Hacker News .hnnew | past | comments | ask | show | jobs | submitlogin

Isn't it easy to send an email and put whatever email we want as the sender? I was just wondering, does it means anyone could post on the post of someone else?


Let's find out.

I've just created a posterous account at http://pmn.posterous.com

The email that I've authorized is paul@pmn.org

I've put one post on there, any other posts that appear are not from me.

(I should note, I use Posterous for some personal stuff and love the service. This isn't something I've been terribly concerned about yet.)


I just got this email from Posterous:

  ATTENTION: We noticed you're sending this from a different
  computer or location, so it won't get posted until we're 
  sure it's you. Please confirm that you sent this.
So, it looks like they've thought about this problem already.


But what action did they ask you to take to confirm that it is you?


Oh, good question - there is a link in the email to confirm that I want it posted. There is also a dashboard that lets me see all of the attempts and either approve or delete them.


OK. Easy enough: email spoofing + ip spoofing.


My welcome email from July 2008 has a prominent box that says, "Setting a password for your account is easy. It's optional, but here's why you should..."

What did you welcome email say?


Yep, my welcome email has the same box suggesting I add a password.

I think they're going to end up just as safe as every other blogging service out there.


I see two posts already.


Sorry about that; that was a mistake I made when creating the blog. I sent an email prior to creating an account - the system was smart and merged them.

I've removed the extra one, so it should be back down to one.


I think they do some checking in the headers. It's not impossible to masquerade as someone.

But how many people want to maliciously post to some random person's Posterous blog? Probably not too many.


If the system was ever adopted widely (which I presume the founders desire) I would imagine that spoof posting would be a huge problem if someone could pull it off.


I suspect blackhat SEOs would be all over it.


All of the black hats who want to abuse numerous holes in your browser of choice?

They wouldn't necessarily even have to get you to click on a link. There have been numerous attacks against image processing libraries.


Actually, I hadn't read this comment! XD


I don't think blackhats would be all over it, the links are completely invisible to a search engine...

Maybe Smear Campaign artists might take to it. Or spammers...


I'm not too familiar with Posterous, are all links nofollowed? Can't you post arbitrary HTML to your own blog?


Or people trying to prove a point, check the front page :P


TechCrunch had a contest about this when Posterous launched: http://techcrunch.com/2008/06/28/posterous-beats-tumblr-in-s...

Michael Arrington posted the results here: http://techcrunch.posterous.com/lots-of-fake-post-attempts-o...


3 fake posts made it through. I'd consider > 0 a failure. I guess you could use a super secret From email address?


"Apparently You don’t need a password. Posterous fail."

http://blog.dustincurtis.com/apparently-765




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: