Thoughts on the Posterous hack
31–40 of 62 posts
Re: Thoughts on the Posterous hack
#32Posterous actually has a nasty security hole which allows you to get the email address for any posterous which the user has not claimed. Here's a posterous I just created: http://john-tfk88.posterous.com/ that I have not claimed. The 'Claim this site' link goes to http://posterous.com/main/register?hash=Bu5fX3lRT2rYPURl7axZ... If you view source that you'll find that my email address is 'hidden' in the page: So, for…
Re: Thoughts on the Posterous hack
#33And this happens absolutely everywhere. And it's true. But this problem won't go away until we start FORCING people to adapt, by adopting stricter measures everywhere.
Re: Thoughts on the Posterous hack
#34He says there is no interest to post to his moms posterous, but is that really true? I can imagine quite a lot of spammers who would love to have a blog-post on an otherwise reputable blog. If spammers manage to abuse this system they could get their blogposts, filled with links and instructions to buy medication, all over all posterous blogs.
I remember reading somewhere about the abysmal conversion rates that spammers get (it was something like 1 in 12 million or something like that). So, you'd need some 12 million blog posts that look real enough to fool a user's reader to get one conversion. And it's not like Posterous isn't aware of the insecure nature of email. As some have suggested, they can just turn on pre-approval of submissions and this whole t…
Re: Thoughts on the Posterous hack
#35"As a user, I fully accept it. http://blog.dustincurtis.com has received almost a million pageviews in the past year, and this is the first time this has ever happened. And It happened because I provoked it in an extremely popular article was posted to a community of hackers. To be honest, I expected someone to try this." as an EDUCATED user YOU accept it, i'm not sure most of the posterous users understand and would…
If someone steals your car, you're out many thousands of dollars and extremely inconvenienced. If some random idiot posts a link to a Nigerian scam on your blog, you just delete it and get on with your life.
That's the problem with minimizing security: you're making it so that there can't (or shouldn't) be trust between users because there's no reliable way to know who is making the post.
"Hey, just a quick note to let you know I tried and I love it! Grab it now!"
Or, more dangerously, someone could post a phishing link and because the context is different, people's trained safeguards ("BE WARY OF E-MAIL!") aren't as wary to blog links.
So yes, there are sometimes tradeoffs between security and ease of use. But I think trust is more important to posterous than you credit.
Re: Thoughts on the Posterous hack
#36He says there is no interest to post to his moms posterous, but is that really true? I can imagine quite a lot of spammers who would love to have a blog-post on an otherwise reputable blog. If spammers manage to abuse this system they could get their blogposts, filled with links and instructions to buy medication, all over all posterous blogs.
I remember reading somewhere about the abysmal conversion rates that spammers get (it was something like 1 in 12 million or something like that). So, you'd need some 12 million blog posts that look real enough to fool a user's reader to get one conversion. And it's not like Posterous isn't aware of the insecure nature of email. As some have suggested, they can just turn on pre-approval of submissions and this whole t…
E-mail spammers might need to send out millions of messages to get a conversion, but a more carefully crafted scam on a popular blog might be profitable with significantly less views.
Re: Thoughts on the Posterous hack
#37There's nothing stopping Posterous keeping it working exactly the same way, but providing an additional layer of protection for users who want to lock down their blog.
1.) Don't publish emails unless they passed DKIM
2.) Don't publish emails unless they passed SPF
3.) Don't publish emails unless they contain a secret password
4.) Don't publish emails unless they're signed with my PGP key.
Any of the above would be enough. It's all about choice.
Re: Thoughts on the Posterous hack
#38Re: Thoughts on the Posterous hack
#39I care about my reputation, therefore I would not use Posterous. There's nothing stopping Posterous keeping it working exactly the same way, but providing an additional layer of protection for users who want to lock down their blog. 1.) Don't publish emails unless they passed DKIM 2.) Don't publish emails unless they passed SPF 3.) Don't publish emails unless they contain a secret password 4.) Don't publish emails un…
Re: Thoughts on the Posterous hack
#40"As a user, I fully accept it. http://blog.dustincurtis.com has received almost a million pageviews in the past year, and this is the first time this has ever happened. And It happened because I provoked it in an extremely popular article was posted to a community of hackers. To be honest, I expected someone to try this." as an EDUCATED user YOU accept it, i'm not sure most of the posterous users understand and would…
If someone steals your car, you're out many thousands of dollars and extremely inconvenienced. If some random idiot posts a link to a Nigerian scam on your blog, you just delete it and get on with your life.