Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

FYI All your subscriber's emails are accessible at https://whiteboardfree.com/email_subscribers.json since you didn't put any authentication on those endpoints. It's a basic Rails app so I'm guessing other users may got a hold of the list already.


I guess their Privacy Policy checks out https://whiteboardfree.com/privacy


This is a pretty crummy wait to disclose a security vulnerability.

Yeah, this one is pretty bad. But let’s try to do better, not worse.


So you're telling me that someone who created a site to post job adverts for jobs that don't test programming skills, has managed to write a security vulnerability into the site? Never!

I don't agree with making candidates write algorithms they don't need to know in a format that they don't need to be able to write them, but I am in favour of testing candidates thoroughly.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: