4 ms·
Indeed. The level of security failure was pretty incredible. They named media serially (So, pics/1.jpg, pics/2.jpg, etc.) and did not have any validation that y
by Exmoor 6y ago
Indeed. The level of security failure was pretty incredible. They named media serially (So, pics/1.jpg, pics/2.jpg, etc.) and did not have any validation that you were allowed to access what you were grabbing so it was literally as easy as possible to grab everything. Oh, and did I mention that private messages were also fully accessible?
- f430 6y agoI am convinced this was an inside job. There is simply no way someone can be this incompetent without willful intent.
- redisman 6y agoLet me introduce you to every early stage startup in the world. Plenty of mature companies also have completely abysmal security practices
- missedthecue 6y agoEver worked for a startup? This is what "move fast, break things" does.
- vlovich123 6y agoI have but only at competent ones. Nothing this flagrantly bad.
- redisman 6y agoI’ve seen not quite this bad but definitely in the same order of magnitude
- nafey 6y agoThis happens at established firms as often as startups.
- bawolff 6y agoYou'd be surprised how incompetent people can be when it comes to security. Nothing i have heard so far would really surprise me for a small startup with very rapid growth.
- wilsynet 6y agoYou take shortcuts. Saying you’ll fix it later. Which never happens because you’re busy on the next feature that is riddled with the next set of shortcuts. It happens.
- jacquesm 6y agoA career in looking at the guts of companies later I can assure that is very much possible.
- eyelidlessness 6y agoI wish I could disclose some of the incompetence I’ve encountered to persuade you otherwise. The reason there aren’t breaches like this of nearly all systems isn’t because most systems are better protected, it’s because no one’s interest (or they’re not interested for the purposes of sharing).
- burlesonK 6y agoI disagree, incompetance is rampant. I worked for a healthcare company who kept it's data at a Dell security center. One of their people ran a SQL script that deleted millions of billing records. They informed us later that they could not recover the data because every 24 hours they were writing over the one backup they kept. We had missed the window by a few hours.
- fomine3 6y agoSo Gab's strategy (fork Mastodon) looks solid for security but they hit performance issue because Mastodon isn't made for such scale.