Clinkle gets hacked before it even launches
techcrunch.com
techcrunch.com
It is by design that if someone finds the API they will be able to use it without authentication and nothing is required on behalf of the "hacker" to access it. Are all users of software hackers under this definition?
I do not believe they are lying in their statement that it was temporarily open and intended to be closed, it makes sense to me why that effort would be put off for test data.
Lots of 'what?' moments in tech reporting lately...
If only tech journalists actually knew something about tech.
"how is this different from facebook or google plus search? i type in someone's name, i get back their full name, profile photo, phone number if it's public, etc."
Fair enough, the only real personal information is your telephone number, and we don't know if they are operating like the white pages, opting out of displaying that publicly.
On the other hand, I'm thinking "how much other stuff are they going to forget to lock down when they go live?"
There are two quotes on the back of my business cards. One of them says, "If you don't have the time to do it right, when you will have the time to do it over?"
Why would you even design an application to allow that? Even if the user was deleted (as potentially indicated by a null phone number), it's still a conflict.
Although I agree that this is not ideal, zero is not null.
Implicit casts -- including to booleans -- are dangerous, but if you try to write APIs to try to avoid every bad thing that might happen with naive use of implicit casting in every language that might be used to consume your API, you won't be able to do anything at all.
>>> NULL == 0
Traceback (most recent call last):
File "<stdin>", line 1, in <module>
NameError: name 'NULL' is not defined
Even None, which is as close to NULL you are going to get in Python is not 0. >>> None == 0
False >>> 'truthy' if None else 'falsy'
'falsy'
>>> 'truthy' if False else 'falsy'
'falsy'
>>> 'truthy' if 0 else 'falsy'
'falsy'Out[1]: False
Idiomatic Python may say "if not user_id:" and erroneously skip this.
Idiomatic test for `None` is:
if something is None:
# ...
It would be incorrect to use `if not something:` here.and weev actually had to do work to break the AT&T service... this looks like he just searched for users.
My point isn't to vilify the unknown "hacker" here but rather to suggest that what is or isn't hacking varies greatly upon whose point of view you're looking at things from, and how badly they'd like to shift the blame for their errors to someone else, and how willing they are to go after you with the full force of a federal prosecutor all too willing to jump on a trending gravy-train. We've set some very dangerous recent precedents where trivial "hacks" have resulted in very serious punishments.
This is the first I've heard of the company and I'm not inclined to use a payment processing company where my first impression of them is they "leak user data like a sieve".
Granted, they are still in development, this can all change, etc, but my first impression is now set, and not in a positive way.
More exciting trend-hopping startup news out of Silicon Valley and Techcrunch.
http://techcrunch.com/2013/09/30/leaked-youtube-video-tumblr...
They are about to ask a lot of people for private information dealing with peoples money. If they have any loose API ends and choose to slough it off as no big deal, then count me out on using their product.