Skip to content

Comment on David E. Chen: Discovering the Heroku Vulnerabilityparent

Comments

Heroku should have filtered other processes out of view that were related to other user's dynos. I think they will fix that.

It was interesting to read how the author figured it out, and his point that he could run a bunch of reapers to steal the information.

Now, if the IT guy running Herkous operations has his hat on straight he will notice the change in bandwidth patterns (higher upload following a heroku push) from the reapers, which is what the Heroku press release alluded to.

Generally, to benefit maliciously you would have to be watching the content without downloading it ("by hand" if you will) and then find something that was worth the effort.

Now that Dynos have more time to be considered in a different light, design changes will at least make the same "lottery watch dog" effect harder to achieve than just lurking on node.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.