Tell HN: Fiverr left customer files public and searchable
211–220 of 252 posts
Re: Tell HN: Fiverr left customer files public and searchable
#212Earlier quoted context omitted.
> Therefore, for these files to be indexed by Google, they need to be linked to from somewhere. So? That’s indeed how Google works. Google does not work how OP describes it. I’ve investigated similar incidents in the past on other platforms, it was always user error causing links to be public.
Can you actually explain why the phrase you cited from OP is wrong? You say that ~”files need to be linked to from somewhere” is correct. How is a file linked to from somewhere [on the internet] if it’s not being served on the internet that Google crawls (ie, HTML)? The only alternative is in… API calls? That Google probably isn’t crawling? “Fiverr might be hosting public HTML somewhere” seems like an entirely reason…
Re: Tell HN: Fiverr left customer files public and searchable
#213"To be clear, this is not a cyber incident. Fiverr does not proactively expose users' private information. The content in question was shared by users in the normal course of marketplace activity to showcase work samples, under agreements and approvals between buyers and sellers. This type of content requires the buyer's consent before it can be uploaded. As always, any request to remove content is handled promptly by our team."
Re: Tell HN: Fiverr left customer files public and searchable
#214Answer from Fiverr: "To be clear, this is not a cyber incident. Fiverr does not proactively expose users' private information. The content in question was shared by users in the normal course of marketplace activity to showcase work samples, under agreements and approvals between buyers and sellers. This type of content requires the buyer's consent before it can be uploaded. As always, any request to remove content i…
Re: Tell HN: Fiverr left customer files public and searchable
#215it's been 5 hours. even manual action to take down the most sensitive files should have completed about 3 hours ago at most. what is happening.
My guess is that if they take down the public hosting, most clients would lose access to work they paid for and fiverr has no way to put these back behind an authorisation. It is just a public list of files, either everyone has access to your file, or do not, including you.
Re: Tell HN: Fiverr left customer files public and searchable
#216Answer from Fiverr: "To be clear, this is not a cyber incident. Fiverr does not proactively expose users' private information. The content in question was shared by users in the normal course of marketplace activity to showcase work samples, under agreements and approvals between buyers and sellers. This type of content requires the buyer's consent before it can be uploaded. As always, any request to remove content i…
I also commented this, but I have to say their statement is false. The links to all the delivered projects are publicly accessible. I went over my orders and I could open every single one from another device, not logged in.
Re: Tell HN: Fiverr left customer files public and searchable
#217Extremely bad stuff here. Can't believe it's been 7 hours now and you can still pull up people's complete prepared tax returns right from a Google search. This should be a business-ending breach of trust and good practices, but I worry there's probably a lack of regulatory might or will to make anything happen.
It looks like they (cloudinary?) blocked the content. Each result from the query site:fiverr-res.cloudinary.com form 1040 returns 404
Re: Tell HN: Fiverr left customer files public and searchable
#218Update: Fiverr denies allegations of a cybersecurity incident on X. “To be clear, this is not a cyber incident. Fiverr does not proactively expose users’ private information. The content in question was shared by users in the normal course of marketplace activity to showcase work samples, under agreements and approvals between buyers and sellers. This type of content requires the buyer’s consent before it can be uplo…
Re: Tell HN: Fiverr left customer files public and searchable
#219Earlier quoted context omitted.
How is it unauthorised if it's freely available via a search without having to bypass any login? It'd be like putting up an advert and then trying to sue anyone who sees it.
Some crazy lawyer included my parents in a traffic death suit’s defendants while they were victims who had their car badly damaged when the reckless driver rammed into two cars (including my parents’) and two pedestrians. The question isn’t whether you’re at fault, it’s whether you want to risk getting a court summons.
Surely the entire point of the court system is to determine who, if anyone, is at fault.
Re: Tell HN: Fiverr left customer files public and searchable
#220Update: Fiverr denies allegations of a cybersecurity incident on X. “To be clear, this is not a cyber incident. Fiverr does not proactively expose users’ private information. The content in question was shared by users in the normal course of marketplace activity to showcase work samples, under agreements and approvals between buyers and sellers. This type of content requires the buyer’s consent before it can be uplo…
this is because you copied the link with the token, token is generated for your logged in user. strip the token and it wouldn't work. other users does not have your token.