Live data from Hacker News

Thoughts on the Posterous hack

blog.dustincurtis.com

11–20 of 62 posts

Re: Thoughts on the Posterous hack

#11
post #9

He says there is no interest to post to his moms posterous, but is that really true? I can imagine quite a lot of spammers who would love to have a blog-post on an otherwise reputable blog. If spammers manage to abuse this system they could get their blogposts, filled with links and instructions to buy medication, all over all posterous blogs.

Ah yes, the sole exception to this security sacrifice is spammers. You have to keep them out, no matter the cost.

Posterous does a good job of keeping them out, I think, because I've never seen a spam post.

Re: Thoughts on the Posterous hack

#12
Uhm you don't have to have an epic GUID e-mail address. Just pair it with your e-mail. So let the user set it to whatever they can remember (their name backwards and ROT13'd, whatever, so long as it's unique) and only accept posts to that address from their verified e-mail. That would at least curb some of the danger of this setup.

Re: Thoughts on the Posterous hack

#13
post #5

couldn't they do something like the email address is yourusernameatyourdomain.comandanextrabityoutset@posterous.com which would be an id you could remember?

or just a random noun@posterous.com? Or make it user-configurable?

or both... assign a random GUID, and then allow the user to set it something they want if they choose. That's probably the simplest way, and of course the simpler the better for both development and security.

Re: Thoughts on the Posterous hack

#14
"As a user, I fully accept it. http://blog.dustincurtis.com has received almost a million pageviews in the past year, and this is the first time this has ever happened. And It happened because I provoked it in an extremely popular article was posted to a community of hackers. To be honest, I expected someone to try this."

as an EDUCATED user YOU accept it, i'm not sure most of the posterous users understand and would make the same decision to user posterous if they did.

this is like saying car companies could sell shitty locks on their cars because they mostly wont be tested anyway, and the driver will have an easier time getting into the car. it's VERY unlikely my mothers car will be broken into just statistically speaking, but hey even if it happens its just one person. not a big deal.

im pretty sure if posterous made it clear how easy this is many users would stay away, just like many people would not buy toyotas if they came with shitty locks, no matter how little they expected to be broken into.

Re: Thoughts on the Posterous hack

#15
Simple. Create an email alias (spacemuffinftw) just for Posterous and post with that, making it your password in a way.

Edit: Seen in other comments -- cool thing would be for Posterous to support SPF. Definitely techie oriented and not for general folks, but in a system like Posterous, it should be baked in from day one. It would protect quite a bit of folks while majority of them not even realizing or even knowing what SPF is.

Re: Thoughts on the Posterous hack

#16
post #14

"As a user, I fully accept it. http://blog.dustincurtis.com has received almost a million pageviews in the past year, and this is the first time this has ever happened. And It happened because I provoked it in an extremely popular article was posted to a community of hackers. To be honest, I expected someone to try this." as an EDUCATED user YOU accept it, i'm not sure most of the posterous users understand and would…

If someone steals your car, you're out many thousands of dollars and extremely inconvenienced.

If some random idiot posts a link to a Nigerian scam on your blog, you just delete it and get on with your life.

Re: Thoughts on the Posterous hack

#17
post #16
post #14

"As a user, I fully accept it. http://blog.dustincurtis.com has received almost a million pageviews in the past year, and this is the first time this has ever happened. And It happened because I provoked it in an extremely popular article was posted to a community of hackers. To be honest, I expected someone to try this." as an EDUCATED user YOU accept it, i'm not sure most of the posterous users understand and would…

If someone steals your car, you're out many thousands of dollars and extremely inconvenienced. If some random idiot posts a link to a Nigerian scam on your blog, you just delete it and get on with your life.

I wonder if your users feel the same way.

Re: Thoughts on the Posterous hack

#18
I think his argument comes off as too utopian for me to accept. Like everyone else has said, of course people will want to exploit an easy loophole on someone who has a bit of exposure.

I think Posterous hasn't grown to a point where they have to worry about it yet, but look at the exploits on Wordpress. They're much more advanced and hackers continually attempt to break in for fun or for abusive reasons. It's naive to assume that you can simply keep this convenience as a security trade off as the product gains the attention of the world.

Re: Thoughts on the Posterous hack

#19
Posterous actually has a nasty security hole which allows you to get the email address for any posterous which the user has not claimed.

Here's a posterous I just created: http://john-tfk88.posterous.com/ that I have not claimed.

The 'Claim this site' link goes to http://posterous.com/main/register?hash=Bu5fX3lRT2rYPURl7axZ...

If you view source that you'll find that my email address is 'hidden' in the page:

   
So, for any unclaimed posterous you can programmatically go to the owner's email address. A nice hack would be to grab the email address of newly created posterous accounts, wait for them to be claimed (or not) and then started spamming them. Yay!

Oh look: http://www.google.co.uk/search?hl=en&q=%22claim+this+sit...

Re: Thoughts on the Posterous hack

#20
post #11
post #9

He says there is no interest to post to his moms posterous, but is that really true? I can imagine quite a lot of spammers who would love to have a blog-post on an otherwise reputable blog. If spammers manage to abuse this system they could get their blogposts, filled with links and instructions to buy medication, all over all posterous blogs.

Ah yes, the sole exception to this security sacrifice is spammers. You have to keep them out, no matter the cost. Posterous does a good job of keeping them out, I think, because I've never seen a spam post.

This seems mostly security by obscurity.

If spammers already have a list of "valid" email addresses, how long before they start randomly hitting post@postereous.com with spoofed headers on a regular basis?

Post reply on HN