Live data from Hacker News

Tell HN: Fiverr left customer files public and searchable

news.ycombinator.com

171–180 of 252 posts

Re: Tell HN: Fiverr left customer files public and searchable

#171
post #69

I've been boycotting Fiverr, so I'm glad I'm not caught up in this. And judging by their response to this issue, I'm glad I've been boycotting it.

I've never tried their platform, but I once made an account on Upwork and it is absolutely ridiculous. I'm sure they are very similar. People are asking for AWS help and giving root passwords to random contractors. A lot of people asking for CPA letters for loans and help with tax problems but their budget is under $100. And outright fraud posts are often seen asking for people to open bank accounts or otherwise bypa…

I think the AI thing also transforms functional requirements into technical requirements, often incorrectly.

"I want to build a website" gets converted into:

"I'm looking for someone with 5+ years of 'hands on' React experience"

Re: Tell HN: Fiverr left customer files public and searchable

#172

It seems that someone sent a DMCA complaint months ago relating to this: https://lumendatabase.org/notices/53130362

> Recipient: Google LLC

This complaint was sent to Google, probably because the cloudinary.com URL appeared in their search results.

It's doubtful anyone at Fiverr was made aware of this - unless Google typically forwards these complaints to the actual host of the offending URL. Even then, it would go to Cloudinary who would in turn need to notify their client. Many hops with plenty of "someone else's problem" barriers for the message to overcome.

Re: Tell HN: Fiverr left customer files public and searchable

#173

This is crazy! So many tax and other financial forms out in the open. But the most interesting file I’ve seen so far seems to be a book draft titled “HOOD NIGGA AFFIRMATIONS: A Collection of Affirming Anecdotes for Hood Niggas Everywhere”. I made it to page 27 out of 63.

I found someone's manuscript, at first I thought it would be scandalous to find it ghost written, but it actually is just annotations and someone proof reading it, the annotations come up in the PDF I found the author on Amazon and the book still hasn't been released this is sad

[deleted]

Re: Tell HN: Fiverr left customer files public and searchable

#174
post #53

Earlier quoted context omitted.

it's worse than you think – it's an admin password to the ~whole site~

Oh my. I feel for the tech team at fiverr. I'm sure it's nasty in there. Sending virtual hugs.

Meanwhile, I hope they get sent to prison for being so cavalier with other people's PII.

Re: Tell HN: Fiverr left customer files public and searchable

#175
post #92
post #81

Earlier quoted context omitted.

Do I have to start emailing the people in the leaked documents with screenshots?

Leaving a paper trail of you having accessed unauthorized private info is a bad idea, some crazy lawyer could decide to include you in a suit. Just not worth the hassle. Email a tip line about the general situation.

How is it unauthorised if it's freely available via a search without having to bypass any login?

It'd be like putting up an advert and then trying to sue anyone who sees it.

Re: Tell HN: Fiverr left customer files public and searchable

#176
post #158

I don't really see what the issue is here? Someone with access to the URL (either the freelancer or the client) leaked it to Google, Google crawled it. How is this Fiverr's fault? I mean, okay, they could sign URLs, but it's not like they left a folder with directory listing on. Someone with access to the URLs, not them, willingly made the URLs public.

Users should have to be authenticated to access the resource, not just rely on the URL being a secret.

Re: Tell HN: Fiverr left customer files public and searchable

#178
post #149

Earlier quoted context omitted.

There were also a ton of ArtIsts of the "Take the job, generate it with AI, throw the slop" rip and run kind of artistry.

Even before AI I remember reading that many of the "custom designed" logos on Fiverr were just ripoffs of existing trademarks.

There are sites where you can buy 200 different shape stencils for $100, and most logos are just those with text added.

When I found out years down the track that I paid like $1000 for a “premium experience” to be offered 6 or so stencils like this, I was pretty furious. Luckily, I picked none of them, and made the artist draw it exactly as I later described.

Re: Tell HN: Fiverr left customer files public and searchable

#179

Files are now returning 404s as of right now, 0900 UTC 4/15. Would be interesting if someone with an account can check if they are visible to intended users or not, and if so, if their mitigation is robust (signed URLs?).

I have an account and I can confirm that the URL's of shared files are still publicly accessible. Google is giving 404's indeed.

Re: Tell HN: Fiverr left customer files public and searchable

#180

Earlier quoted context omitted.

The fact that you're thinking purely in frameworks is the exact problem that plagues the software industry. Framework-focused development is why we're in this mess; frameworks make it easy for people who don't understand how to program to publish shitty software by copying-and-pasting code and fudging around a few strings or variables to match their use case. That kind of accessibility is great for low-stakes softwar…

I follow your logic here, and it's certainly a coherent argument. That said, there are perhaps some factors you are overlooking which matter. The first is that no amount of certification solves the actual problem (which is that security mistakes are made, often in new and novel ways.) Secondly the amount of software being needed (and produced) is immense. Bridges require engineers, but the demand for new bridges is t…

"Bridges" are shorthand. There is no shortage of need for new infrastructure. Any kind of construction needs engineers involved to ensure what's being built doesn't collapse from a gust of wind. Apparently, in the US, there seem to be about 1.5 million engineers and 4.5 million software developers. Well, I think in the short term, certifying only 1.5 million "software engineers" would be fine, actually. Note that my argument pertains only to sensitive software. If you want to make software that doesn't pose a danger to its users, you don't need an 'engineer'. This should have the second-order benefit of making PII toxic waste. If you need a real engineering team to process PII, companies that don't need PII will stop scraping every last fucking thing and leaking it. The majority of software in the world doesn't actually need PII to function, they could just be incentivized to stop hoarding it and use a regular "software development" team if they want to deliver cheap and fast.

I also wouldn't specifically associate this with college degrees. In fact I think universities are doing a shockingly bad job of producing functional software developers. But, on the other hand, you don't need a university to produce a good programmer. Software development is possibly the most open, information-available discipline in the world. Self-motivated learners can absolutely become competent on their own. The certification should be merit-based, and provide a clear path to learning the material the certification is based on. Many people will go through the effort to educate themselves and learn the required skills, especially if certified software engineers are in high demand and command a higher salary.

Regarding the penalty-for-failure, as I said, the harm is not as immediately apparent as when people die in a bridge collapse. But leaking sensitive information still leads to people dying, even if the connection is not as direct. Doxxing and blackmail frequently lead to suicide, and there are other damages that could lead to a butterfly effect culminating in a higher death rate, or, even if not death, tangible harm. This leak contained birth certificates, IDs, passports, tax documentation, passwords, all kinds of information that could be used to ruin someone's life with identity fraud. There is also, of course, some software in the world that is directly safety-critical, much of the software used in the health field for instance, which is also currently being written by the lowest bidder in many cases.

Regarding management, they don't need a certification but rather consequences for their actions. Currently the incentive structure is such that management is rewarded for cutting costs and is never punished for harming customers. Fiverr, for instance, should be facing an investigation that threatens to shut down the business given that not only did this happen in the first place, and not only did they ignore it for 40 days, but even after it went public the sensitive files were still accessible for 12+ hours (notably, after they were definitely made aware of it, given reports in this thread of people receiving replies from Fiverr about it). Maybe throw in some criminal liability for the people most responsible for a situation this horrible. Management would tighten up real quick.

I don't agree that this is unimplementable in the real world at all. If anything it's a complete abnormality that software development is the way it is, when most other skilled professions are licensed and regulated.

Post reply on HN