wolffyluna: A green unicorn holding her tail in her mouth (Default)
[personal profile] wolffyluna
So, you know how pillowfort.io had some security down time a little while ago? That was roughly when I went from 'ooh, I should buy a key some time' to '...let's wait and see.' Mostly because I'm not a security expert, and I didn't know the details, so I wasn't sure if they were caught out by something weird, or if this was a moonpig level You Should Have Predicted This sorta security issue.

Turns out, it looks like it was the latter!

Which, gee, oof. I mean, yay my instincts, for predicting it'd be this sort of thing-- but oooooof.

Yeah, so definitely not going to pillowfort until they've at least done some more pentests.

Date: 2018-12-19 05:01 am (UTC)
zenolalia: A lalafell wearing rabbit ears stares wistfully into the sunset, asking Yoshi-P when male viera will come back from the war. (Default)
From: [personal profile] zenolalia
They've got to get a legal team sooner than later, because the second an EU user tries to press charges under the GDPR, they're extremely fucked.

I really, really want to like pillowfort, I really do, but they've been having a lot of "missteps" over the last few weeks.

Date: 2018-12-19 11:40 pm (UTC)
zenolalia: A lalafell wearing rabbit ears stares wistfully into the sunset, asking Yoshi-P when male viera will come back from the war. (Default)
From: [personal profile] zenolalia
I do want to believe in them. But the entire set of problems just screams, "group of college freshmen got together and decided to make a social media website as a fun friend-time activity and did NOT think it through at all."

Like, there's a really persistent level of naivete involved in all of these choices they keep making.

Date: 2018-12-19 12:29 pm (UTC)
tornir: A silhouette of a horned viking helmet in a red circled prohibition sign. (No Spam)
From: [personal profile] tornir
After it was taken down, the 503 page announced to the world they were using a four year old web server.
The server's dev site lists every patched vulnerability, and the versions affected by it; Black Hat shopping list. :(
I don't know if they've patched that (I don't even know if they can), but I too have adopted a '...let's wait and see.' policy, while hoping my friends who haven't don't get burned.

Date: 2018-12-20 12:54 pm (UTC)
tornir: A silhouette of a horned viking helmet in a red circled prohibition sign. (No Spam)
From: [personal profile] tornir
Humble have a book bundle these guys should really get, and it'd only cost them three keys.

Date: 2018-12-19 08:16 pm (UTC)
lady_kishiria: (Default)
From: [personal profile] lady_kishiria
Yeah, I was going to get a Pillowfort code and held off for the same reasons you did.

Date: 2018-12-20 05:48 pm (UTC)
lb_lee: Raige making a horrified face. (D:)
From: [personal profile] lb_lee
I admit, I have had no interest in pillowfort, but this has just made me feel better about it. Lately my biggest concerns about my website use is security stuff.

I think I'm basically just going to try and camp out here.

Profile

wolffyluna: A green unicorn holding her tail in her mouth (Default)
wolffyluna

March 2026

S M T W T F S
12 34567
891011121314
15161718192021
22232425262728
293031    

Style Credit

Expand Cut Tags

No cut tags
Page generated Mar. 22nd, 2026 04:08 am
Powered by Dreamwidth Studios