Earlier quoted context omitted.
What would the crime be?
Well, he's knowingly misrepresenting himself. He's sending email as Dustin, with the specific intent of gaining unauthorized access to a system. (and he knows he's not authorized to post on Dustin's posterous)
How I "hacked" Dustin Curtis's Posterous.
51–60 of 123 posts
Re: How I "hacked" Dustin Curtis's Posterous.
#52I agree with the conclusion. Posterous could fix this problem by implementing something like The Zucchini Method ( http://www.jgc.org/antispam/03152005-2150120647b00f4af9d3443... [PDF]). Basically, they could accept posts via email as long as the user included some hard to guess word (or other token) in the subject line.
They should just use SPF. This is what SPF is designed for, and it allows them to keep the user experience simple and straightforward. No weird passphrase to enter into the email, no weird random email address to email to, etc.
If your address is gmail and my address is gmail, our mx domain has the same spf record and same IPs. Sure, some mail servers will prevent you from authenticating with one ID and sending as another, but many others will let that slide.
Re: How I "hacked" Dustin Curtis's Posterous.
#53I agree with the conclusion. Posterous could fix this problem by implementing something like The Zucchini Method ( http://www.jgc.org/antispam/03152005-2150120647b00f4af9d3443... [PDF]). Basically, they could accept posts via email as long as the user included some hard to guess word (or other token) in the subject line.
or do what flickr does and give you a unique email address to send to that only you will know. you can add it to your address book so you won't have to remember it, and it's probably stronger than what most users would choose for a password.
Re: How I "hacked" Dustin Curtis's Posterous.
#54I agree with the conclusion. Posterous could fix this problem by implementing something like The Zucchini Method ( http://www.jgc.org/antispam/03152005-2150120647b00f4af9d3443... [PDF]). Basically, they could accept posts via email as long as the user included some hard to guess word (or other token) in the subject line.
or do what flickr does and give you a unique email address to send to that only you will know. you can add it to your address book so you won't have to remember it, and it's probably stronger than what most users would choose for a password.
Re: How I "hacked" Dustin Curtis's Posterous.
#55I agree with the conclusion. Posterous could fix this problem by implementing something like The Zucchini Method ( http://www.jgc.org/antispam/03152005-2150120647b00f4af9d3443... [PDF]). Basically, they could accept posts via email as long as the user included some hard to guess word (or other token) in the subject line.
or do what flickr does and give you a unique email address to send to that only you will know. you can add it to your address book so you won't have to remember it, and it's probably stronger than what most users would choose for a password.
Re: How I "hacked" Dustin Curtis's Posterous.
#56Earlier quoted context omitted.
Well, he's knowingly misrepresenting himself. He's sending email as Dustin, with the specific intent of gaining unauthorized access to a system. (and he knows he's not authorized to post on Dustin's posterous)
That much is obvious, but what would cause the FBI to get involved and what would he be charged with?
Re: How I "hacked" Dustin Curtis's Posterous.
#57Earlier quoted context omitted.
They should just use SPF. This is what SPF is designed for, and it allows them to keep the user experience simple and straightforward. No weird passphrase to enter into the email, no weird random email address to email to, etc.
SPF only identifies the sending domain, not the sender himself. If your address is gmail and my address is gmail, our mx domain has the same spf record and same IPs. Sure, some mail servers will prevent you from authenticating with one ID and sending as another, but many others will let that slide.
Re: How I "hacked" Dustin Curtis's Posterous.
#58Earlier quoted context omitted.
or do what flickr does and give you a unique email address to send to that only you will know. you can add it to your address book so you won't have to remember it, and it's probably stronger than what most users would choose for a password.
Such considerations might be overkill for flickr/posterous but that does leave your "secret" email address in the logs of every smtp relay along the way. Its sort of equivalent to putting a password in a URL.
I really hope they don't complicate an otherwise zen-like experience.
Re: How I "hacked" Dustin Curtis's Posterous.
#59Earlier quoted context omitted.
True, but opening an unlocked door is hardly breaking into a house, yet you'd still get in trouble for it.
Locked or not it's still trespass, which is illegal, in most places.
Re: How I "hacked" Dustin Curtis's Posterous.
#60Earlier quoted context omitted.
> What's different between the way they did it and the way you did it? he was successful. seriously, though, the difference probably is that you put more time and effort into creating a posterous that was more secure. something as simple as "create it using a difficult email address" should cover most bases. something that most people likely don't do.
I put zero time into it. I created a brand new Posterous account, left everything as the default and posted the email address tied to the account here.