Live data from Hacker News

Never Give Your Information To 10 Minute Old Startups

blog.ryankearney.com

61–70 of 185 posts

Re: Never Give Your Information To 10 Minute Old Startups

#61

I'm curious, did you let them know that this vulnerability exists before you wrote an article and posted it to HN? If you let them know and they ignored you, then I understand that you'd want to write an article and spread it around. It's important that customers know when a company doesn't value their security. At that point, the proper way for them to handle it is to quietly fix it, and then let all their affected…

Since you presented 2 possibilities here, neither of which are accurate, what is your response to the reality of the situation?

Re: Never Give Your Information To 10 Minute Old Startups

#62

10 minutes? Never give your information to a business that made a mistake like this, ever . That wasn't merely a "security vulnerability". It was also a demonstration that the people running the business have absolutely no idea what they are doing when it comes to security, privacy, or testing and release processes. (Actually, there is an alternative explanation, which is even worse: they knew and didn't care. I pref…

"Never give your information to a business that made a mistake like this, ever."

Fwiw back in 1996 or 97 the UPS website did the same thing. By altering the tracking number you could see somewhat complete information on someone else's shipment. Since the tracking numbers ran in sequence from the shippers log books giving one tracking number from a competitor you could see all their customers. (To get that all you had to do was place a single order so they shipped to you. Although I guess it wouldn't have been even easier to social engineer someone to simply give you any tracking number and save that step.)

Re: Never Give Your Information To 10 Minute Old Startups

#63

Earlier quoted context omitted.

And did you let them know privately before you posted this comment? http://news.ycombinator.com/item?id=4619411

Details of the vulnerability were not posted until it was patched, which was no more than 60 seconds after that initial post.

Given the severity of the hole, I am thankful that you posted what you did

Re: Never Give Your Information To 10 Minute Old Startups

#64

Earlier quoted context omitted.

You speak of "responsible disclosure", but what about "responsible launch"? If a backend is coded this poorly, it betrays irreparable and highly dangerous levels of idiocy, laziness, and lack of foresight in the ones who coded it. Everyone deserves to be informed of this blunder so they know to avoid this group like the plague. Public ridicule and preemptive destruction of the brand is the only conscionable reaction.

It sounds like it wasn't launched yet. The founders say they built it for themselves and their friends to start. Someone discovered the URL and posted it to Hacker News. They probably should have shut it down or disabled registrations once it got out until it was tested.

Friends are customers, too. One row in your database is a customer.

Before ever putting a service up on the public Internet (service defined here as "accepts arbitrary requests" and "delivers arbitrary responses"), I would hope every human being that knows his way around a text editor treats user data like the Dead Sea Scrolls. If you store a row in a database, you then think of every way that an unauthorized party can gain access to that row and close each in multiple ways. I can recite dozens of cases where user data hasn't been treated with the respect it deserves (i.e., every single Bitcoin disclosure due to newer developers running sites that are handling money).

If people took user data more seriously than they do in general, we'd have a lot less leaks. Imagine if this had gone undiscovered and the service took off? Imagine how many undiscovered vulnerabilities there are in there, with this track record to start?

I can't sympathize with this at all. I just can't.

Re: Never Give Your Information To 10 Minute Old Startups

#65
post #34

Earlier quoted context omitted.

I have mixed feeling about this. On one hand we all want to move quickly, get users, add new features, etc etc. On the other, security issues like this are just so vital that nothing else really matter if your data is not secure. It's especially true for a BACKUP SERVICE that promises ridiculous stuff like "99.999999999%" uptime on the frontpage.

we're incredibly sorry about all of this. honestly, this was all accidental. it was a pet project we started to toy with Glacier and a week later i accidentally hit the Like button sending a ping to my friends on FB. bless my friends for being so influential i guess. shame on us for using Rails carelessly. if you have any experience with startups, you'll know that 99% of the things you launch go nowhere--this project…

To be honest this is a much better response than the previous on in the other thread.

Also, can you explain what "Glacier is built for durability of 99.999999999%" actually means, if not uptime?

Re: Never Give Your Information To 10 Minute Old Startups

#66
post #62

10 minutes? Never give your information to a business that made a mistake like this, ever . That wasn't merely a "security vulnerability". It was also a demonstration that the people running the business have absolutely no idea what they are doing when it comes to security, privacy, or testing and release processes. (Actually, there is an alternative explanation, which is even worse: they knew and didn't care. I pref…

"Never give your information to a business that made a mistake like this, ever." Fwiw back in 1996 or 97 the UPS website did the same thing. By altering the tracking number you could see somewhat complete information on someone else's shipment. Since the tracking numbers ran in sequence from the shippers log books giving one tracking number from a competitor you could see all their customers. (To get that all you had…

Fair point, though of course that was at a time when most of the world hadn't even heard of the World Wide Web yet. Most people running web sites handling sensitive information have learned a lot of lessons since then.

Re: Never Give Your Information To 10 Minute Old Startups

#68
post #34

Earlier quoted context omitted.

we're incredibly sorry about all of this. honestly, this was all accidental. it was a pet project we started to toy with Glacier and a week later i accidentally hit the Like button sending a ping to my friends on FB. bless my friends for being so influential i guess. shame on us for using Rails carelessly. if you have any experience with startups, you'll know that 99% of the things you launch go nowhere--this project…

Contacted a PR person in between the last thread and this one, I'm guessing? That's a rapid 180. You have a long way to go in my mind, in terms of fixing the initial response. You probably have help now, which is great, but your initial kneejerk demonstrates underlying trouble to me which you need to fix. You're in a tough spot, too, because you can't delete those godawful comments without looking suspicious.

huh? you realize this was a pet project right? we're two dudes with no jobs.

Re: Never Give Your Information To 10 Minute Old Startups

#69

Holy shit! I consider myself a mediocre programmer at best and even I wouldn't make such a dumb mistake. This is literally something only a amateur would do. I'm just awe struck that this would even happen. How?

Same here haha. I'd be pretty upset if that was my personal information up and available for all to see, but thankfully that wasn't the case.

How this happened is what I want to know too.

Re: Never Give Your Information To 10 Minute Old Startups

#70
post #34

Earlier quoted context omitted.

I have mixed feeling about this. On one hand we all want to move quickly, get users, add new features, etc etc. On the other, security issues like this are just so vital that nothing else really matter if your data is not secure. It's especially true for a BACKUP SERVICE that promises ridiculous stuff like "99.999999999%" uptime on the frontpage.

we're incredibly sorry about all of this. honestly, this was all accidental. it was a pet project we started to toy with Glacier and a week later i accidentally hit the Like button sending a ping to my friends on FB. bless my friends for being so influential i guess. shame on us for using Rails carelessly. if you have any experience with startups, you'll know that 99% of the things you launch go nowhere--this project…

RE: durability:

http://aws.amazon.com/glacier/faqs/#How_durable_is_Amazon_Gl...

Post reply on HN