Earlier quoted context omitted.
It kind of is, though. Google doesn't randomly try to visit every URL on the internet. It follows links. Therefore, for these files to be indexed by Google, they need to be linked to from somewhere.
> Therefore, for these files to be indexed by Google, they need to be linked to from somewhere. So? That’s indeed how Google works. Google does not work how OP describes it. I’ve investigated similar incidents in the past on other platforms, it was always user error causing links to be public.
Tell HN: Fiverr left customer files public and searchable
161–170 of 252 posts
Re: Tell HN: Fiverr left customer files public and searchable
#162Earlier quoted context omitted.
> Therefore, for these files to be indexed by Google, they need to be linked to from somewhere. So? That’s indeed how Google works. Google does not work how OP describes it. I’ve investigated similar incidents in the past on other platforms, it was always user error causing links to be public.
The only thing that's user error here is the developers of Fiverr exposing files without proper session authentication.
It’s bizarre UX if you link a file to someone and the link doesn’t work.
Re: Tell HN: Fiverr left customer files public and searchable
#163I don't get why disclosing is considered acceptable, it seems like racketeering to me, "pay up or else I'll make this hypothetical issue an actual issue for you" When I reported an issue and gotten no response, I sat on it for 6 years, reported it again and they took the whole site down without reaching out to me, never quite got it, but if people are doing this, it makes sense not to acknowledge any report and just…
I did include "bug bounty" in the email subject since they claimed to have a private program. Other than that, no mention of any kind of compensation. It probably doesn't even have any kind of resume value since it's not an actual code flaw/CVE, just an "unlocked door."
Re: Tell HN: Fiverr left customer files public and searchable
#164Re: Tell HN: Fiverr left customer files public and searchable
#165Re: Tell HN: Fiverr left customer files public and searchable
#166Re: Tell HN: Fiverr left customer files public and searchable
#167Earlier quoted context omitted.
It's so much worse in the industry, the truth is that many people literally have no idea how to secure things, what to secure, why to secure it - they pay no attention and are plainly ignorant of the state of the world and oftentimes just stupid. I worked at a company where a customer called confused because when they googled our company as they did every day to login to their portal they found that drivers licenses…
> they were just the cheapest labor the company could find who could do the thing. Thats the problem right there. The company doesn't care . No amount of personal certifications is going to fix that. It MUST be on the companies. They should be fined out of existence for such breaches and they would quickly change tune.
Looks like this is a great opportunity for an object lesson. Let’s see how it goes…
As far as certification stuff…
Civil engineering has had licensing forever. That’s because Bad Things Happen, when they make mistakes.
I do think that it would be a good idea to score/certify critical infrastructure stuff. That might involve certification of the people that make it, but it should certainly involve penalties for the people responsible. That might include the authors, but it should probably also include the folks that decide to use the bad code.
I know that ISO 9000 is an attempt to address this kind of thing. In my opinion, it’s kind of a mess. I’ve worked in ISO 9000 shops, and it’s not much fun. The thing you learn, pretty quickly, is how to end-run the process, as it’s so heavy, that it basically stops all forward progress. It doesn’t have to, but often does.
Mistakes get made. If you design carefully, these mistakes won’t cause real damage.
I just figured out that an app I wrote, that’s been out for two years, has an embarrassing bug (mea culpa). I’ll get it fixed today.
Because I’m pretty careful, it doesn’t affect stuff like user privacy. It just introduces performance overhead, in one operation, so the fix will mean that the app will suddenly speed up.
I’m not sure that certification would have solved it. My security mindset is why user privacy wasn’t affected, and that comes from experience.
> Good judgment comes from experience. Experience comes from bad judgement.
Re: Tell HN: Fiverr left customer files public and searchable
#168Would be interesting if someone with an account can check if they are visible to intended users or not, and if so, if their mitigation is robust (signed URLs?).
Re: Tell HN: Fiverr left customer files public and searchable
#169Wow, the other comments weren't exaggerating. This is really bad. If my tax returns or other data were part of this, I might consider legal action. I wonder if somewhere like Wired/Ars Technica/404media might pick this up?
[0] https://www.reddit.com/r/Fiverr/comments/1slzoey/other_atten...
Re: Tell HN: Fiverr left customer files public and searchable
#170Earlier quoted context omitted.
I have uploaded the email here: https://gist.github.com/aidanbh/3da7cecb3e2496e5c5110b88f21b... (technically, I guess that doesn't prove anything other than it is in my Sent folder? it has a message ID but I guess only the purelymail admin could confirm that) In any event, this should never have required an outside reminder. The indexing issue may be something non obvious. But the core decision not to use signed/expi…
I've contacted fiverr before about obvious fraud being conducted through their platform, and they just sent me in endless loops of "open a ticket". "No, e-mail us about it." "No, e-mail us at our security contact about it." Crickets, and then a response saying to please open a ticket. Basically, they aren't set up for anyone to actually contact them and expect a resolution.
For sure their internal metrics are all green and solved tickets are on the rise.