How does Posterous authenticate a message in the absence of DKIM or SPF records in DNS? The domain dustincurtis.com does not have an SPF record and DKIM is not supported by the mail host for dustincurtis.com(Google Apps for your Domain). I assumed that Posterous did something clever using the IP address of the SMTP peer or the headers in the message. Does Posterous fallback to just checking the sender email address?
> Does Posterous fallback to just checking the sender email address? Apparently so, I didn't even change my name.
How I "hacked" Dustin Curtis's Posterous.
81–90 of 123 posts
Re: How I "hacked" Dustin Curtis's Posterous.
#82Yes, someone did figure out how to post to Dustin's site today. This security hole is now fixed.
We had a specific problem with the way we dealt with SPF records. Dustin didn't set any up, and there was a specific way that Robin Duckett's email server responded that caused us to flag it as a false negative for spoofing.
For the vast majority of users who use gmail, hotmail or other services, this was never an issue.
Since our launch on day one, we have taken email spoof detection very seriously. It's one of our core differentiators: to be able to securely post to your blog by emailing a single, easy to remember address. We don't want to do secret addresses or secret words.
Over the past 2 years, we've developed robust spoof detection ip and spend a ton of time trying to stay a step ahead of hackers. Fortunately, we've only had a few very specific, isolated cases where one of our sites was spoofed and each time we have improved our system.
Thanks for bringing this to our attention. We always need to be one step ahead of the hackers/spoofers, and we thank the Hacker News community for keeping us on our toes!
Re: How I "hacked" Dustin Curtis's Posterous.
#83Earlier quoted context omitted.
That much is obvious, but what would cause the FBI to get involved and what would he be charged with?
jcromartie's premise was, "If Dustin were a major corporation or a politician..." IANAL, and it's not exactly the same circumstances, but when Sarah Palin's e-mail was hacked during the 2008 U.S. presidential campaign, the FBI and Secret Service both "got involved". According to Wikipedia the hacker in question was eventually found guilty of (1) felony obstruction of justice by destruction of records and (2) misdemea…
The parent has a lot of upvotes, so I really want to know why they agree he committed a crime, rather than found a bug.
Re: How I "hacked" Dustin Curtis's Posterous.
#84Earlier quoted context omitted.
it's a hack in the Bruce Schneier "easiest way to steal pancakes has nothing to do with where money changes hands" sense... Our goal is to eat, without paying, at the local restaurant. And we've got a lot of options. We can eat and run. We can pay with a fake credit card, a fake check, or counterfiet cash. We can persuade another patron to leave the restraunt without eating and eat his food. We can impersonate (or ac…
You've made this celiac crave pancakes again. Bad.
Re: How I "hacked" Dustin Curtis's Posterous.
#85Does Posterous filter SEO spam? Otherwise this loophole seems like a perfect opportunity for SEO spam to start filtering in on lapsed accounts that still have some PageRank...
Re: How I "hacked" Dustin Curtis's Posterous.
#86Hey guys. I'm the cofounder of Posterous. Yes, someone did figure out how to post to Dustin's site today. This security hole is now fixed. We had a specific problem with the way we dealt with SPF records. Dustin didn't set any up, and there was a specific way that Robin Duckett's email server responded that caused us to flag it as a false negative for spoofing. For the vast majority of users who use gmail, hotmail or…
Posterous:email spoof detection PayPal:credit card fraud detection
See the section in Founders at Work on the value that better fraud detection created for PayPal.
Re: How I "hacked" Dustin Curtis's Posterous.
#87Earlier quoted context omitted.
it's a hack in the Bruce Schneier "easiest way to steal pancakes has nothing to do with where money changes hands" sense... Our goal is to eat, without paying, at the local restaurant. And we've got a lot of options. We can eat and run. We can pay with a fake credit card, a fake check, or counterfiet cash. We can persuade another patron to leave the restraunt without eating and eat his food. We can impersonate (or ac…
You've made this celiac crave pancakes again. Bad.
Re: How I "hacked" Dustin Curtis's Posterous.
#88Warning him would have been nice, this IS, by definition almost, malicious - regardless of how you chose to interpret the word yourself.
Re: How I "hacked" Dustin Curtis's Posterous.
#89Earlier quoted context omitted.
or do what flickr does and give you a unique email address to send to that only you will know. you can add it to your address book so you won't have to remember it, and it's probably stronger than what most users would choose for a password.
Such considerations might be overkill for flickr/posterous but that does leave your "secret" email address in the logs of every smtp relay along the way. Its sort of equivalent to putting a password in a URL.
This isn't UUCP, the message will go from A to B across the internet backbone. There will only be SMTP relays along the way if either your email host or the receiver's email host has chosen to set things up that way. We'd have a much bigger problem with internet security if everyone's email was relayed through questionable servers as a matter of course.
Re: How I "hacked" Dustin Curtis's Posterous.
#90Earlier quoted context omitted.
jcromartie's premise was, "If Dustin were a major corporation or a politician..." IANAL, and it's not exactly the same circumstances, but when Sarah Palin's e-mail was hacked during the 2008 U.S. presidential campaign, the FBI and Secret Service both "got involved". According to Wikipedia the hacker in question was eventually found guilty of (1) felony obstruction of justice by destruction of records and (2) misdemea…
Basically what I am wondering is if he were to make a post to Pepsi's blog on Posterous, what would the federal crime be? The parent has a lot of upvotes, so I really want to know why they agree he committed a crime, rather than found a bug.