Exploiting filepicker.io
digitalmisinformation.posterous.com
digitalmisinformation.posterous.com
I'm about to implement filepicker.io for a project and really do not mind any kind of server-side integration that would avoid chances of malicious users abusing the service against our filepicker.io or S3 usage.
Even more excited to get Filepicker implemented now!
It doesn't totally solve the problem, it just moves it; but it moves it to a less vulnerable location if you never have to get your API key into a browser where anyone can check it out by viewing source, or, in extremis, opening FireBug.
Edit: The Filepicker.io email seems to indicate a PKI-style solution, but I can only sort of guess at the implementation.
What you're interested in is:
"signature" - "A signature value that authorizes the form and proves that only you could have created it. This value is calculated by signing the Base64-encoded policy document with your AWS Secret Key, a process that I will demonstrate below."
I suppose that's solved by serving the form over https. Perhaps that's just what I was missing.
That said, it's a pretty obvious problem which is inherent in the way Filepicker is doing things right now. Simple sometimes comes at the expense of secure. I'd argue that they made a fairly reasonable trade-off for the time.
Good to see Brett and the team are responding quickly.
I don't see why anyone would have integrated without this.