Live data from Hacker News

Thoughts on the Posterous hack

blog.dustincurtis.com

21–30 of 62 posts

Re: Thoughts on the Posterous hack

#21
post #16
post #14

"As a user, I fully accept it. http://blog.dustincurtis.com has received almost a million pageviews in the past year, and this is the first time this has ever happened. And It happened because I provoked it in an extremely popular article was posted to a community of hackers. To be honest, I expected someone to try this." as an EDUCATED user YOU accept it, i'm not sure most of the posterous users understand and would…

If someone steals your car, you're out many thousands of dollars and extremely inconvenienced. If some random idiot posts a link to a Nigerian scam on your blog, you just delete it and get on with your life.

Unless you're one of several companies or high profile individuals that uses the service (YCombinator, Alex Bogusky, etc.)

Edit — More extensive list here: http://posterous.com/explore/moreblogs

Re: Thoughts on the Posterous hack

#23

Here's the deal - as soon as your blog reaches any level of popularity, people are going to want to deface it / hack it any way they can just because it's that much bigger of a prize. If Posterous is this easy to hack, once you have a decent sized blog you're going to have a constant field day until they implement something better. If you want to keep security simple enough that it doesn't strangle the service then h…

Apparently not, because his blog had "any level of popularity" long before it was hacked. Since this is the first I've ever heard of a Posterous hack, clearly it's not true that all decent sized blogs are being hacked constantly.

On the surface, what you say makes sense, but the real life data doesn't back it up.

Compare to: http://www.schneier.com/blog/archives/2010/05/why_arent_ther...

Re: Thoughts on the Posterous hack

#24
The real danger here isn't spam, it's false flag attacks.

If something offensive appears on your posterous under your name, will anyone believe you when you claim it's a hack?

On the other hand, maybe it provides a convenient excuse if you post something dumb and want to disown it . . .

Re: Thoughts on the Posterous hack

#25
post #16
post #14

"As a user, I fully accept it. http://blog.dustincurtis.com has received almost a million pageviews in the past year, and this is the first time this has ever happened. And It happened because I provoked it in an extremely popular article was posted to a community of hackers. To be honest, I expected someone to try this." as an EDUCATED user YOU accept it, i'm not sure most of the posterous users understand and would…

If someone steals your car, you're out many thousands of dollars and extremely inconvenienced. If some random idiot posts a link to a Nigerian scam on your blog, you just delete it and get on with your life.

maybe to you it doesn't matter, but these things can be intensely personal to people. it's still an issue of violating your space (to the layman end user, i know the technical definitions of "your space" are nebulous, im talking about the emotional ones that i think posterous is kind of violating).

and what happens when the idiot who posts the nigerian scam on your blog scams your mother who is reading your blog and assumes it's from you? no big deal? move on with your life? try and be a little imaginative with the things that could be done here...

if it's not a big deal, posterous should make it clear to users what they give up for convenience. again, i really don't think users would make the same choice they are to user posterous if they understood the implication. whether or not it matters to you.

and more importantly, there are a ton of people suggesting pretty viable alternatives that wouldn't make it harder to post and would still allow a lot more security.

Re: Thoughts on the Posterous hack

#26
My email address is of the form firstname@lastname.com, and I got around this issue by creating an alias for sending in Gmail that's firstname+randomstring@lastname.com. As a security measure it's not perfect, but it's not something someone's just going to be able to guess.

That solves the issue for me, but not for most (less tech-savvy) people. I think what Posterous needs is the ability to require confirmation by email when a post is made by email. I get that you can do this by setting your blog to 'anyone can post', but that seems counterintuitive, and most people don't understand how easy it is to spoof emails. As long as the confirmation can be done by email, I don't think it'd be much of an inconvenience.

Re: Thoughts on the Posterous hack

#27
post #5

Earlier quoted context omitted.

or just a random noun@posterous.com? Or make it user-configurable?

or both... assign a random GUID, and then allow the user to set it something they want if they choose. That's probably the simplest way, and of course the simpler the better for both development and security.

Surely the easiest way would be to require you put your password somewhere in the body of the email.

eg:

  Hi this is an example blog post
  I'm gonna see if this works
  ys8uc99p

Re: Thoughts on the Posterous hack

#28
post #9

He says there is no interest to post to his moms posterous, but is that really true? I can imagine quite a lot of spammers who would love to have a blog-post on an otherwise reputable blog. If spammers manage to abuse this system they could get their blogposts, filled with links and instructions to buy medication, all over all posterous blogs.

I remember reading somewhere about the abysmal conversion rates that spammers get (it was something like 1 in 12 million or something like that).

So, you'd need some 12 million blog posts that look real enough to fool a user's reader to get one conversion.

And it's not like Posterous isn't aware of the insecure nature of email. As some have suggested, they can just turn on pre-approval of submissions and this whole thing would be moot.

Put it another way: if you were to compete against them, would you create a blog-by-email service that focuses on being secure? Or ease of use? I imagine the latter has a lot more value to users. As Schneier always says, security is all about trade-offs and choosing to handle "what-if" scenarios tend to be less nice than handling "this-is-what-is-going-on-for-real" scenarios

Re: Thoughts on the Posterous hack

#29
1) Why can I not comment on the actual post? That's a little disconcerting.

2) I don't understand the need to post by e-mail. What does that gain me? Is there any use in that other than gimmick? Wouldn't a nice site offer me more chances for formatting, etc? What is the difference between typing info into a site and into an e-mail? What is the benefit? Can't a site be easier to use than e-mail?

3) Security is not a concern? I hope you are happy with the size of your company since it can not grow, because once you become any kind of force in the market, you will have to deal with things that you may not have to deal with now.

If you can't think of any scenarios in which this is a problem, let me enlighten you: - Lawsuits because an angry ex/employee/anyone posts items on a blog. (Yes, this can happen with other systems, but a lack of security is different from being hacked/people stealing passwords, etc). - Competitors who want to cause you problems. - Unhappy customers who find their site "hacked" including support time and money. Now that the "hack" is discovered, expect more. Security through ignorance is gone once the ignorance is gone.

When you ignore warning signs because nothing bad has happened YET, get ready. Look at BP. Over 700 violations they shrugged off because it didn't affect them. Now it does and their stock, company name, and the well-being of many they affected is in the toilet.

This is your wake up call. Listen to it: don't ignore it. Security matters.

Re: Thoughts on the Posterous hack

#30
Posterous could offer a really simple, and optional, security option by disabling auto-posting unless your email includes a secret key. E.g. you would have to write 'passkey=tomato' somewhere in your email.

If the email doesn't include the passkey, the user would receive a "click link to publish" email.

Simple.

Post reply on HN