Live data from Hacker News

Moonpig.com Vulnerability – Exposes customer data

ifc0nfig.com

121–124 of 124 posts

Re: Moonpig.com Vulnerability – Exposes customer data

#121

Earlier quoted context omitted.

> does not seem to be a defensible action // What harm is there in viewing data? None. Defended. Which do you find is indefensible, seeking to consume data or consuming it? Or, does one need to actively seek it and also consume it to cross your threshold of immorality? Or ...

What harm is there in viewing data? None. Yes there is – you've consumed other people's data without permission. Would the same apply to physical trespass in your mind? Is there any harm in entering an accidentally unlocked house and snooping around? There's nothing preventing you from doing so... I'd argue that it's wrong, and equivalent to consuming data which is obviously intended to be private. It's not like ther…

>you've consumed other people's data //

Except you don't consume it, you view it. The data remains and is accessible at all times to others. If you don't use it you haven't consumed it in any way.

>Is there any harm in entering an accidentally unlocked house and snooping around? //

There is a lack of equivalence here IMO as personal space, such as in a dwelling place, is quite different from non-dwelling space. The case of viewing data (to me) is like a person walking across your farmland without permission; quite different to finding them in your bedroom. The lack of equivalence between physical and virtual spaces makes this analogy fundamentally flawed.

If it's addressable on the internet then it's not private: If you hide your diary under your bed, that's private. If you hide it under a bush in the park, that's not private.

>Surely you can only consume data if you seek to do so? //

I shouldn't have used "consume", as the data is not consumed but viewed (unless it's used in later actions that "consume" it somehow). That said, you can view data without seeking to view it; you can seek to view data without being able to view it. If in the OP the person had tried altering the account ID and they couldn't view data from their other account would they still be committing an indefensible wrong in your opinion?

Interestingly I was just on a site called PC Builder that had price data in INR (Rupee), switching to USD added a section to the URL and I, to see if I could use the site in GBP, went to the URL and altered it ... did I commit a crime in your opinion?

Re: Moonpig.com Vulnerability – Exposes customer data

#122
post #30

They have 3 other brands: http://photobox.co.uk http://uk.paper-shaker.com https://sticky9.com Only the later seems to enforce SSL. I registered a dummy account on photobox, username/password/email, via their form which was not using ssl.

Photobox is the parent company, which bought out moonpig, Papershaker and sticky9. Each product is an entirely different codebase and different team working on it (I know because I did some work for Papershaker, part of which was working on a site wide switchover to SSL - which for now you can manually opt into: https://uk.paper-shaker.com/).

Re: Moonpig.com Vulnerability – Exposes customer data

#123
post #58

Earlier quoted context omitted.

Personally (and I know this is likely to be an unpopular sentiment on HN) I have very little sympathy for weev. He knowingly and deliberately attack a weakness he had found to scrape data, knowing that the access was unauthorized. I disagree that the data was in the public domain (although the Third Circuit disagrees) - just because something is accessible to the public doesn't mean it's in the public domain. Just be…

Doubt it's as unpopular as you think.

Apparently - probably because of a silent majority instead of a vocal minority.

Re: Moonpig.com Vulnerability – Exposes customer data

#124
post #83

I've seen dumber. In my second real job, I was a book editor, but I noticed our web master literally had a file called accounts.js which held a static array of usernames, passwords, and billing information for all of our customers. I told him this was terrible security, and he said, literally, "You'd have to view source to even know passwords.js exists, and our source is pretty hard to read. I'm not worried." I took…

"I took all the info to our CEO and got him demoted to server maintenance guy, on the spot, and I took over his job" WOW. You are a terrible human being.

No, I'm really not. This guy was an arrogant ass who ignored me because I was 22 and he was 51 and he "was doing this stuff when I was still pooping my pants". He refused to follow best practices, and he refused to take advice.

I told our CEO what this guy was doing, why it was bad, why nobody else does that, and how it ought to be done instead. I honestly thought our boss would just force him to follow my recommendations. But instead he told me to just re-do it the right way myself. Boss made the best decision for the company.

You could have presented your objections in a more tactful manner, but you didn't, because you're a judgmental asshole.

Post reply on HN