Thoughts on the Posterous hack
blog.dustincurtis.com
Thoughts on the Posterous hack
1–10 of 62 posts
Re: Thoughts on the Posterous hack
#2Re: Thoughts on the Posterous hack
#3couldn't they do something like the email address is yourusernameatyourdomain.comandanextrabityoutset@posterous.com which would be an id you could remember?
Re: Thoughts on the Posterous hack
#4Re: Thoughts on the Posterous hack
#5couldn't they do something like the email address is yourusernameatyourdomain.comandanextrabityoutset@posterous.com which would be an id you could remember?
Re: Thoughts on the Posterous hack
#6The compromise I suggested here addresses both concerns (ease of use and security)
Re: Thoughts on the Posterous hack
#7It's the typical false assumption non-technical users have about security: who would be interested in hacking me anyway? Automated scripts, that is who.
Also, how are the email posts interpreted by posterous - is it possible to post custom html snippets and javascripts via email? This would be scammer's heaven, as they could probably even hide that a blog has been spammed.
Re: Thoughts on the Posterous hack
#8If you want to keep security simple enough that it doesn't strangle the service then hand out a unique email like post-45h231sxax23s1@posterous.com and have the user add that to their address book - viola, you've managed to add a layer of obscurity to posterous' posting mechanism at least, even though it's still not really a strong one.
Re: Thoughts on the Posterous hack
#9I can imagine quite a lot of spammers who would love to have a blog-post on an otherwise reputable blog. If spammers manage to abuse this system they could get their blogposts, filled with links and instructions to buy medication, all over all posterous blogs.
Re: Thoughts on the Posterous hack
#10edit:
It looks like this is already standard functionality (if turned on, and even if not there is still an email sent with a delete link).
I don't think dustin does a good job explaining why "It is OK" in this blog post, but I think I agree with his conclusion, this doesn't seem like a big deal if a user has opted for the more optimistic workflow rather than the more precautionary one.