Live data from Hacker News

Tell HN: Fiverr left customer files public and searchable

news.ycombinator.com

101–110 of 252 posts

Re: Tell HN: Fiverr left customer files public and searchable

#101
post #92
post #81

Earlier quoted context omitted.

Do I have to start emailing the people in the leaked documents with screenshots?

Leaving a paper trail of you having accessed unauthorized private info is a bad idea, some crazy lawyer could decide to include you in a suit. Just not worth the hassle. Email a tip line about the general situation.

Good call!

Re: Tell HN: Fiverr left customer files public and searchable

#102

Earlier quoted context omitted.

Any time someone tries to suggest certification as a solution I ask the same question: How would it have solved this problem? Would the certification require someone to take an official certification test for the framework used? And therefore we’re only allowed to use frameworks which have certification tests available? If you want to write some new software, do you have to generate a certification for it and get tha…

The fact that you're thinking purely in frameworks is the exact problem that plagues the software industry. Framework-focused development is why we're in this mess; frameworks make it easy for people who don't understand how to program to publish shitty software by copying-and-pasting code and fudging around a few strings or variables to match their use case. That kind of accessibility is great for low-stakes softwar…

I follow your logic here, and it's certainly a coherent argument.

That said, there are perhaps some factors you are overlooking which matter.

The first is that no amount of certification solves the actual problem (which is that security mistakes are made, often in new and novel ways.)

Secondly the amount of software being needed (and produced) is immense. Bridges require engineers, but the demand for new bridges is tiny. The demand for new software is enormous, and the current rate of production requires many more people that could ever be certified.

In other words, say you only allowed comp-sci graduates with a proper 4 year degree, covering assembly upwards etc. The supply of programmers would drop to what colleges could produce. Which is not nearly enough.

The analogy also falls down a bit on penalty-for-failure, a collapsed bridge kills people, bugs in my notepad app might lead to information leaks? Thats not the same thing.

In truth, at least for the last 35 years, the number of unqualified developers exceed qualified ones by orders of magnitude. And there still seems to be no limit to software demand.

Finally there have been no studies I am aware if that suggest that security flaws are added more frequently by non comp-sci grads compared to comp-sci grads. Anecdotally I don't see that distinction myself. (From my observation security outcomes correlate to the degree to which the individual considers security to be important.)

And, of course, security issues are not limited to programmers- management has a role to play as well. Should they be certified too?

So, I'm not convinced that your suggestion, however desirable, would solve the problem. And since it's clearly unimplementable in the real world it's a moot argument anyway.

Re: Tell HN: Fiverr left customer files public and searchable

#103
post #89

Earlier quoted context omitted.

https://fiverr-res.cloudinary.com/image/upload/f_pdf,q_auto/... This is too funny

Personally, this is the funniest one to me. It turns out Fiverr uses cloudinary for their internal documents as well. (Note: this one is not confidential and is public information) https://fiverr-res.cloudinary.com/image/upload/f_pdf,q_auto/...

I saw that too. Ddg didn't give me a lot of results. Beyond a few dozen

Re: Tell HN: Fiverr left customer files public and searchable

#104

Earlier quoted context omitted.

This is the result of somebody who has no idea how the fuck the tech they're using works. They surely knew it should be private, but they did not know that they were making it publicly available because they were blindly fumbling their way around in a job beyond their competence level. There is a 0% chance this was ordinary carelessness, in the form of "I know better but don't care enough", this is so clearly a case…

Any time someone tries to suggest certification as a solution I ask the same question: How would it have solved this problem? Would the certification require someone to take an official certification test for the framework used? And therefore we’re only allowed to use frameworks which have certification tests available? If you want to write some new software, do you have to generate a certification for it and get tha…

> Would the certification require someone to take an official certification test for the framework used?

> And therefore we’re only allowed to use frameworks which have certification tests available?

When it's safety-critical, yes, absolutely. A service that handles sensitive PII, such as the one whose "engineers" should be prosecuted for this incident, is definitionally safety-critical.

If you're afraid in that world you'd be unable to work, maybe you deserve to be.

Re: Tell HN: Fiverr left customer files public and searchable

#105
post #69

I've been boycotting Fiverr, so I'm glad I'm not caught up in this. And judging by their response to this issue, I'm glad I've been boycotting it.

I've never tried their platform, but I once made an account on Upwork and it is absolutely ridiculous. I'm sure they are very similar.

People are asking for AWS help and giving root passwords to random contractors. A lot of people asking for CPA letters for loans and help with tax problems but their budget is under $100. And outright fraud posts are often seen asking for people to open bank accounts or otherwise bypass KYC.

Upwork now has an AI feature to help write job posts, so all the time you can see things like "If you want to attract freelancers like X, I can change it." So now the job posts are all written like corporate ones talking about "highly experienced in X" but pay almost nothing. Half the time the clients don't even know the words in their own post. And it charges every time someone applies to a job and then more to boost to top of list because every job gets 30+ applications supposedly.

Re: Tell HN: Fiverr left customer files public and searchable

#106
post #89

Earlier quoted context omitted.

https://fiverr-res.cloudinary.com/image/upload/f_pdf,q_auto/... This is too funny

Personally, this is the funniest one to me. It turns out Fiverr uses cloudinary for their internal documents as well. (Note: this one is not confidential and is public information) https://fiverr-res.cloudinary.com/image/upload/f_pdf,q_auto/...

Shows you how much these certifications are worth in reality.

Re: Tell HN: Fiverr left customer files public and searchable

#109
post #69

I've been boycotting Fiverr, so I'm glad I'm not caught up in this. And judging by their response to this issue, I'm glad I've been boycotting it.

I've never tried their platform, but I once made an account on Upwork and it is absolutely ridiculous. I'm sure they are very similar. People are asking for AWS help and giving root passwords to random contractors. A lot of people asking for CPA letters for loans and help with tax problems but their budget is under $100. And outright fraud posts are often seen asking for people to open bank accounts or otherwise bypa…

Upwork struck me as a straight up scam or pyramid scheme or something. Total turnoff.

Re: Tell HN: Fiverr left customer files public and searchable

#110

Earlier quoted context omitted.

Any time someone tries to suggest certification as a solution I ask the same question: How would it have solved this problem? Would the certification require someone to take an official certification test for the framework used? And therefore we’re only allowed to use frameworks which have certification tests available? If you want to write some new software, do you have to generate a certification for it and get tha…

The fact that you're thinking purely in frameworks is the exact problem that plagues the software industry. Framework-focused development is why we're in this mess; frameworks make it easy for people who don't understand how to program to publish shitty software by copying-and-pasting code and fudging around a few strings or variables to match their use case. That kind of accessibility is great for low-stakes softwar…

i have bad news for you
Post reply on HN