Just for the record, I meant it sincerely when I said that we were grateful that Ben Newman and Albert Sheu showed us an XSS hole in Qato, and that has now been fixed. The site in question was just an unpromoted testing prototype which barely has any content and happened to have the Quora-like skin on at that moment. It probably shouldn't even have been publicly accessible. Another Qato site on the same server is htt…
Just a quick note - these "assurances" that the Quora-like skin was just a prototype doesn't do anything to allay my suspicions that the xss vulnerability is probably a core issue with the "general purpose Q&A engine" underneath it. If you're relying on the "skin" to enforce xss security, you don't really understand the importance of the various bits of MVC.
Quora engineers accused of vandalizing a clone’s website
41–50 of 59 posts
Re: Quora engineers accused of vandalizing a clone’s website
#42Same thing happened in my friend's company and they fired the engineer who identified and exploited the permanent XSS in their competitor's website. Personally I would do the very same thing. 1. It's against the law 2. Extremely unprofessional and childish 3. There are better ways to report security vulnerabilities
Re: Quora engineers accused of vandalizing a clone’s website
#43[edit: Troll answers have been deleted, but you can still read the trolling comment thread: http://www.quora.com/Is-Qato-a-serious-Quora-clone-attempt/a... and http://www.quora.com/Is-Qato-a-serious-Quora-clone-attempt/a... ] On the Quora thread, http://www.quora.com/Is-Qato-a-Quora-clone-attempt-or-a-simi... there are some answers by trolls pretending to represent Qato. "Sameul Codsaw" writes: 'Also, we are using Ru…
Quora has a lot of passionate users.
"Quora has a lot of trolls" FTFY
with that kind of comment. Impersonation is crap and childish behavio(u)r and not about being "passionate" about a site or a technology.
I don't think Quora guys are to blame, but
- These comments should be moderated/removed/shouldn't have been allowed in the first place
- Calling idiots that do things like that "passionate users" does both the service and the internet in general a disservice. They are idiots. Period. That's not funny, that's not cool or helpful. Your reply seems kind of supportive and I don't get why.
Re: Quora engineers accused of vandalizing a clone’s website
#44Earlier quoted context omitted.
Quora has a lot of passionate users.
I'm curious why, does anybody know? After looking at Stackoverflow I considered technical Q&A a solved problem, and it seems to translate well to other topics.
Re: Quora engineers accused of vandalizing a clone’s website
#45Everyone's right that it was an ill-advised thing to do, but stepping back ignoring the law (I know..) and just asking yourself the gut question: What's worse? injecting a relatively harmless script into the product (that frankly caused them to fix an issue that could have been very painful for them if someone more devious had found it first), or Qato's ripoff of Quora in the first place?
For what it's worth, my takeaway on this is not that Qato "ripped off Quora", to me its quite clear they're building an engine for Q&A websites, and they've used Quroa (and Stackoverflow) as examples of what you can build with it. Not so much "ripping off" - I see it more like the sort of Photoshop demo where a guy on stage recreates some well known image to show off Photoshop as a tool. The problem is, their tool ha…
[Edit: I already feel kind of bad about this comment. I love me some 3$ multi-meters. Still. Analogy stands.]
Re: Quora engineers accused of vandalizing a clone’s website
#46Earlier quoted context omitted.
Just a quick note - these "assurances" that the Quora-like skin was just a prototype doesn't do anything to allay my suspicions that the xss vulnerability is probably a core issue with the "general purpose Q&A engine" underneath it. If you're relying on the "skin" to enforce xss security, you don't really understand the importance of the various bits of MVC.
I believe the skin and the XSS vulnerability were two separate issues. Even if the site had been using a different skin, the XSS vulnerability would have still existed.
I shouldn't be hearing "Oh, the Quora skin is just a prototype", I should be hearing something like "the dev site the Quora prototype skin was being developed on was running a 6 month old branch of our engine software, check out out github history to see all the security changes made in the "production ready" branch since November".
Re: Quora engineers accused of vandalizing a clone’s website
#47Earlier quoted context omitted.
Your chemistry class example is nonsensical. In class, if there is an opportunity to explore a few things and a mess is made, maybe you would not be blamed. That's usually not how labs are run--you follow a procedure and mixing chemicals with no forethought is a huge safety hazard to everybody in the lab. Neither the "real world" nor the Internet is a place with a mutual agreement between all participants to experime…
Maybe a better example would be going into your neighbor's backyard and testing how readily his shrubbery lights on fire. Oops, it's burning! Tell him to "fix the bug" and move on. No, a better example is going into your backyard, shining a flashlight onto your neighbor's shrubbery, and then having the neighbor complain to you about changing the shrubbery's color from black to green. The protocol for a shrub is: you…
If we're doing silly analogies, it's the equivalent of Starbucks sending their staff round to your new cafe with Groupons leaving no coffee or seats for the real customers and then publicly mocking your staff's incompetence in handling the situation. Sure, it's your fault for running the promotion and not buying enough coffee, but you might still consider BigCorp's behaviour a little underhand.
Re: Quora engineers accused of vandalizing a clone’s website
#48Earlier quoted context omitted.
If Qato is going to copy someone's design, can't they find something better than Quora ? I mean, Quora's design isn't going to win them any awards; it looks like Quora didn't even use Photoshop, just straight-up CSS.
Because they are unoriginal followers. If they had any sense of direction they'd be able to build something of their own.
There are simply too many people drawing from the historical experiences and examples laid by e.g. Metafilter, Digg, image boards, etc. for it to consititute individual acts of copying. That there are so many whitelabel apps & plugins ready for the implementing only accelerates this evolution.
Re: Quora engineers accused of vandalizing a clone’s website
#49Earlier quoted context omitted.
I believe the skin and the XSS vulnerability were two separate issues. Even if the site had been using a different skin, the XSS vulnerability would have still existed.
Precisely my point. I shouldn't be hearing "Oh, the Quora skin is just a prototype", I should be hearing something like "the dev site the Quora prototype skin was being developed on was running a 6 month old branch of our engine software, check out out github history to see all the security changes made in the "production ready" branch since November".
Re: Quora engineers accused of vandalizing a clone’s website
#50Earlier quoted context omitted.
If Qato is going to copy someone's design, can't they find something better than Quora ? I mean, Quora's design isn't going to win them any awards; it looks like Quora didn't even use Photoshop, just straight-up CSS.
It doesn't just look like they don't use photoshop. They "design in code". http://www.quora.com/Joel-Lewenstein/Life-Without-Photoshop