Live data from Hacker News

You don’t need a password. Posterous fail.

blog.dustincurtis.com

61–70 of 84 posts

Re: You don’t need a password. Posterous fail.

#61
post #30

While we're talking about Posterous, does anyone know why it adds a random number to the end of article URLs, as in http://blog.dustincurtis.com/apparently-765 ? I know it's not a big deal, but I find that aesthetically unpleasing, as it kind of ruins an otherwise beautiful URL.

It is a namespace thing. I am pretty sure. When I use a title for my posterous posts that no one ever used before, the permalink is just the title. When I for example post something titled generally like "photo" it becomes "photo-73864"

Re: You don’t need a password. Posterous fail.

#62
post #37

Earlier quoted context omitted.

Shouldn't it work oppositely? Prevent the post from appearing until you explicitly approve it from a link in an email.

Sort of defeats the purpose of Posterous though. It's nice to be able to send an email and be done with it. Though for an account coming under constant attack, it'd be nice to have the option though. Edit: What they should really do is obfuscate the posting email addresses a little. Make my posting email 1234randomwords@posterous.com, and give me the option to change it to something else if I am coming under attack.

I don't think it defeats the purpose, so to speak, since it's verified by another email. You never have to leave your email client.

It's certainly and extra step that takes away from the smooth flowing process already set in place, though.

Re: You don’t need a password. Posterous fail.

#64
post #41

Earlier quoted context omitted.

I guess nobody believed you, because it sounds so ridiculous. Do you have an idea why Google imposes that rule?

I'm not sure it's true. Do a quick search on Google news and click some links -- there are plenty of results that don't have numbers in the url.

From http://www.google.com/support/news_pub/bin/answer.py?answer=...

this rule is waived with News sitemaps.

Re: You don’t need a password. Posterous fail.

#65
post #58

Earlier quoted context omitted.

But most major domains use domain keys / DKIM. http://en.wikipedia.org/wiki/DKIM As far as I understand it, you can't fake being an SMTP server sending mail from such a domain because their emails get signed with a private key whose matching public key is published by DNS.

There are several ways to defeat DKIM here: • If you can break DNS, you can get an NXDOMAIN reply, making recipients think there aren't any domainkeys • If the domainkey private key is small, you can factor it. There's an article on HN's frontpage right now about this. • If the server uses domainkeys, but it doesn't specifically verify the From: header, an attacker can still forge a message if they share a popular ma…

An auto-response confirmation would make posterous suck.

Re: You don’t need a password. Posterous fail.

#66

I did it. Sorry Dustin. It really was me. I changed one field in outlook. I realise Posterous requires you to "confirm" the post, I just wanted to see if you had defaulted that requirement to off.

You realize you broke the law and admitted to it.

Re: You don’t need a password. Posterous fail.

#67
post #26

Posterous really does fail here. I can see why they would want to tolerate a little of this to preserve ease of use for their users (just like Amazon with their Kindle email address). However, there are a number of steps that Posterous can take to combat forged headers in ways that should not impact users at all. Enabling SPF, for example, would be a good start. Technically, it's the same problem as email spam, and m…

> The other fix would be to use an email address that can't be guessed from the blog address. In other words, the email address is the password.

Multiply (http://multiply.com) does something similar. You set your post-by-email id. And, then email your posts to the post-by-email-id@your-multiply-id.multiply.com. You decide how complicated or easy you want your post-by-email-id to be.

As someone said, this is not 100% secure as the email address is sent as clear text as it passes through mail servers, but it's more difficult for someone to guess it.

They do perform additional checks on the message sent to make sure it came from you, perhaps similar to those that Posterous does.

Re: You don’t need a password. Posterous fail.

#68

I did it. Sorry Dustin. It really was me. I changed one field in outlook. I realise Posterous requires you to "confirm" the post, I just wanted to see if you had defaulted that requirement to off.

You realize you broke the law and admitted to it.

Honest question, what law was broken here?

Re: You don’t need a password. Posterous fail.

#69
post #61
post #30

While we're talking about Posterous, does anyone know why it adds a random number to the end of article URLs, as in http://blog.dustincurtis.com/apparently-765 ? I know it's not a big deal, but I find that aesthetically unpleasing, as it kind of ruins an otherwise beautiful URL.

It is a namespace thing. I am pretty sure. When I use a title for my posterous posts that no one ever used before, the permalink is just the title. When I for example post something titled generally like "photo" it becomes "photo-73864"

So all post URLs share a single global namespace, regardless of ownership? That's not a very clever design IMO.

Re: You don’t need a password. Posterous fail.

#70
post #59

Sure active users will notice spam posts but what about the long tail of customers who no longer update their Posterous blog? What happens when a 'creative' link marketer finds a way to index those sites and inject posts?

Running a spam filter on posts should work well.

I'd almost be more concerned with essentially getting DDOS'd with spam traffic to the posting address.
Post reply on HN