Live data from Hacker News

Tell HN: Fiverr left customer files public and searchable

news.ycombinator.com

241–250 of 252 posts

Re: Tell HN: Fiverr left customer files public and searchable

#241
post #46

Wow, the other comments weren't exaggerating. This is really bad. If my tax returns or other data were part of this, I might consider legal action. I wonder if somewhere like Wired/Ars Technica/404media might pick this up?

Company is now telling media this is intended behavior and users knew these files were public / shared the URLs themselves. We need to get some media with wider scope to challenge that.

Right? On what planet does someone think that if they share a doc in a private 1on1 chat on Fiverr, that means the doc is going to be indexed by google. Shameless.

Re: Tell HN: Fiverr left customer files public and searchable

#242
post #76

@dang example query feels incredibly doxxy, and feels bad form to link directly to full copies of people's [stuff] and [personal info] as seen on this page :/ I know this is all Fiverr's fault for allegedly missing the responsible disclosure but now is this the ideal way for us to discuss, with these particular examples? I ask not to spare Fiverr, but I would be so mad if I were first for the result in OP or my perso…

@dang doesn't work write an email if you mean your comment in a non performative way.

First thought is about driving a discussion rather than putting on a performance, yes? then second thought I see would be performative, thanks for the call out and the very important tip I will not forget!

Re: Tell HN: Fiverr left customer files public and searchable

#243

Earlier quoted context omitted.

Link please :pray:

Now returns Null for me, but looks like it was https://fiverr-res.cloudinary.com/image/upload/f_pdf,q_auto/... Also, a version of this appears to be currently sold on Amazon for $15 USD.

They patched the "non-existent" issue it seems. And totally denied it happened in the first place. Honestly, someone should do a dump of redacted client documents to teach them a lesson. Short of a class action lawsuit would be an understatement. This is really huge.

Re: Tell HN: Fiverr left customer files public and searchable

#244
post #235
post #181

Earlier quoted context omitted.

Also if you are personally liable of gross negligence, you will: 1. Get paid more (as less fake "engineers" are available for the responsibility). 2. Push back harder (or at least document in detail) on malpractice during development. Manager did not listen to your warnings? Document it and when shit hits the fan, the manager gets the stick instead of you. Hitting companies with monetary fines does not work. Hitting…

> Hitting companies with monetary fines does not work. Hitting the employees with jail time will make sure they don't sign on dangerous or known problematic systems. What!? So, when you can't switch jobs because the market is bad or for any other reason, your choices are: 1) quit and lose the income (which you can't afford) or 2) sign on whatever and accept the risk of jail time?

The job market in such society would not be the same as it is now.

If you are certified, chances are you will have lots of choices to work.

Re: Tell HN: Fiverr left customer files public and searchable

#245
post #235
post #181

Earlier quoted context omitted.

Also if you are personally liable of gross negligence, you will: 1. Get paid more (as less fake "engineers" are available for the responsibility). 2. Push back harder (or at least document in detail) on malpractice during development. Manager did not listen to your warnings? Document it and when shit hits the fan, the manager gets the stick instead of you. Hitting companies with monetary fines does not work. Hitting…

> Hitting companies with monetary fines does not work. Hitting the employees with jail time will make sure they don't sign on dangerous or known problematic systems. What!? So, when you can't switch jobs because the market is bad or for any other reason, your choices are: 1) quit and lose the income (which you can't afford) or 2) sign on whatever and accept the risk of jail time?

Sounds like every other vocation out there.

Software devs have been insanely privileged, for the last couple of decades. That seems to be changing.

Re: Tell HN: Fiverr left customer files public and searchable

#247

Earlier quoted context omitted.

It’s a huge mistake to assume these links have to originate from fiverr-hosted HTML, it’s far more likely Google is finding them from places like GitHub repos used by fiverr-users.

That was my first thought, but is it logical to assume that 5+ unrelated people took their finished tax return URL and linked it on a website/tweet/etc? Who would do that? Even still, Fiverr could very well have GDPR/CCPA/etc liability as the host of these files, because they related to its services, it's not just a generic file host.

> Who would do that?

Indian users, at least that’s what github data suggests.

Re: Tell HN: Fiverr left customer files public and searchable

#250
post #120
post #73

Earlier quoted context omitted.

My work has a “donuts” slack channel for this. You find an unlocked computer you post “donuts on me!” Social pressure says they buy the office donuts. Still get a few a week, but at least it’s public and amusing.

This would be borderline illegal in most countries. Not very enforcable, sure, but illegal.

Nobody would give a damn about it.
Post reply on HN