Lobsters Bug Allows Unauthorized Email Access

(lobste.rs)

14 points | by RandomGerm4n 3 hours ago

3 comments

  • Cpoll 52 minutes ago
    The poster was banned for "Irresponsible disclosure and threatening users privacy to advertise a startup." Unless the post was edited, is the moderator referring to their mention of HN?
    • opem 40 minutes ago
      I guess not! From pushcx's (mod) comment:

      > Between the threats in this post, this user only using their account to post this, their inviter (employer?) only using their account to promote their AI security scanner, I've gone ahead and handed out some user and domain bans here.

    • JdeBP 35 minutes ago
      No. The poster didn't communicate the bug per the posted instructions at https://github.com/lobsters/lobsters/blob/main/SECURITY.md ; the poster actually exploited the flaw to scrape personal data of users which xe then threatened to post; and the company being promoted was nothing to do with Hacker News at all, but was a company that sells software security stuff, with which which two lobste.rs accounts were connected.
  • el_io 2 hours ago
    Cringe
    • codingjoe 1 hour ago
      It's so out there, I can't tell if its the greatest or worst humor ever.
  • sargstuff 2 hours ago
    Guess the 'how do I post to lobsters?' secret is out[0]. aka snarf the mail distribution list. send out to mail distribution list. If worthy enough article, sent email gets posted/archived on site.

    [0] : "But yak shaving is fun" : https://news.ycombinator.com/item?id=48555838