Live data from Hacker News

Tell HN: Fiverr left customer files public and searchable

news.ycombinator.com

211–220 of 252 posts

Re: Tell HN: Fiverr left customer files public and searchable

#212

Earlier quoted context omitted.

> Therefore, for these files to be indexed by Google, they need to be linked to from somewhere. So? That’s indeed how Google works. Google does not work how OP describes it. I’ve investigated similar incidents in the past on other platforms, it was always user error causing links to be public.

Can you actually explain why the phrase you cited from OP is wrong? You say that ~”files need to be linked to from somewhere” is correct. How is a file linked to from somewhere [on the internet] if it’s not being served on the internet that Google crawls (ie, HTML)? The only alternative is in… API calls? That Google probably isn’t crawling? “Fiverr might be hosting public HTML somewhere” seems like an entirely reason…

It’s a huge mistake to assume these links have to originate from fiverr-hosted HTML, it’s far more likely Google is finding them from places like GitHub repos used by fiverr-users.

Re: Tell HN: Fiverr left customer files public and searchable

#213
Answer from Fiverr:

"To be clear, this is not a cyber incident. Fiverr does not proactively expose users' private information. The content in question was shared by users in the normal course of marketplace activity to showcase work samples, under agreements and approvals between buyers and sellers. This type of content requires the buyer's consent before it can be uploaded. As always, any request to remove content is handled promptly by our team."

https://x.com/fiverr/status/2044389801495773339?s=20

Re: Tell HN: Fiverr left customer files public and searchable

#214

Answer from Fiverr: "To be clear, this is not a cyber incident. Fiverr does not proactively expose users' private information. The content in question was shared by users in the normal course of marketplace activity to showcase work samples, under agreements and approvals between buyers and sellers. This type of content requires the buyer's consent before it can be uploaded. As always, any request to remove content i…

I also commented this, but I have to say their statement is false. The links to all the delivered projects are publicly accessible. I went over my orders and I could open every single one from another device, not logged in.

Re: Tell HN: Fiverr left customer files public and searchable

#215

it's been 5 hours. even manual action to take down the most sensitive files should have completed about 3 hours ago at most. what is happening.

My guess is that if they take down the public hosting, most clients would lose access to work they paid for and fiverr has no way to put these back behind an authorisation. It is just a public list of files, either everyone has access to your file, or do not, including you.

My guess is that there is literally no one there who knows how to fix this. Seriously, look through the proposed solutions here, plenty of devs wouldn't know how to do any of them. It might not even be possible, with their architecture, to fix it quickly and retain functionality. I have worked in a place full of noobs where I'm certain none of the devs including me would have the first idea how to fix something like this.

Re: Tell HN: Fiverr left customer files public and searchable

#216

Answer from Fiverr: "To be clear, this is not a cyber incident. Fiverr does not proactively expose users' private information. The content in question was shared by users in the normal course of marketplace activity to showcase work samples, under agreements and approvals between buyers and sellers. This type of content requires the buyer's consent before it can be uploaded. As always, any request to remove content i…

I also commented this, but I have to say their statement is false. The links to all the delivered projects are publicly accessible. I went over my orders and I could open every single one from another device, not logged in.

this is because copied the link with the token, token is generated for your logged in user. strip the token and it wouldn't work

Re: Tell HN: Fiverr left customer files public and searchable

#217
post #70

Extremely bad stuff here. Can't believe it's been 7 hours now and you can still pull up people's complete prepared tax returns right from a Google search. This should be a business-ending breach of trust and good practices, but I worry there's probably a lack of regulatory might or will to make anything happen.

It looks like they (cloudinary?) blocked the content. Each result from the query site:fiverr-res.cloudinary.com form 1040 returns 404

Yikes! It should not require the service provider to block PII, but at least someone plugged the leak.

Re: Tell HN: Fiverr left customer files public and searchable

#218

Update: Fiverr denies allegations of a cybersecurity incident on X. “To be clear, this is not a cyber incident. Fiverr does not proactively expose users’ private information. The content in question was shared by users in the normal course of marketplace activity to showcase work samples, under agreements and approvals between buyers and sellers. This type of content requires the buyer’s consent before it can be uplo…

this is because you copied the link with the token, token is generated for your logged in user. strip the token and it wouldn't work. other users does not have your token.

Re: Tell HN: Fiverr left customer files public and searchable

#219
post #188

Earlier quoted context omitted.

How is it unauthorised if it's freely available via a search without having to bypass any login? It'd be like putting up an advert and then trying to sue anyone who sees it.

Some crazy lawyer included my parents in a traffic death suit’s defendants while they were victims who had their car badly damaged when the reckless driver rammed into two cars (including my parents’) and two pedestrians. The question isn’t whether you’re at fault, it’s whether you want to risk getting a court summons.

I'm confused about what you're saying - are you saying that your parents risked getting a court summons though they weren't at fault?

Surely the entire point of the court system is to determine who, if anyone, is at fault.

Re: Tell HN: Fiverr left customer files public and searchable

#220

Update: Fiverr denies allegations of a cybersecurity incident on X. “To be clear, this is not a cyber incident. Fiverr does not proactively expose users’ private information. The content in question was shared by users in the normal course of marketplace activity to showcase work samples, under agreements and approvals between buyers and sellers. This type of content requires the buyer’s consent before it can be uplo…

this is because you copied the link with the token, token is generated for your logged in user. strip the token and it wouldn't work. other users does not have your token.

That's true, I just checked. I will edit my post, thanks!
Post reply on HN