Live data from Hacker News

You don’t need a password. Posterous fail.

blog.dustincurtis.com

31–40 of 84 posts

Re: You don’t need a password. Posterous fail.

#31
post #27
post #26

Posterous really does fail here. I can see why they would want to tolerate a little of this to preserve ease of use for their users (just like Amazon with their Kindle email address). However, there are a number of steps that Posterous can take to combat forged headers in ways that should not impact users at all. Enabling SPF, for example, would be a good start. Technically, it's the same problem as email spam, and m…

> "The other fix would be to use an email address that can't be guessed from the blog address. In other words, the email address is the password." You'd still be sending your password in the clear, possibly through other peoples mail servers. Not great security.

The perfect is the enemy of the good.

There is a trade-off here between security and usability. 99% security is good enough for a lot of purposes and has its place.

Re: You don’t need a password. Posterous fail.

#32
post #30

While we're talking about Posterous, does anyone know why it adds a random number to the end of article URLs, as in http://blog.dustincurtis.com/apparently-765 ? I know it's not a big deal, but I find that aesthetically unpleasing, as it kind of ruins an otherwise beautiful URL.

Google's crawler (especially the blog and news ones) requires a three digit or larger number in the url. That is why you should keep a year/date in a url.

Update: Not sure why I got downvoted, but here is the reference from Google News:

http://www.google.com/support/news_pub/bin/answer.py?hl=en&#...

Re: You don’t need a password. Posterous fail.

#34
post #32
post #30

While we're talking about Posterous, does anyone know why it adds a random number to the end of article URLs, as in http://blog.dustincurtis.com/apparently-765 ? I know it's not a big deal, but I find that aesthetically unpleasing, as it kind of ruins an otherwise beautiful URL.

Google's crawler (especially the blog and news ones) requires a three digit or larger number in the url. That is why you should keep a year/date in a url. Update: Not sure why I got downvoted, but here is the reference from Google News: http://www.google.com/support/news_pub/bin/answer.py?hl=en&#...

Why do they want this?

Re: You don’t need a password. Posterous fail.

#36
post #30

While we're talking about Posterous, does anyone know why it adds a random number to the end of article URLs, as in http://blog.dustincurtis.com/apparently-765 ? I know it's not a big deal, but I find that aesthetically unpleasing, as it kind of ruins an otherwise beautiful URL.

It might be a namespace thing? I have seen that too, and that is the only thing that comes to mind.

Re: You don’t need a password. Posterous fail.

#37
post #9

Earlier quoted context omitted.

As I understand it, they send you a mail telling you about the post and letting you remove it. Not perfect, but probably works 99% of the time.

Shouldn't it work oppositely? Prevent the post from appearing until you explicitly approve it from a link in an email.

Sort of defeats the purpose of Posterous though. It's nice to be able to send an email and be done with it. Though for an account coming under constant attack, it'd be nice to have the option though.

Edit: What they should really do is obfuscate the posting email addresses a little. Make my posting email 1234randomwords@posterous.com, and give me the option to change it to something else if I am coming under attack.

Re: You don’t need a password. Posterous fail.

#38
post #28

Earlier quoted context omitted.

I updated the post to reflect reality. Usually, Posterous catches this stuff and sends an email asking you to confirm that you really are you. They analyze the headers more closely than just looking at the name. For some reason, this didn't work in this case.

According to him he just changed his email address to your email address in Outlook. Edit: dcurtis edited his comment. Originally he claimed there was some kind of secret algorithm that prevents spoofing.

[deleted]

Re: You don’t need a password. Posterous fail.

#39
post #32
post #30

While we're talking about Posterous, does anyone know why it adds a random number to the end of article URLs, as in http://blog.dustincurtis.com/apparently-765 ? I know it's not a big deal, but I find that aesthetically unpleasing, as it kind of ruins an otherwise beautiful URL.

Google's crawler (especially the blog and news ones) requires a three digit or larger number in the url. That is why you should keep a year/date in a url. Update: Not sure why I got downvoted, but here is the reference from Google News: http://www.google.com/support/news_pub/bin/answer.py?hl=en&#...

Don't downvote snewe, he/she is correct: http://www.google.com/support/news_pub/bin/answer.py?answer=...

I can't figure out why though. It sounds like an incredibly stupid rule.

Re: You don’t need a password. Posterous fail.

#40
post #34
post #32

Earlier quoted context omitted.

Google's crawler (especially the blog and news ones) requires a three digit or larger number in the url. That is why you should keep a year/date in a url. Update: Not sure why I got downvoted, but here is the reference from Google News: http://www.google.com/support/news_pub/bin/answer.py?hl=en&#...

Why do they want this?

[deleted]
Post reply on HN