Live data from Hacker News

You don’t need a password. Posterous fail.

blog.dustincurtis.com

71–80 of 84 posts

Re: You don’t need a password. Posterous fail.

#71
post #69
post #61

Earlier quoted context omitted.

It is a namespace thing. I am pretty sure. When I use a title for my posterous posts that no one ever used before, the permalink is just the title. When I for example post something titled generally like "photo" it becomes "photo-73864"

So all post URLs share a single global namespace, regardless of ownership? That's not a very clever design IMO.

yep, looks like it.

if you check for example: http://posterous.com/explore You can see all pretty unique titles without a number appended and then a post titled "Tetris" gets "/tetris-194"

Even if you post something without a title it just gets an ID assigned which is (this is a guess tho) the unique ID in their database of all blogs.

Re: You don’t need a password. Posterous fail.

#72
Hey guys. I'm the cofounder of Posterous.

Yes, someone did figure out how to post to Dustin's site today. This security hole is now fixed.

We had a specific problem with the way we dealt with SPF records. Dustin didn't set any up, and there was a specific way that Robin Duckett's email server responded that caused us to flag it as a false negative for spoofing.

For the vast majority of users who use gmail, hotmail or other services, this was never an issue.

Since our launch on day one, we have taken email spoof detection very seriously. It's one of our core differentiators: to be able to securely post to your blog by emailing a single, easy to remember address. We don't want to do secret addresses or secret words.

Over the past 2 years, we've developed robust spoof detection ip and spend a ton of time trying to stay a step ahead of hackers. Fortunately, we've only had a few very specific, isolated cases where one of our sites was spoofed and each time we have improved our system.

Thanks for bringing this to our attention. We always need to be one step ahead of the hackers/spoofers, and we thank the Hacker News community for keeping us on our toes!

Re: You don’t need a password. Posterous fail.

#73
post #55

Earlier quoted context omitted.

Except that's more like 10% or even 1% security.

Oh really? I don't think you know what you mean. In point of fact, I just sent myself a very important password in clear text. Hack me.

The task for a spammer isn't to hack account. It's to hack ANY account.

Being able to hack any posterous account is going to be far far easier than trying to hack a particular account.

Re: You don’t need a password. Posterous fail.

#75
post #71
post #69

Earlier quoted context omitted.

So all post URLs share a single global namespace, regardless of ownership? That's not a very clever design IMO.

yep, looks like it. if you check for example: http://posterous.com/explore You can see all pretty unique titles without a number appended and then a post titled "Tetris" gets "/tetris-194" Even if you post something without a title it just gets an ID assigned which is (this is a guess tho) the unique ID in their database of all blogs.

This is changing soon! It's on our roadmap.

Re: You don’t need a password. Posterous fail.

#76
post #18

What I'm surprised is why posterous doesn't do more check on all the headers sent by the email software (X-Mailer, and so on) and ask for a confirmation if those other headers are different enough from a known correct configuration... Of course someone who received an email from the blog owner could use that to fake all those headers but at least it would prevent people posting by simply guessing the email address.

Oh, we do that. This was a specific bug that is now fixed.

Re: You don’t need a password. Posterous fail.

#77
post #25
post #11

Earlier quoted context omitted.

Headers are name/value pairs, a typical email will have 20 of those. It's possible to copy them if you have received an email from the blog owner or maybe from a mailing list post.

You only need to know the owner's email address. Access to a message or a mailing list post by them won't provide any further advantage.

Email address is not enough. This one case was a coincidence.

"We had a specific problem with the way we dealt with SPF records. Dustin didn't set any up, and there was a specific way that Robin Duckett's email server responded that caused us to flag it as a false negative for spoofing."

Re: You don’t need a password. Posterous fail.

#78
post #4

Not so big a deal IMHO. You can always set a pass if spammers start targeting your blog.

The password is for visiting, not for posting. If you set a password, nobody can visit your blog w/o the password. http://posterous.com/help/private_sites "You can set a password on your Posterous site so only the readers you want can see it. To see your site, a user must go to your site url and also enter the correct password for your site."

Right, my bad. Still there is an option to receive confirmation link for each post.

Re: You don’t need a password. Posterous fail.

#80
post #77
post #25

Earlier quoted context omitted.

You only need to know the owner's email address. Access to a message or a mailing list post by them won't provide any further advantage.

Email address is not enough. This one case was a coincidence. "We had a specific problem with the way we dealt with SPF records. Dustin didn't set any up, and there was a specific way that Robin Duckett's email server responded that caused us to flag it as a false negative for spoofing."

I think he said that: The blog owner's email host did not provide SPF protection; the intruder's email host appended some headers that lured Posterous to classify the email as genuine.

So, having access to the blog owner's email headers would not have provided any additional advantage to the intruder.

Post reply on HN