff] and [personal info] as seen on this page :/ I know this is all Fiverr's fault for allegedly missing the responsible disclosure but now is this the ideal way for us to discuss, with these particular examples? I ask not to spare Fiverr, but I would be so mad if I were first for the result in OP or my perso…

@dang I agree that some/many of these links should not be posted here.

If this gets swept under the rug, it doesn't seem like they are going to do anything about it, and it will mean that only the bad people are going to be able to find this stuff.. who knows for how long.
Post reply on HN