Live data from Hacker News

How I "hacked" Dustin Curtis's Posterous.

news.ycombinator.com

61–70 of 123 posts

Re: How I "hacked" Dustin Curtis's Posterous.

#61
post #2

I agree with the conclusion. Posterous could fix this problem by implementing something like The Zucchini Method ( http://www.jgc.org/antispam/03152005-2150120647b00f4af9d3443... [PDF]). Basically, they could accept posts via email as long as the user included some hard to guess word (or other token) in the subject line.

The subject line is the title of the the post at Posterous... though I suppose the could strip it out... i.e. "subj: Blog Post Title Goes here #sekretpassword".

Certainly not ideal. Typos would confuse matters and the idea of secret word authentication is not exactly common/obvious for the masses.

Re: How I "hacked" Dustin Curtis's Posterous.

#62
post #49
post #46

Earlier quoted context omitted.

> What's different between the way they did it and the way you did it? he was successful. seriously, though, the difference probably is that you put more time and effort into creating a posterous that was more secure. something as simple as "create it using a difficult email address" should cover most bases. something that most people likely don't do.

I put zero time into it. I created a brand new Posterous account, left everything as the default and posted the email address tied to the account here.

I believe the default requires authorizing your posts. That may be the issue.

Re: How I "hacked" Dustin Curtis's Posterous.

#63

Earlier quoted context omitted.

Well, he's knowingly misrepresenting himself. He's sending email as Dustin, with the specific intent of gaining unauthorized access to a system. (and he knows he's not authorized to post on Dustin's posterous)

That much is obvious, but what would cause the FBI to get involved and what would he be charged with?

jcromartie's premise was, "If Dustin were a major corporation or a politician..."

IANAL, and it's not exactly the same circumstances, but when Sarah Palin's e-mail was hacked during the 2008 U.S. presidential campaign, the FBI and Secret Service both "got involved". According to Wikipedia the hacker in question was eventually found guilty of (1) felony obstruction of justice by destruction of records and (2) misdemeanor unauthorized access to a computer.

http://en.wikipedia.org/wiki/Sarah_Palin_email_hack

Re: How I "hacked" Dustin Curtis's Posterous.

#64

Earlier quoted context omitted.

Such considerations might be overkill for flickr/posterous but that does leave your "secret" email address in the logs of every smtp relay along the way. Its sort of equivalent to putting a password in a URL.

Yeah, we're not talking about credit card info. Why not have post@ plus a secret@ available in your options. The more technically inclined could easily use the second, most likely safe enough, system. I really hope they don't complicate an otherwise zen-like experience.

Security shouldn't be optional.

And this wouldn't fix the issue at all... I bet that 80%+ of users would leave the default post@ submission address.

Re: How I "hacked" Dustin Curtis's Posterous.

#66

Earlier quoted context omitted.

Well, he's knowingly misrepresenting himself. He's sending email as Dustin, with the specific intent of gaining unauthorized access to a system. (and he knows he's not authorized to post on Dustin's posterous)

That much is obvious, but what would cause the FBI to get involved and what would he be charged with?

Examples: The hackers that sent sequential iPad device numbers to AT&T servers and got email addresses back. The hacker that guesses Sarah Palin's password.

Re: How I "hacked" Dustin Curtis's Posterous.

#67

Earlier quoted context omitted.

Yeah, we're not talking about credit card info. Why not have post@ plus a secret@ available in your options. The more technically inclined could easily use the second, most likely safe enough, system. I really hope they don't complicate an otherwise zen-like experience.

Security shouldn't be optional. And this wouldn't fix the issue at all... I bet that 80%+ of users would leave the default post@ submission address.

Security shouldn't be optional.

That seems like a very dogmatic attitude. Security almost always comes at some cost (e.g., inconvenience), and sometimes that cost is not worth the benefit.

Re: How I "hacked" Dustin Curtis's Posterous.

#69
post #57

Earlier quoted context omitted.

SPF only identifies the sending domain, not the sender himself. If your address is gmail and my address is gmail, our mx domain has the same spf record and same IPs. Sure, some mail servers will prevent you from authenticating with one ID and sending as another, but many others will let that slide.

Yes, but that's a fault of the mailserver on that domain. It shouldn't allow spoofed email to be sent from its own domain.

Sounds like a good partial solution to me. If SPF traces it back to a mail server that doesn't allow spoofed email, it could skip the confirmation step. GMail lets people change the from field, but only to an email address they can show they have access to, by clicking a confirmation link.

Re: How I "hacked" Dustin Curtis's Posterous.

#70
post #25
post #18

Earlier quoted context omitted.

[deleted]

How embarrassing for you. How exactly would the email go to the forger if they are spoofing YOUR email address. Coffee in the morning, gin at night. Never switch the two.

I like that better than "What are you smoking?" Still overly rude, though.
Post reply on HN