Security Flaw Found in Tumblr, Company Says It’s Now Fixed

Posted by ADMIN on Sunday, March 20, 2011



It started with a tweet Saturday morning, sounding an alarm of a security breach in the popular microblogging platform Tumblr. “OMG… The Tumbeasts are spitting out passwords!,” it warned.

That tweet spread like wildfire, notifying the world of a coding error that opened a security hole with the potential of revealing users’ passwords, server IP addresses, API keys and personal information.

Fortunately, Tumbler reacted, fixing the problem and then issuing this official message about 5 to 6 hours after the flaw was discovered:
“A human error caused some sensitive server configuration information to be exposed this morning. Our technicians took immediate measures to protect from any issues that may come as a result.
We’re triple checking everything and bringing in outside auditors to confirm, but we have no reason to believe that anything was compromised. We’re certain that none of your personal information (passwords, etc.) was exposed, and your blog is backed up and safe as always. This was an embarrassing error, but something we were prepared for.
The fact that this occurred at all is still unacceptable, and we’ll be seriously evaluating and adjusting our processes to ensure an error like this can never happen again.
Please let us know if you have absolutely any questions.”
What caused the error? That’s still under intense discussion at The Hacker News and elsewhere in the hacker community, but many think the culprit was a errant piece of PHP code. Obviously, spelling counts.


Let us know in the comments if you think those who discovered the security flaw were more eager to broadcast its existence than notify the Tumbler coders who might have been in a position to quickly fix it.

Kindly Bookmark and Share it:

0 comments:

Post a Comment

 

Recent Posts

join me on facebook

Follow Me On Twitter

GET TWEETS!

technooguide Team on Twitter Counter.com

About This Blog

TecHnooGuide.blogspot.com started as a personal blog in Jan 2011, under the first domain name TechnooGuide.

TechnooGuide aims to provide the latest news about technology and gadgets, social media, computers, and the internet in general to all the people of the world.

Everything just started as a hobby and passion of the editor-in-chief of this blog to write the latest news in the internet, particularly in the field of technology, gadgets, and computers. The simple passion started to get serious as this blog continue to grow.

I’m optimistic the year 2011 would be a success, but of course that wouldn’t happen without you being part of the community. If there’s anything you have to say, I’d love to hear that. Cheers!

| TecHnooGuide © 2011. All Rights Reserved | Template Style Modified by Ahmed korat & Designed by mohammed Ahmedzai|