Live data from Hacker News

Quora engineers accused of vandalizing a clone’s website

greyreview.com

21–30 of 59 posts

Re: Quora engineers accused of vandalizing a clone’s website

#21
Same thing happened in my friend's company and they fired the engineer who identified and exploited the permanent XSS in their competitor's website. Personally I would do the very same thing.

1. It's against the law 2. Extremely unprofessional and childish 3. There are better ways to report security vulnerabilities

Re: Quora engineers accused of vandalizing a clone’s website

#22
post #13

I just left the following comment: -- It's pretty lame to copy the design and trade dress of another product. It does not bode well for your skill or ability. Backstory: A long time ago I wrote Delicious. We had hundreds of copycats and competitors. The ones that weren't direct copies were the ones that did better. I'm sure this doesn't apply to you for whatever reason.

If Qato is going to copy someone's design, can't they find something better than Quora?

I mean, Quora's design isn't going to win them any awards; it looks like Quora didn't even use Photoshop, just straight-up CSS.

Re: Quora engineers accused of vandalizing a clone’s website

#23
post #19

Everyone's right that it was an ill-advised thing to do, but stepping back ignoring the law (I know..) and just asking yourself the gut question: What's worse? injecting a relatively harmless script into the product (that frankly caused them to fix an issue that could have been very painful for them if someone more devious had found it first), or Qato's ripoff of Quora in the first place?

Putting the legal issues aside? It doesn't matter either way: security vulnerabilities trump copycats (in my opinion). Publicly releasing details of an XSS vulnerability on a third party's site has much bigger ramifications than a copycat site. Plenty of websites deal with copycats all the time: they're frustrating, but they're not necessarily overly threatening. On the other hand, a 0 day could compromise the securi…

Mixed agreement.

...that could completely destroy your business

Yep.

Re: Quora engineers accused of vandalizing a clone’s website

#24
Just for the record, I meant it sincerely when I said that we were grateful that Ben Newman and Albert Sheu showed us an XSS hole in Qato, and that has now been fixed.

The site in question was just an unpromoted testing prototype which barely has any content and happened to have the Quora-like skin on at that moment. It probably shouldn't even have been publicly accessible.

Another Qato site on the same server is http://robofaqs.com, which is sporting our OSQA clone theme. It doesn't look anything like Quora at all, but is powered by literally the same server instance. That's what we're trying to say - Qato is the general purpose Q&A engine under the skin, and these various skins just modulate the way a Qato site looks.

Re: Quora engineers accused of vandalizing a clone’s website

#25

Same thing happened in my friend's company and they fired the engineer who identified and exploited the permanent XSS in their competitor's website. Personally I would do the very same thing. 1. It's against the law 2. Extremely unprofessional and childish 3. There are better ways to report security vulnerabilities

I sincerely hope that's not what happens here. I would hate to see someone lose their job over what seems to have been a temporary lapse in judgement.

Re: Quora engineers accused of vandalizing a clone’s website

#26
post #25

Same thing happened in my friend's company and they fired the engineer who identified and exploited the permanent XSS in their competitor's website. Personally I would do the very same thing. 1. It's against the law 2. Extremely unprofessional and childish 3. There are better ways to report security vulnerabilities

I sincerely hope that's not what happens here. I would hate to see someone lose their job over what seems to have been a temporary lapse in judgement.

Same here. But for developers who've worked at organizations like Mozilla in the past, you'd think they'd be better at handling this the way it should be rather than going script kiddy and juvenile on their own site.

Re: Quora engineers accused of vandalizing a clone’s website

#27
post #2

The full quote from Rick Ross is "I am grateful that Ben Newman and Albert Sheu of Quora have identified a (now fixed) XSS vulnerability in our test site, but I am surprised that Quora policy permits developers to engage so openly in vandalizing other people's websites." which is slightly nicer than that article makes it sound. Personally, I think the Quora engineers involved made some poor decisions. Anyone who look…

As a former web application security guy, and now developer, identifying and disclosing vulnerabilities on websites is still very much a troubled area. Most companies don't have proper security@ email addresses set up or monitored, and still don't take kindly to vulns being reported.

That said, publicly disclosing a flaw in addition to defacing the website, even temporarily, is certainly not a classy way to go about it.

Re: Quora engineers accused of vandalizing a clone’s website

#28
post #22
post #13

I just left the following comment: -- It's pretty lame to copy the design and trade dress of another product. It does not bode well for your skill or ability. Backstory: A long time ago I wrote Delicious. We had hundreds of copycats and competitors. The ones that weren't direct copies were the ones that did better. I'm sure this doesn't apply to you for whatever reason.

If Qato is going to copy someone's design, can't they find something better than Quora ? I mean, Quora's design isn't going to win them any awards; it looks like Quora didn't even use Photoshop, just straight-up CSS.

Because they are unoriginal followers. If they had any sense of direction they'd be able to build something of their own.

Re: Quora engineers accused of vandalizing a clone’s website

#29

Just for the record, I meant it sincerely when I said that we were grateful that Ben Newman and Albert Sheu showed us an XSS hole in Qato, and that has now been fixed. The site in question was just an unpromoted testing prototype which barely has any content and happened to have the Quora-like skin on at that moment. It probably shouldn't even have been publicly accessible. Another Qato site on the same server is htt…

FYI, underlined hyperlinks make it impossible to tell the difference between a "q" and a "g" in a URL. As such, I'd suggest you spend some time finding a better name for that unfortunately named site you linked.

Re: Quora engineers accused of vandalizing a clone’s website

#30

Just for the record, I meant it sincerely when I said that we were grateful that Ben Newman and Albert Sheu showed us an XSS hole in Qato, and that has now been fixed. The site in question was just an unpromoted testing prototype which barely has any content and happened to have the Quora-like skin on at that moment. It probably shouldn't even have been publicly accessible. Another Qato site on the same server is htt…

FYI, underlined hyperlinks make it impossible to tell the difference between a "q" and a "g" in a URL. As such, I'd suggest you spend some time finding a better name for that unfortunately named site you linked.

So I take it you're not a fan of http://www.gamefaqs.com ? ;-)
Post reply on HN