Live data from Hacker News

iViewed your API keys

wale.id.au

91–100 of 116 posts

Re: iViewed your API keys

#91
post #77
post #74

The Algolia side is required and expected, no? I know you can hide said details to be even safer, but it's expected to have the API public tokens available to the client so they can use the API from your site. The keys shouldn't work on other sites since the API will whitelist your application URL, so stealing them is pointless.

wouldn't `curl -H 'api key' -H'origin:whitelist-url'` let you use Algolia as if you were ABC if all Algolia does is URL whitelisting?

You can also use your browser to go to the site and query Algolia. What’s the difference?

Re: iViewed your API keys

#92

Earlier quoted context omitted.

> If you randomly try my front door and find that it's unlocked, don't expect me to be thanking you. Why? If someone tries my front door, doesn't go in but confirms that it is unlocked by opening it by an inch (=verifies the DB credentials but doesn't run any queries) without really peering into my private spaces, then privately reaches out with "hey, hey, your door is not locked - I haven't went in but I know it's u…

A friend or a nice neighbor: why not. But a random stranger? I'd certainly be unhappy! Why would they even try to open the door in the first place?

Better one who would let me know, than someone who would steal everything and sell it, no?

Re: iViewed your API keys

#93

Earlier quoted context omitted.

weev didn’t just “browse a public url at AT&T”. That is dishonestly reductionist. He noticed the bug and then used it to retrieve and make public the private data of over a hundred thousand people.

The data was already publicly available. Didn’t he just publicize the url?

[deleted]

Re: iViewed your API keys

#94
post #20

Earlier quoted context omitted.

They’ve been reasonable by waiting four months from initial contact, but in vulnerability disclosures it’s polite to add a better timeline of events. There’s still some detail that hasn’t been fully resolved, but it’s not clear what the residual impact is. This particular post doesn’t really seem to go into too much depth about what these keys are used for, or the damage that could be done, but I’m erring on the side…

> Lastly, the ABC is a corporate entity that is fully owned by the commonwealth (and beloved by most Australians) - tue article describes it as ‘state media’, which has sinister propaganda connotations of broadcasters in some other countries. I’d compare ABC to PBS in America. They both are state media. I think more liberal usage of accurate terms in this way is needed. Folks ought to know who funded and produced the…

Both PBS and ABC are independent of the ‘state’ though. They’re public broadcasters funded by public funds, which are administered by a federal agency (Dep of Industry in Australia).

Re: iViewed your API keys

#95
Broader context: iView (from the ABC in Australia, a publicly funded broadcaster) was pretty much first to market here for streaming TV, and view on demand.

The other stations have all since caught up, but ABC have a tremendous amount of quality children's content so it's a very popular service with families.

However, the current government is not a fan of funding the ABC and as such they've been operating with a very tight and reducing budget for most of the last decade. The edges of their products including interactive news pieces and election/pandemic coverage (and some of these API key issues) are a bit rough but the overall achievement is excellent.

Re: iViewed your API keys

#96

Earlier quoted context omitted.

But why is the Australian government so "police state" minded? Is that really what the Australian people want? I'd guess they just don't care either way, but in that case why would the Australian politicians push for that? Canada has a pretty similar apathy towards politics but even then we don't see the government forcing Canadian citizens to implement backdoors or raiding the offices of a broadcaster. (Yes the rece…

In simple terms, Australia is a relatively young country that formed its own government in 1901. It was also isolated from the rest of the world and has a harsh environment with a lot of things that can kill you. This produced an overall culture of helping each other when you can (what gets called “mateship”), and trust in the government to help when it is needed. Australians generally like an orderly society, that t…

Don't forget our geography either! We're in fairly close proximity, physically and politically, with authoritarian Asian states like Singapore, Malaysia and China.

Re: iViewed your API keys

#97

Earlier quoted context omitted.

Also in the US, where you can be sentenced to 41 months in prison for browsing a public URL at AT&T, and where the the Governor of Missouri wants to make it illegal to view the html source of a web page (because some state web site leaked all the SSNs of their teachers in some hidden html or something). If I found something like this on a site I don't think I would notify anyone. Too risky. Maybe over TOR if they hav…

weev didn’t just “browse a public url at AT&T”. That is dishonestly reductionist. He noticed the bug and then used it to retrieve and make public the private data of over a hundred thousand people.

My understanding was they just sent random icc-id codes as a query parameter to a public url, and if you hit a valid id it returned an email address. It was working as "designed", and not a bug.

Re: iViewed your API keys

#98
Also, almost every Android app in Google Play has all the Firebase API keys exposed in their manifests, and it's really easy to retrieve them from APK/AAB's.

Re: iViewed your API keys

#99

Earlier quoted context omitted.

Also in the US, where you can be sentenced to 41 months in prison for browsing a public URL at AT&T, and where the the Governor of Missouri wants to make it illegal to view the html source of a web page (because some state web site leaked all the SSNs of their teachers in some hidden html or something). If I found something like this on a site I don't think I would notify anyone. Too risky. Maybe over TOR if they hav…

weev didn’t just “browse a public url at AT&T”. That is dishonestly reductionist. He noticed the bug and then used it to retrieve and make public the private data of over a hundred thousand people.

You are equivocating. Iirc this bug you refer too WAS the public urls

Re: iViewed your API keys

#100
post #39
post #11

Earlier quoted context omitted.

I booked a hotel stay (in Canada, not Australia) and got an error page at some point that dumped out all env vars including database credentials. Tried my best to report (not publicly disclose) it, including asking the front desk for contact information for IT; no response. I think we're (on HN) often in quite a bubble of being (or striving to be) hot on this sort of thing, or frankly far trickier to exploit sorts of…

Most C-level people couldn't care less about security. I'm yet to work for a SaaS that implements 2FA, yet at some point all of them have had passwords that a script kiddie could brute force within an hour. The only time I've seen security become a top-level priority was when some customer demanded some kind of checkbox compliance like SOC / ISO27001.

You call it checkbox compliance, but it does at least make vendors think about pretty much the bare minimum in all-around security posture, and then have an external audit - as someone who has to approve SaaS vendors it makes my life much easier.
Post reply on HN