Live data from Hacker News

Thoughts on the Posterous hack

blog.dustincurtis.com

31–40 of 62 posts

Re: Thoughts on the Posterous hack

#32

Posterous actually has a nasty security hole which allows you to get the email address for any posterous which the user has not claimed. Here's a posterous I just created: http://john-tfk88.posterous.com/ that I have not claimed. The 'Claim this site' link goes to http://posterous.com/main/register?hash=Bu5fX3lRT2rYPURl7axZ... If you view source that you'll find that my email address is 'hidden' in the page: So, for…

Yikes. One of the top hits is for (what appears to be) Jamie Cullum's posterous. Can't tell if it's actually his or just a fan site. But your trick doesn't seem to work for it.

http://en.wikipedia.org/wiki/Jamie_Cullum

Re: Thoughts on the Posterous hack

#33
I see this argument all the time. "Oh, Joe Schmo won't know how to do this! It'll frighten them!".

And this happens absolutely everywhere. And it's true. But this problem won't go away until we start FORCING people to adapt, by adopting stricter measures everywhere.

Re: Thoughts on the Posterous hack

#34
post #28
post #9

He says there is no interest to post to his moms posterous, but is that really true? I can imagine quite a lot of spammers who would love to have a blog-post on an otherwise reputable blog. If spammers manage to abuse this system they could get their blogposts, filled with links and instructions to buy medication, all over all posterous blogs.

I remember reading somewhere about the abysmal conversion rates that spammers get (it was something like 1 in 12 million or something like that). So, you'd need some 12 million blog posts that look real enough to fool a user's reader to get one conversion. And it's not like Posterous isn't aware of the insecure nature of email. As some have suggested, they can just turn on pre-approval of submissions and this whole t…

Regarding conversion rates, people have been trained to distrust email, but the same isn't necessarily true for blogs. If a spammer put together a well-worded "spam" message — especially if it's something people write about all of the time, like electronics, music or book reviews, etc. — it's not unreasonable to expect conversion rates would be much higher.

Re: Thoughts on the Posterous hack

#35
post #16
post #14

"As a user, I fully accept it. http://blog.dustincurtis.com has received almost a million pageviews in the past year, and this is the first time this has ever happened. And It happened because I provoked it in an extremely popular article was posted to a community of hackers. To be honest, I expected someone to try this." as an EDUCATED user YOU accept it, i'm not sure most of the posterous users understand and would…

If someone steals your car, you're out many thousands of dollars and extremely inconvenienced. If some random idiot posts a link to a Nigerian scam on your blog, you just delete it and get on with your life.

Assuming that there's a trust being built between users, far more dangerous results can happen than 'nigerian scam' posts.

That's the problem with minimizing security: you're making it so that there can't (or shouldn't) be trust between users because there's no reliable way to know who is making the post.

"Hey, just a quick note to let you know I tried and I love it! Grab it now!"

Or, more dangerously, someone could post a phishing link and because the context is different, people's trained safeguards ("BE WARY OF E-MAIL!") aren't as wary to blog links.

So yes, there are sometimes tradeoffs between security and ease of use. But I think trust is more important to posterous than you credit.

Re: Thoughts on the Posterous hack

#36
post #28
post #9

He says there is no interest to post to his moms posterous, but is that really true? I can imagine quite a lot of spammers who would love to have a blog-post on an otherwise reputable blog. If spammers manage to abuse this system they could get their blogposts, filled with links and instructions to buy medication, all over all posterous blogs.

I remember reading somewhere about the abysmal conversion rates that spammers get (it was something like 1 in 12 million or something like that). So, you'd need some 12 million blog posts that look real enough to fool a user's reader to get one conversion. And it's not like Posterous isn't aware of the insecure nature of email. As some have suggested, they can just turn on pre-approval of submissions and this whole t…

NB, scam != spam.

E-mail spammers might need to send out millions of messages to get a conversion, but a more carefully crafted scam on a popular blog might be profitable with significantly less views.

Re: Thoughts on the Posterous hack

#37
I care about my reputation, therefore I would not use Posterous.

There's nothing stopping Posterous keeping it working exactly the same way, but providing an additional layer of protection for users who want to lock down their blog.

1.) Don't publish emails unless they passed DKIM

2.) Don't publish emails unless they passed SPF

3.) Don't publish emails unless they contain a secret password

4.) Don't publish emails unless they're signed with my PGP key.

Any of the above would be enough. It's all about choice.

Re: Thoughts on the Posterous hack

#38
An interesting thing posterous could to is send the user a (daily? weekly?) email "reminding" him of the blog, and making it so that just replies to that email count as posts. This lets them even change the GUID for each user if they think it has been compromised.

Re: Thoughts on the Posterous hack

#39

I care about my reputation, therefore I would not use Posterous. There's nothing stopping Posterous keeping it working exactly the same way, but providing an additional layer of protection for users who want to lock down their blog. 1.) Don't publish emails unless they passed DKIM 2.) Don't publish emails unless they passed SPF 3.) Don't publish emails unless they contain a secret password 4.) Don't publish emails un…

We do a mix of these things. In this specific case, it failed. We're investigating.

Re: Thoughts on the Posterous hack

#40
post #16
post #14

"As a user, I fully accept it. http://blog.dustincurtis.com has received almost a million pageviews in the past year, and this is the first time this has ever happened. And It happened because I provoked it in an extremely popular article was posted to a community of hackers. To be honest, I expected someone to try this." as an EDUCATED user YOU accept it, i'm not sure most of the posterous users understand and would…

If someone steals your car, you're out many thousands of dollars and extremely inconvenienced. If some random idiot posts a link to a Nigerian scam on your blog, you just delete it and get on with your life.

Actually, since the internet never forgets, a hacked blog might cause much more severe damage than a stolen car. There are also other sorts of crimes besides Nigerian scams.
Post reply on HN