Lobsters Bug Allows Unauthorized Email Access

(lobste.rs)

24 points | by RandomGerm4n a day ago ago

8 comments

  • Cpoll a day ago ago

    The poster was banned for "Irresponsible disclosure and threatening users privacy to advertise a startup." Unless the post was edited, is the moderator referring to their mention of HN?

    • opem a day ago ago

      I guess not! From pushcx's (mod) comment:

      > Between the threats in this post, this user only using their account to post this, their inviter (employer?) only using their account to promote their AI security scanner, I've gone ahead and handed out some user and domain bans here.

    • JdeBP a day ago ago

      No. The poster didn't communicate the bug per the posted instructions at https://github.com/lobsters/lobsters/blob/main/SECURITY.md ; the poster actually exploited the flaw to scrape personal data of users which xe then threatened to post; and the company being promoted was nothing to do with Hacker News at all, but was a company that sells software security stuff, with which which two lobste.rs accounts were connected.

  • el_io a day ago ago

    Cringe

    • codingjoe a day ago ago

      It's so out there, I can't tell if its the greatest or worst humor ever.

    • a day ago ago
      [deleted]
  • sargstuff a day ago ago

    Guess the 'how do I post to lobsters?' secret is out[0]. aka snarf the mail distribution list. send out to mail distribution list. If worthy enough article, sent email gets posted/archived on site.

    [0] : "But yak shaving is fun" : https://news.ycombinator.com/item?id=48555838

  • Natfan a day ago ago

    [flagged]