Live data from Hacker News

Clickbank order details in plain view

google.com

71–80 of 81 posts

Re: Clickbank order details in plain view

#71
post #51

Earlier quoted context omitted.

Did you get the job?

No. It was a week long, paid interview. After a couple of days I decided not to come back. Mainly because the main project seemed illegal (which I'll admit held some criminal mastermind allure) and I had another job lined up in Japan. In retrospect, I wish I would have done it as the job in Japan was terrible and I've not come across a similar opportunity since.

The NSA has a contractor position open in Honolulu.

Re: Clickbank order details in plain view

#72
post #71
post #51

Earlier quoted context omitted.

No. It was a week long, paid interview. After a couple of days I decided not to come back. Mainly because the main project seemed illegal (which I'll admit held some criminal mastermind allure) and I had another job lined up in Japan. In retrospect, I wish I would have done it as the job in Japan was terrible and I've not come across a similar opportunity since.

The NSA has a contractor position open in Honolulu.

I graduated from high school and am pretty good at powerpoint, so I am assuming I am overqualified.

Re: Clickbank order details in plain view

#75
post #35

Clickbank is a joke! I remember year ago you could put in Google product name and "thank you" and you would find thank you page with direct download link. EDIT: Someone even made CB product to protect thank you page: Fix My Thank You Page http://fixmythankyoupage.com/ only $97 LOL!

I guess Google really started taking advantage of "today's digital internet" > Adding "no follow" tags to your Robots.txt file is a smart step but it's simply not enough on today's digital internet.

On the old analog internet it worked great.

Re: Clickbank order details in plain view

#76
post #52

Earlier quoted context omitted.

Why is this racist juvenility the top rated comment in this thread?

I don't think it's funny because it's racist, I think it's funny because it reveals what kind of embarrassing data a security hole like this brings out.

Except anyone can edit the emails, even now.

Re: Clickbank order details in plain view

#77

The problem was that some average developer was lazy and do whatever that worked, with no concern about potential security implications.

No, not lazy. Being lazy would have been doing a simple session check and then redirecting to a login page if the session user id did not match the user id in the order. The developer had no idea what he/she was doing. Brutal.

You have me listening. What would be the correct course of action while not lazy and knowing what you're doing? I know that "knowing what you're doing" and this question doesn't go together, but still anything better than a check/redirect?

Re: Clickbank order details in plain view

#79

Hi, this is Matt Hulett the CEO of ClickBank. ClickBank was recently made aware of a situation in which customers were posting their information using social bookmarking sites, which are indexed by Google. As a result, ClickBank is taking steps to limit the information that a consumer can inadvertently share through such services. We take customer privacy very seriously and believe that all individuals share responsi…

How was customer payment information NOT disclosed?! It is on Google!! The URLs should be protected by authentication! It should be impossible for Google or anyone else to access it without a login. It does not matter that some customers shared it on social sites. Saying there is no problem if the social sharing doesn't occur is security through obscurity.

I've been through this before. Online receipts identified with long, random URLs. Users posting them online with no regard for security. Requiring a login for purchase was deemed infeasible since it adds friction to the checkout process. The only thing keeping the online receipt from google was robots.txt.

Re: Clickbank order details in plain view

#80

Earlier quoted context omitted.

How was customer payment information NOT disclosed?! It is on Google!! The URLs should be protected by authentication! It should be impossible for Google or anyone else to access it without a login. It does not matter that some customers shared it on social sites. Saying there is no problem if the social sharing doesn't occur is security through obscurity.

I've been through this before. Online receipts identified with long, random URLs. Users posting them online with no regard for security. Requiring a login for purchase was deemed infeasible since it adds friction to the checkout process. The only thing keeping the online receipt from google was robots.txt.

Except there are neither long URLs nor unindexed (no meta tags, no nothing!)
Post reply on HN