Live data from Hacker News

Thoughts on the Posterous hack

blog.dustincurtis.com

41–50 of 62 posts

Re: Thoughts on the Posterous hack

#41
post #25
post #16

Earlier quoted context omitted.

If someone steals your car, you're out many thousands of dollars and extremely inconvenienced. If some random idiot posts a link to a Nigerian scam on your blog, you just delete it and get on with your life.

maybe to you it doesn't matter, but these things can be intensely personal to people. it's still an issue of violating your space (to the layman end user, i know the technical definitions of "your space" are nebulous, im talking about the emotional ones that i think posterous is kind of violating). and what happens when the idiot who posts the nigerian scam on your blog scams your mother who is reading your blog and…

Appreciate the concern, and we hear you. We're still investigating this particular case. Normally we'll catch these types of spoofed emails. What we need to do is refine our system.

To be honest, we haven't had many complaints about spam emails or spoofs -- it literally never happens, otherwise we would hear about it all the time. We answer every help email we get -- so we have a decent idea of what our users care about and what pains they really see.

If trust is an issue, we will fix it.

Re: Thoughts on the Posterous hack

#42
post #11

Earlier quoted context omitted.

Ah yes, the sole exception to this security sacrifice is spammers. You have to keep them out, no matter the cost. Posterous does a good job of keeping them out, I think, because I've never seen a spam post.

This seems mostly security by obscurity. If spammers already have a list of "valid" email addresses, how long before they start randomly hitting post@postereous.com with spoofed headers on a regular basis?

That's a war we will fight when we have to. And we will fight it with relish and aplomb.

Re: Thoughts on the Posterous hack

#43

I care about my reputation, therefore I would not use Posterous. There's nothing stopping Posterous keeping it working exactly the same way, but providing an additional layer of protection for users who want to lock down their blog. 1.) Don't publish emails unless they passed DKIM 2.) Don't publish emails unless they passed SPF 3.) Don't publish emails unless they contain a secret password 4.) Don't publish emails un…

We do a mix of these things. In this specific case, it failed. We're investigating.

Cool. Would it be possible for me as a user to specify that only PGP signed emails should be auto-posted, and everything else should be subject to a confirmation email?

That would be the ideal scenario for me personally...

Re: Thoughts on the Posterous hack

#44
post #36
post #28

Earlier quoted context omitted.

I remember reading somewhere about the abysmal conversion rates that spammers get (it was something like 1 in 12 million or something like that). So, you'd need some 12 million blog posts that look real enough to fool a user's reader to get one conversion. And it's not like Posterous isn't aware of the insecure nature of email. As some have suggested, they can just turn on pre-approval of submissions and this whole t…

NB, scam != spam. E-mail spammers might need to send out millions of messages to get a conversion, but a more carefully crafted scam on a popular blog might be profitable with significantly less views.

How's it easier to make 12 million carefully crafted scams without raising anyone's suspicion that the posts aren't legitimate? I could see the scam working on a Viagra blog, but how is it useful to anyone to have copies of what clearly look like a fishy post all over the place, possibly followed up by the real authors calling you out and telling people NOT to buy from you?

Besides, if you're scamming, why not just create a free blog? There are tons of get-rich-quick schemes out there doing just that...

Re: Thoughts on the Posterous hack

#45

Posterous actually has a nasty security hole which allows you to get the email address for any posterous which the user has not claimed. Here's a posterous I just created: http://john-tfk88.posterous.com/ that I have not claimed. The 'Claim this site' link goes to http://posterous.com/main/register?hash=Bu5fX3lRT2rYPURl7axZ... If you view source that you'll find that my email address is 'hidden' in the page: So, for…

We're investigating this. We'll update asap.

Re: Thoughts on the Posterous hack

#46

I think his argument comes off as too utopian for me to accept. Like everyone else has said, of course people will want to exploit an easy loophole on someone who has a bit of exposure. I think Posterous hasn't grown to a point where they have to worry about it yet, but look at the exploits on Wordpress. They're much more advanced and hackers continually attempt to break in for fun or for abusive reasons. It's naive…

That's the thing -- it's not an "easy" loophole. Like any arms race, every website is in competition with its foils -- scammers, phishers, spammers and their ilk.

I disagree that it's not possible to stay ahead of them. That's our job.

Re: Thoughts on the Posterous hack

#47
post #15

Simple. Create an email alias (spacemuffinftw) just for Posterous and post with that, making it your password in a way. Edit : Seen in other comments -- cool thing would be for Posterous to support SPF . Definitely techie oriented and not for general folks, but in a system like Posterous, it should be baked in from day one. It would protect quite a bit of folks while majority of them not even realizing or even knowin…

SPF is already baked in. You can't set up an email account without understanding the ins and outs of that stuff. It is one part of an arsenal.

Re: Thoughts on the Posterous hack

#48

Earlier quoted context omitted.

We do a mix of these things. In this specific case, it failed. We're investigating.

Cool. Would it be possible for me as a user to specify that only PGP signed emails should be auto-posted, and everything else should be subject to a confirmation email? That would be the ideal scenario for me personally...

That's a good idea. What I want is some end-user-friendly PGP-like solution. If it existed in a form that we knew millions of users already were used to using, or that we could roll out -- we would do it in a heartbeat.

Have to think about normals on it though. It's not good enough to think about tech savvy people like us.

But for those who care, it might be the best way. Thanks.

Re: Thoughts on the Posterous hack

#49
post #28

Earlier quoted context omitted.

I remember reading somewhere about the abysmal conversion rates that spammers get (it was something like 1 in 12 million or something like that). So, you'd need some 12 million blog posts that look real enough to fool a user's reader to get one conversion. And it's not like Posterous isn't aware of the insecure nature of email. As some have suggested, they can just turn on pre-approval of submissions and this whole t…

Regarding conversion rates, people have been trained to distrust email, but the same isn't necessarily true for blogs. If a spammer put together a well-worded "spam" message — especially if it's something people write about all of the time, like electronics, music or book reviews, etc. — it's not unreasonable to expect conversion rates would be much higher.

FWIW, anyone who hangs around blogs knows a spam comment when they see one. I'd imagine that it's even harder to make a fake blog post believable, since it's easier to wing something like: "yeah I agree [link to fishy site]" than it is to make a well-written post (especially if it needs to be generic enough to pass as legitimate in 12 million different blogs...)

Re: Thoughts on the Posterous hack

#50
post #27

Earlier quoted context omitted.

or both... assign a random GUID, and then allow the user to set it something they want if they choose. That's probably the simplest way, and of course the simpler the better for both development and security.

Surely the easiest way would be to require you put your password somewhere in the body of the email. eg: Hi this is an example blog post I'm gonna see if this works ys8uc99p

I think that putting a password inside the post field (the email body) could lead to some issues. :)
Post reply on HN