4 ms·
Extremely bad stuff here. Can't believe it's been 7 hours now and you can still pull up people's complete prepared tax returns right from a Google search. This
by evmaki 6mo ago
Extremely bad stuff here. Can't believe it's been 7 hours now and you can still pull up people's complete prepared tax returns right from a Google search. This should be a business-ending breach of trust and good practices, but I worry there's probably a lack of regulatory might or will to make anything happen.
- TkTech 6mo agoIt's very unfortunate but a significant amount of the most damaging stuff in this is from the underprivileged and those with minimal means who were trying to find help they could afford. Non-profits trying to get website help, confidential reports for charities trying to get translations, children seeking therapy (fiverr has a therapy category!?) for some truly dark stuff. Utterly inexcusable that this is still up after so many hours.
- mellosouls 6mo agoTechnically, 40 days and 7 hours!
- ChrisMarshallNY 6mo ago...and forty nights...
- kkarpkkarp 6mo ago...since you leaked my data away
- deepserket 6mo agoIt looks like they (cloudinary?) blocked the content. Each result from the query site:fiverr-res.cloudinary.com form 1040 returns 404
- abustamam 6mo agoYikes! It should not require the service provider to block PII, but at least someone plugged the leak.
- morpheuskafka 6mo agoThe company put out its first statement: > “Fiverr does not proactively expose users’ private information. The content in question was shared by users in the normal course of marketplace activity to showcase work samples, under agreements and approvals between buyers and sellers. This type of content requires the buyer’s explicit consent before it can be uploaded. As always, any request to remove content is handled promptly by our team." https://sqmagazine.co.uk/fiverr-security-flaw-private-documents-google/ https://sqmagazine.co.uk/fiverr-security-flaw-private-docume... It sounds like they are trying to claim the users involved published the links and that's why they are on Google? But how could anyone believe that multiple users intentionally published their SSN? Re the takedown, I'm also guessing it's from Cloudinary. Maybe HTTP Referrer based?
- janoelze 6mo agoThe DMCA takedown also suggests at least one user was not aware of that file being public. This all comes down to what that "sharing" action specifically looked like. ChatGPT recently had a similar case with the sharing feature on conversations leading to publicly indexed convos. That incident would have also matched the implied definition of sharing here.