Lobsters Bug Allows Unauthorized Email Access

(lobste.rs)

19 points | by RandomGerm4n 9 hours ago ago

8 comments

  • Cpoll 7 hours ago

    The poster was banned for "Irresponsible disclosure and threatening users privacy to advertise a startup." Unless the post was edited, is the moderator referring to their mention of HN?

    • opem 7 hours ago

      I guess not! From pushcx's (mod) comment:

      > Between the threats in this post, this user only using their account to post this, their inviter (employer?) only using their account to promote their AI security scanner, I've gone ahead and handed out some user and domain bans here.

    • JdeBP 6 hours ago

      No. The poster didn't communicate the bug per the posted instructions at https://github.com/lobsters/lobsters/blob/main/SECURITY.md ; the poster actually exploited the flaw to scrape personal data of users which xe then threatened to post; and the company being promoted was nothing to do with Hacker News at all, but was a company that sells software security stuff, with which which two lobste.rs accounts were connected.

  • el_io 8 hours ago

    Cringe

    • codingjoe 7 hours ago

      It's so out there, I can't tell if its the greatest or worst humor ever.

    • 7 hours ago
      [deleted]
  • sargstuff 8 hours ago

    Guess the 'how do I post to lobsters?' secret is out[0]. aka snarf the mail distribution list. send out to mail distribution list. If worthy enough article, sent email gets posted/archived on site.

    [0] : "But yak shaving is fun" : https://news.ycombinator.com/item?id=48555838

  • Natfan 5 hours ago

    [flagged]