4 ms·
Their voicemails seem to be public... Just pick a key from https://twelephone-voicemail.s3.amazonaws.com https://twelephone-voicemail.s3.amazonaws.com and voi
by ryanseys 13y ago
Their voicemails seem to be public...
Just pick a key from https://twelephone-voicemail.s3.amazonaws.com https://twelephone-voicemail.s3.amazonaws.com
and voila!
https://twelephone-voicemail.s3.amazonaws.com/1rajmadugulaedwardallison12013-04-23T17:06:49Z.wav https://twelephone-voicemail.s3.amazonaws.com/1rajmadugulaed...
- cmatthieu 13y agoYou would need to know the exact millisecond of the timestamp and usernames to access it. Our plans are to allow sharing of video/voice messages publicly if the user chooses. Feedback welcome...
- ryanseys 13y agoI think this is unacceptable because this is easily brute-forceable, especially when you (by default) tweet the other user that a voicemail has been left. https://twitter.com/ryanseys/status/355009243306405890 https://twitter.com/ryanseys/status/355009243306405890 EDIT: Also, the timestamp is per-second (1rajmadugulaedwardallison12013-04-23T17:06:49Z.wav) not per millisecond, making bruteforce a rather elementary task when combined with twitter tweet information.
- cmatthieu 13y agoGood point. Salting the key should make this better.
- ryanseys 13y agoAnd restrict access to this page (which lists all the keys, salted or otherwise)... https://twelephone-voicemail.s3.amazonaws.com/ https://twelephone-voicemail.s3.amazonaws.com/
- pathy 13y agoOh my, why isn't this page restricted? That is a very serious flaw in the system. Not exactly caring about the users' privacy, or security.
- cmatthieu 13y agoWe haven't yet officially released voice messaging but the feature stuck into this release. We'll correct the access on our next update (prior to it being announced). Thanks everyone.
- aw3c2 13y agoThis is a issue where you pull the plug right now, fix the issue and tell your users about. Otherwise your company just dug its own grave publicity-wise. Privacy is the foremost important issue if you handle people's communication.
- JshWright 13y agoYou have to wait for an "update" before you can take that page down?
- spyder 13y agoYea, the answer reminds me to the security issue with the Zamfoo cpanel plugin, when the developer promised to fix it in the next update but for some other reasons he couldn't release the update for weeks: http://www.webhostingtalk.com/showthread.php?t=1275572 http://www.webhostingtalk.com/showthread.php?t=1275572 https://news.ycombinator.com/item?id=5888036 https://news.ycombinator.com/item?id=5888036
- pbhjpbhj 13y agoOne message may or may not be someone waiting for about 30s for the "beep" to tell them to start their message. Lol. [I have poor impulse control, sorry.]
- jabbernotty 13y agoAs ryanseys points out, a timestamp and username doesn't provide any kind of security. Since this uses Twitter, a good move may be to use Twitter's API to check if the correct user has been logged in (I don't know the Twitter API). Would using direct messages work?
- aw3c2 13y agoWhat do you mean? I just picked random Key values from that and could download those files with no problem. This is a crazy privacy issue!
- swinglock 13y agoIt's totally understandable to make a mistake like this and it's early, but it's scary how you think that's an acceptable solution.
- untog 13y agoTo be clear, I just went to that first URL, copy and pasted the key to the end of the URL, and I listened to you leaving a message saying "This is a test. 1,2,3". I did not need to know anything else. This is not good.
- methehack 13y agoWouldn't it be better to share this directly with the service provider instead of exposing users' data like this? Also kinder?