The real danger here isn't spam, it's false flag attacks. If something offensive appears on your posterous under your name, will anyone believe you when you claim it's a hack? On the other hand, maybe it provides a convenient excuse if you post something dumb and want to disown it . . .
Thoughts on the Posterous hack
51–60 of 62 posts
Re: Thoughts on the Posterous hack
#52Here's the deal - as soon as your blog reaches any level of popularity, people are going to want to deface it / hack it any way they can just because it's that much bigger of a prize. If Posterous is this easy to hack, once you have a decent sized blog you're going to have a constant field day until they implement something better. If you want to keep security simple enough that it doesn't strangle the service then h…
Apparently not, because his blog had "any level of popularity" long before it was hacked. Since this is the first I've ever heard of a Posterous hack, clearly it's not true that all decent sized blogs are being hacked constantly. On the surface, what you say makes sense, but the real life data doesn't back it up. Compare to: http://www.schneier.com/blog/archives/2010/05/why_arent_ther...
Re: Thoughts on the Posterous hack
#53Posterous actually has a nasty security hole which allows you to get the email address for any posterous which the user has not claimed. Here's a posterous I just created: http://john-tfk88.posterous.com/ that I have not claimed. The 'Claim this site' link goes to http://posterous.com/main/register?hash=Bu5fX3lRT2rYPURl7axZ... If you view source that you'll find that my email address is 'hidden' in the page: So, for…
Yikes. One of the top hits is for (what appears to be) Jamie Cullum's posterous. Can't tell if it's actually his or just a fan site. But your trick doesn't seem to work for it. http://en.wikipedia.org/wiki/Jamie_Cullum
Re: Thoughts on the Posterous hack
#54"As a user, I fully accept it. http://blog.dustincurtis.com has received almost a million pageviews in the past year, and this is the first time this has ever happened. And It happened because I provoked it in an extremely popular article was posted to a community of hackers. To be honest, I expected someone to try this." as an EDUCATED user YOU accept it, i'm not sure most of the posterous users understand and would…
Further, I think if you made the downsides of everything abundantly clear to people then they would just be really scared. Everything, including posting to hackernews, has horrific potential consequences. But generally as long as bad things don't happen, people don't pay much attention to them. Where there's no smoke, there's no fire.
Re: Thoughts on the Posterous hack
#55Simple. Create an email alias (spacemuffinftw) just for Posterous and post with that, making it your password in a way. Edit : Seen in other comments -- cool thing would be for Posterous to support SPF . Definitely techie oriented and not for general folks, but in a system like Posterous, it should be baked in from day one. It would protect quite a bit of folks while majority of them not even realizing or even knowin…
SPF is already baked in. You can't set up an email account without understanding the ins and outs of that stuff. It is one part of an arsenal.
Re: Thoughts on the Posterous hack
#56Posterous actually has a nasty security hole which allows you to get the email address for any posterous which the user has not claimed. Here's a posterous I just created: http://john-tfk88.posterous.com/ that I have not claimed. The 'Claim this site' link goes to http://posterous.com/main/register?hash=Bu5fX3lRT2rYPURl7axZ... If you view source that you'll find that my email address is 'hidden' in the page: So, for…
We have looked into this issue and have confirmed this is not a security hole. No personal information is revealed to users other than through obscure links that are only available to the true site owner.
This url is only available:
1. In the emails we send to users to claim their site. So only the true owner receives these 2. On the Posterous site itself but only when we know it's the site owner (based on cookies and other tests)
That Google search does include a bunch of unclaimed sites. However, none of those sites will include the secret hash, and therefore none will expose the email address.
The fact that we include the email address in the form is definitely odd, and we're removing that now. But nonetheless, it's only visible to the person who created that site, behind obscure URLs.
We're very confident in the system we have built. While making things super simple for the common user, we never forget that our users care a lot about keeping their information secure.
Thanks for bringing this to our attention. We always need to be one step ahead of the hackers/spoofers, and we thank the Hacker News community for keeping us on our toes!
Re: Thoughts on the Posterous hack
#57Yes, someone did figure out how to post to Dustin's site today. This security hole is now fixed.
We had a specific problem with the way we dealt with SPF records. Dustin didn't set any up, and there was a specific way that Robin Duckett's email server responded that caused us to flag it as a false negative for spoofing.
For the vast majority of users who use gmail, hotmail or other services, this was never an issue.
Since our launch on day one, we have taken email spoof detection very seriously. It's one of our core differentiators: to be able to securely post to your blog by emailing a single, easy to remember address. We don't want to do secret addresses or secret words.
Over the past 2 years, we've developed robust spoof detection ip and spend a ton of time trying to stay a step ahead of hackers. Fortunately, we've only had a few very specific, isolated cases where one of our sites was spoofed and each time we have improved our system.
Thanks for bringing this to our attention. We always need to be one step ahead of the hackers/spoofers, and we thank the Hacker News community for keeping us on our toes!
Re: Thoughts on the Posterous hack
#58Posterous actually has a nasty security hole which allows you to get the email address for any posterous which the user has not claimed. Here's a posterous I just created: http://john-tfk88.posterous.com/ that I have not claimed. The 'Claim this site' link goes to http://posterous.com/main/register?hash=Bu5fX3lRT2rYPURl7axZ... If you view source that you'll find that my email address is 'hidden' in the page: So, for…
Hey guys. I'm the cofounder of Posterous. We have looked into this issue and have confirmed this is not a security hole. No personal information is revealed to users other than through obscure links that are only available to the true site owner. This url is only available: 1. In the emails we send to users to claim their site. So only the true owner receives these 2. On the Posterous site itself but only when we kno…
I'll leave my original post intact as an example of what happens when you get 3 hours sleep and then shoot your mouth off.
Re: Thoughts on the Posterous hack
#591) Why can I not comment on the actual post? That's a little disconcerting. 2) I don't understand the need to post by e-mail. What does that gain me? Is there any use in that other than gimmick? Wouldn't a nice site offer me more chances for formatting, etc? What is the difference between typing info into a site and into an e-mail? What is the benefit? Can't a site be easier to use than e-mail? 3) Security is not a c…
Re: Thoughts on the Posterous hack
#60Earlier quoted context omitted.
maybe to you it doesn't matter, but these things can be intensely personal to people. it's still an issue of violating your space (to the layman end user, i know the technical definitions of "your space" are nebulous, im talking about the emotional ones that i think posterous is kind of violating). and what happens when the idiot who posts the nigerian scam on your blog scams your mother who is reading your blog and…
Appreciate the concern, and we hear you. We're still investigating this particular case. Normally we'll catch these types of spoofed emails. What we need to do is refine our system. To be honest, we haven't had many complaints about spam emails or spoofs -- it literally never happens, otherwise we would hear about it all the time. We answer every help email we get -- so we have a decent idea of what our users care ab…
Because you're below most people's radar. Compared to blogger or anything similar, you barely measure.
So essentially you are practicing security through obscurity.
Of course we know that is foolhardy.