Saturday, October 15, 2011

Security Investigation update

Early Saturday morning, b@b was taken down and left with a splash-page that read:


I'm investigating a potential security breach.


I have reason to believe there may have been a security breach with the b@ server. At the moment it was discovered, I didn't have a good explanation so first thought was to immediately take the site offline for further analysis. I will post blog updates when I have something to report.


don't want to speculate at this point but I will put up a blog post. I appreciate your patience.


Jae

I then reported on Sat Oct 15 2:07pm:


An anonymous tipster stepped forward and described a method to reveal user ids using a client-side bookmarklet technique. Its pretty smart! While this did not pose any threat to the server or the integrity of the data, it is considered an unintentional loophole in the architecture. Therefore, I think it would be necessary to address the issue before bringing the site back online. I will have to kindly ask for your patience.


To the tipster: Deep Bow to You

Final update on Sun Oct 16 2:52pm:

It turns out it wasn't all that difficult to fix the work-around. It has been patched now.

1 comment:

  1. out of curiosity, could we have more details on how this exploit worked?

    ReplyDelete