@ElliotSpeck: > ...I'm available for consulting if you ever want to hire a security manager for @phpfog. :)
As someone who takes security seriously, and manages shared hosting security for a living, I can't imagine what the PHPFog people are going through right now. Finding security holes in commercial systems and discreetly notifying the owners of the problem is one thing; broadcasting knowledge of the holes to the world without a reasonable wait is akin to criminal. I don't care if they actually exploited it, they just threw wide the door without a second thought.
Last time this happened to me, I gave 6 months free on a dedicated server which was announced in an e-mail that went out to around a thousand users (the focus was explaining why feature x was disabled for the past few days).
It was brought up in discussion that it was probably too much, but the alternative to me was terrifying considering the amount of tickets opened because of the preventative measures.
I wouldn't go as far as that. It's sure bad form, but disclosing a fact (maybe with the exception of immediate national security concerns) can't be considered a crime.
This will cost the PHPfog folks some and they can - and should - pursue civil action against whoever causes damage to them.
Publicly admitting to having committed a "computer crime"? That's a different story.
I think the point _phred was trying to make is that publicly disclosing the issue like this puts all of the sites on PHPFog at risk.
After berating one of the "d00ds" involved on Twitter, it looks to me like he told his friend how to exploit the problem, and his friend (or his friend's friend) made the site and exploited the hole.
If I show someone how to break into your house, and that person tells someone else "hey, nbpoole's house is open, let me show you," and your house gets broken into am I completely innocent of the crime? Security knowledge is the kind of knowledge that gets things broken into, so security people need necessarily be cautious with who they tell about security problems.
Now, this particular case may or may not be criminal, but it is at least incredibly irresponsible.
"Wow, heroku for PHP. I thought of this once, sadly I wouldn't be able to get 1.2 mil in funding :(".
Well, at least we didn't have to look too hard for a motive.
I hope they get it sorted
(I had to create a different account because I have no_procrast activated on my main account. It'd be awesome if no_procrast would be automatically disabled during the weekend.)
(Just a quick note that some features are harder than it seems at first)
A classic case of the fallacy that having the idea is 90% of the work.