news.volyx.in

Tell HN: Fiverr left customer files public and searchable

831 points by morpheuskafka · 138 days ago · 232 comments on HN

Article summary

Fiverr, a gig work platform, used a service called Cloudinary to process and store files, including sensitive client information, but failed to secure them properly, making them publicly accessible and searchable on Google. This has resulted in hundreds of files, including tax forms and other personal documents, being exposed. The issue was reported to Fiverr's security team 40 days prior, but no response was received. The leak includes personal identifiable information (PII) and other sensitive data.

Main themes

  • Data breach
  • Security vulnerability
  • Cloud storage
  • Personal identifiable information
  • Corporate responsibility

What commenters say

  • The leak is a serious breach of security and privacy, and Fiverr's lack of response to the initial report is unacceptable.
  • The fact that Fiverr bought Google Ads for keywords related to the leaked documents suggests they were aware of the issue and tried to profit from it.
  • The exposure of sensitive information, including tax forms and admin passwords, has significant consequences for individuals and businesses affected.
  • Some argue that the tech team at Fiverr deserves sympathy, while others believe that the company's incompetence and negligence warrant severe consequences.
  • There is a need for stricter regulations and certifications for companies handling sensitive data to prevent such leaks in the future.
  • The leak highlights the importance of individual vigilance, such as freezing credit and monitoring personal data, to protect against identity theft and other malicious activities.