Live data from Hacker News

Quora engineers accused of vandalizing a clone’s website

greyreview.com

31–40 of 59 posts

Re: Quora engineers accused of vandalizing a clone’s website

#31
post #16

Vandalism is a stupid word to use. I imagine the process went something like this: "I wonder what happens if I add $.fadeOut() as the text of the question" "Oh crap, it worked". This is called experimentation. If you're in chemistry class and you mess up a lab, you're not accused of vandalizing apparatus... it's simply what happens when you are trying something out. Similarly, when you have a text box on a test websi…

Your chemistry class example is nonsensical. In class, if there is an opportunity to explore a few things and a mess is made, maybe you would not be blamed. That's usually not how labs are run--you follow a procedure and mixing chemicals with no forethought is a huge safety hazard to everybody in the lab. Neither the "real world" nor the Internet is a place with a mutual agreement between all participants to experime…

Maybe a better example would be going into your neighbor's backyard and testing how readily his shrubbery lights on fire. Oops, it's burning! Tell him to "fix the bug" and move on.

No, a better example is going into your backyard, shining a flashlight onto your neighbor's shrubbery, and then having the neighbor complain to you about changing the shrubbery's color from black to green.

The protocol for a shrub is: you shine light on it, it reflects light back. The protocol for a public web service is: you send it an HTTP request, it sends an HTTP response. If you don't want your neighbors to see your shrubbery, build a fence. If you don't want your website to contain arbitrary scripts, don't let users submit arbitrary scripts.

Re: Quora engineers accused of vandalizing a clone’s website

#32
post #18

Vandalism is a stupid word to use. I imagine the process went something like this: "I wonder what happens if I add $.fadeOut() as the text of the question" "Oh crap, it worked". This is called experimentation. If you're in chemistry class and you mess up a lab, you're not accused of vandalizing apparatus... it's simply what happens when you are trying something out. Similarly, when you have a text box on a test websi…

I disagree. 1. There are plenty of proof of concepts you can develop that don't destroy the page. 2. The Quora engineers in question didn't enter stuff into a textbox and leave it alone. They went and publicly disclosed a cross-site scripting vulnerability in a competitor's website. Edit: Ben deleted his "answer" which disclosed the XSS. However, the comments on the answer are still accessible (for now) if anyone is…

The "ethics" of "full disclosure" are a long-running subject, but many people agree that the technique is fine. Don't shoot the messenger.

Re: Quora engineers accused of vandalizing a clone’s website

#33

Just for the record, I meant it sincerely when I said that we were grateful that Ben Newman and Albert Sheu showed us an XSS hole in Qato, and that has now been fixed. The site in question was just an unpromoted testing prototype which barely has any content and happened to have the Quora-like skin on at that moment. It probably shouldn't even have been publicly accessible. Another Qato site on the same server is htt…

Did robofaqs have the same vulnerability? If so, that's a way bigger story than this brouhaha.

Re: Quora engineers accused of vandalizing a clone’s website

#34
post #22
post #13

I just left the following comment: -- It's pretty lame to copy the design and trade dress of another product. It does not bode well for your skill or ability. Backstory: A long time ago I wrote Delicious. We had hundreds of copycats and competitors. The ones that weren't direct copies were the ones that did better. I'm sure this doesn't apply to you for whatever reason.

If Qato is going to copy someone's design, can't they find something better than Quora ? I mean, Quora's design isn't going to win them any awards; it looks like Quora didn't even use Photoshop, just straight-up CSS.

It doesn't just look like they don't use photoshop.

They "design in code".

http://www.quora.com/Joel-Lewenstein/Life-Without-Photoshop

Re: Quora engineers accused of vandalizing a clone’s website

#35
post #25

Same thing happened in my friend's company and they fired the engineer who identified and exploited the permanent XSS in their competitor's website. Personally I would do the very same thing. 1. It's against the law 2. Extremely unprofessional and childish 3. There are better ways to report security vulnerabilities

I sincerely hope that's not what happens here. I would hate to see someone lose their job over what seems to have been a temporary lapse in judgement.

Temporary lapses in judgement are exactly what "fireable offenses" are designed to prevent. Bright lines for tolerable acts, especially in regards to outside resources, help everybody know how to stay on the good side of management.

By way of example, some years ago a story went around about HP support being prohibited from suggesting a user adjust their BIOS. This was back in the day when checking BIOS to see if hard drives, ports and RAM were being detected properly (say, Win98 era), but for HP it was a fireable offense. It may not have resulted in the death of any user's computer in any given instance, but the risk of problems was great enough that they couldn't allow support people to deviate from the troubleshooting matrix in this way.

In this case it seems more a problem of ethics than policy, and no doubt Quora is not very large of a company and does not yet have stringent policies like HP's, but to argue "no harm no foul" is to set a bad precedent at the peak of a slippery slope.

Re: Quora engineers accused of vandalizing a clone’s website

#36
post #28
post #22

Earlier quoted context omitted.

If Qato is going to copy someone's design, can't they find something better than Quora ? I mean, Quora's design isn't going to win them any awards; it looks like Quora didn't even use Photoshop, just straight-up CSS.

Because they are unoriginal followers. If they had any sense of direction they'd be able to build something of their own.

Ok. I know it's against the rules, but why is this getting voted down?

This comment comes from my experience (see above) rather than mere negative opinion.

Re: Quora engineers accused of vandalizing a clone’s website

#37
post #30

Earlier quoted context omitted.

FYI, underlined hyperlinks make it impossible to tell the difference between a "q" and a "g" in a URL. As such, I'd suggest you spend some time finding a better name for that unfortunately named site you linked.

So I take it you're not a fan of http://www.gamefaqs.com ? ;-)

Gamefaqs has a self-describing name that pertains to their main business (Game. FAQs.) Qato doesn't have the same thing going for it.

Re: Quora engineers accused of vandalizing a clone’s website

#38

Just for the record, I meant it sincerely when I said that we were grateful that Ben Newman and Albert Sheu showed us an XSS hole in Qato, and that has now been fixed. The site in question was just an unpromoted testing prototype which barely has any content and happened to have the Quora-like skin on at that moment. It probably shouldn't even have been publicly accessible. Another Qato site on the same server is htt…

Just a quick note - these "assurances" that the Quora-like skin was just a prototype doesn't do anything to allay my suspicions that the xss vulnerability is probably a core issue with the "general purpose Q&A engine" underneath it. If you're relying on the "skin" to enforce xss security, you don't really understand the importance of the various bits of MVC.

Re: Quora engineers accused of vandalizing a clone’s website

#39
post #12
post #9

[edit: Troll answers have been deleted, but you can still read the trolling comment thread: http://www.quora.com/Is-Qato-a-serious-Quora-clone-attempt/a... and http://www.quora.com/Is-Qato-a-serious-Quora-clone-attempt/a... ] On the Quora thread, http://www.quora.com/Is-Qato-a-Quora-clone-attempt-or-a-simi... there are some answers by trolls pretending to represent Qato. "Sameul Codsaw" writes: 'Also, we are using Ru…

Quora has a lot of passionate users.

I'm curious why, does anybody know? After looking at Stackoverflow I considered technical Q&A a solved problem, and it seems to translate well to other topics.

Re: Quora engineers accused of vandalizing a clone’s website

#40

Everyone's right that it was an ill-advised thing to do, but stepping back ignoring the law (I know..) and just asking yourself the gut question: What's worse? injecting a relatively harmless script into the product (that frankly caused them to fix an issue that could have been very painful for them if someone more devious had found it first), or Qato's ripoff of Quora in the first place?

For what it's worth, my takeaway on this is not that Qato "ripped off Quora", to me its quite clear they're building an engine for Q&A websites, and they've used Quroa (and Stackoverflow) as examples of what you can build with it. Not so much "ripping off" - I see it more like the sort of Photoshop demo where a guy on stage recreates some well known image to show off Photoshop as a tool.

The problem is, their tool has at least one xss vulnerability. I've been there myself, and usually a single xss vulnerability is an indication that the underlying design of the system didn't take xss (and probably web security in general) seriously enough. It's _possible_ this was just a single place where user supplied data sanitisation wasn't done correctly, but I'd bet good money that it's indicative of a development mindset that failed to be paranoid enough. I'll bet there's a bunch of places they're going to find exactly the same error, and won't be at all surprised to find SQL injection vulnerabilities, http header vulnerabilities, and any of a whole bunch of other "common web programming" errors. I'll be amazed if right now there aren't a bunch of people running fuzzers against any site suspected of having the Qato "engine" underneath it. I'll not be at all surprised to hear several of them get compromised before the weekend and start running dick-pill-seo spam...

Post reply on HN