Live data from Hacker News

Tumblr security hole (the gaping kind)

news.ycombinator.com

81–85 of 85 posts

Re: Tumblr security hole (the gaping kind)

#83
post #78

Earlier quoted context omitted.

QA departments are notorious for not being very creative. You'd need a star QA department to find the /admin hole, I think.

No, you just need functional tests. Having these kind of bugs in a spare time project is fine, but if you call yourself a startup and ask customers to trust you with data, you need to seriously consider security issues.

yea i mean it seems to be a first step obvious point.

Re: Tumblr security hole (the gaping kind)

#84
post #11

Earlier quoted context omitted.

ok, maybe :) But forgeting to secure your admin area deserves more than a simple warning. Can you imagine if the person that discovered the vulnerability decided to delete all the user accounts?

Or try out the usernames and passwords on say BofA?

The passwords aren't stored in plaintext, they said.
Post reply on HN