Skip to content

Comment on Exploiting filepicker.io

Comments

On it! We have a new security release coming out next week that allows the use of server-side secrets to lock down both uploads and reads. We've already contacted the author and are happy to work with anyone who is concerned and get them early access

Also, given the feedback, we're implementing a way to set the max file size on your developer portal. Fix should go out in the next 10-15 minutes

Took a bit longer to handle the edge cases, but we now have the max file size stopgap implemented. On your developer portal you can set the maximum size that you'll allow to be uploaded. We're still moving forward with the more fully-featured security functionality, but wanted to make this available ASAP

This is great, but there isn't any indication of what units the max filesize is using. Kilobytes or megabytes?

Oops! Sorry, bytes

So for 30 MB I should put in 30000000?

or 31457280

Your response time is awesome!

I'm about to implement filepicker.io for a project and really do not mind any kind of server-side integration that would avoid chances of malicious users abusing the service against our filepicker.io or S3 usage.

We take this stuff seriously. Great, shoot me an email at brett at filepicker.io and we can walk through how to get you set up on the new security scheme

Totally agree! Seeing that the Filepicker team is responsive to this kind of public feedback and are reaching out to the author in a appreciative and collaborative way speaks volumes about their character.

Even more excited to get Filepicker implemented now!

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.