HNHacker News
TopNewBestAskShowJobs

tmaher

12 karma · joined January 9, 2013

submissionscomments
tmaher··on Security Vulnerabilities in Heroku
It was actually slightly more dumb than that.

Like most sites, after you register your account, we generate a nonce and email it to the provided address. You click the link with the nonce, we prompt you to set your password, and your account is ready. Our bug was that for already-verified users, the nonce column in the database is empty (it's a nonce, you see, so we only use it once...). This was the root cause for both bugs Mr. Sclafani describes.

tmaher··on Security Vulnerabilities in Heroku
Hi, our response can be found at...

http://blog.heroku.com/archives/2013/1/9/password_hijacking_...

Thanks again to Stephen for giving us ample time to fix this.

-Tom Maher, Heroku Security Team