Wow, the other comments weren't exaggerating. This is really bad. If my tax returns or other data were part of this, I might consider legal action. I wonder if somewhere like Wired/Ars Technica/404media might pick this up?
Company is now telling media this is intended behavior and users knew these files were public / shared the URLs themselves. We need to get some media with wider scope to challenge that.
Tell HN: Fiverr left customer files public and searchable
241–250 of 252 posts
Re: Tell HN: Fiverr left customer files public and searchable
#242@dang example query feels incredibly doxxy, and feels bad form to link directly to full copies of people's [stuff] and [personal info] as seen on this page :/ I know this is all Fiverr's fault for allegedly missing the responsible disclosure but now is this the ideal way for us to discuss, with these particular examples? I ask not to spare Fiverr, but I would be so mad if I were first for the result in OP or my perso…
@dang doesn't work write an email if you mean your comment in a non performative way.
Re: Tell HN: Fiverr left customer files public and searchable
#243Earlier quoted context omitted.
Link please :pray:
Now returns Null for me, but looks like it was https://fiverr-res.cloudinary.com/image/upload/f_pdf,q_auto/... Also, a version of this appears to be currently sold on Amazon for $15 USD.
Re: Tell HN: Fiverr left customer files public and searchable
#244Earlier quoted context omitted.
Also if you are personally liable of gross negligence, you will: 1. Get paid more (as less fake "engineers" are available for the responsibility). 2. Push back harder (or at least document in detail) on malpractice during development. Manager did not listen to your warnings? Document it and when shit hits the fan, the manager gets the stick instead of you. Hitting companies with monetary fines does not work. Hitting…
> Hitting companies with monetary fines does not work. Hitting the employees with jail time will make sure they don't sign on dangerous or known problematic systems. What!? So, when you can't switch jobs because the market is bad or for any other reason, your choices are: 1) quit and lose the income (which you can't afford) or 2) sign on whatever and accept the risk of jail time?
If you are certified, chances are you will have lots of choices to work.
Re: Tell HN: Fiverr left customer files public and searchable
#245Earlier quoted context omitted.
Also if you are personally liable of gross negligence, you will: 1. Get paid more (as less fake "engineers" are available for the responsibility). 2. Push back harder (or at least document in detail) on malpractice during development. Manager did not listen to your warnings? Document it and when shit hits the fan, the manager gets the stick instead of you. Hitting companies with monetary fines does not work. Hitting…
> Hitting companies with monetary fines does not work. Hitting the employees with jail time will make sure they don't sign on dangerous or known problematic systems. What!? So, when you can't switch jobs because the market is bad or for any other reason, your choices are: 1) quit and lose the income (which you can't afford) or 2) sign on whatever and accept the risk of jail time?
Software devs have been insanely privileged, for the last couple of decades. That seems to be changing.
Re: Tell HN: Fiverr left customer files public and searchable
#246Re: Tell HN: Fiverr left customer files public and searchable
#247Earlier quoted context omitted.
It’s a huge mistake to assume these links have to originate from fiverr-hosted HTML, it’s far more likely Google is finding them from places like GitHub repos used by fiverr-users.
That was my first thought, but is it logical to assume that 5+ unrelated people took their finished tax return URL and linked it on a website/tweet/etc? Who would do that? Even still, Fiverr could very well have GDPR/CCPA/etc liability as the host of these files, because they related to its services, it's not just a generic file host.
Indian users, at least that’s what github data suggests.
Re: Tell HN: Fiverr left customer files public and searchable
#248Re: Tell HN: Fiverr left customer files public and searchable
#249Re: Tell HN: Fiverr left customer files public and searchable
#250Earlier quoted context omitted.
My work has a “donuts” slack channel for this. You find an unlocked computer you post “donuts on me!” Social pressure says they buy the office donuts. Still get a few a week, but at least it’s public and amusing.
This would be borderline illegal in most countries. Not very enforcable, sure, but illegal.