Hacker Newsnew | past | comments | ask | show | jobs | submit | viaredux's commentslogin

Amazing. Love the dedication to fix this minor annoyance, which I also share. Would be great if there was a kind of universal tool for this, as I am sure many of those shitty apps share the same internals.


I also commented this, but I have to say their statement is false. The links to all the delivered projects are publicly accessible. I went over my orders and I could open every single one from another device, not logged in.


this is because copied the link with the token, token is generated for your logged in user. strip the token and it wouldn't work


Update: Fiverr denies allegations of a cybersecurity incident on X.

“To be clear, this is not a cyber incident. Fiverr does not proactively expose users’ private information. The content in question was shared by users in the normal course of marketplace activity to showcase work samples, under agreements and approvals between buyers and sellers. This type of content requires the buyer’s consent before it can be uploaded. As always, any request to remove content is handled promptly by our team.”


this is because you copied the link with the token, token is generated for your logged in user. strip the token and it wouldn't work. other users does not have your token.


You send the bearer token as a GET argument?

I’m sure there’s a good reason for that. I do it, in a server that I publish for general use, but won’t do it, for the server that I control, as I make sure that it reads headers.

Some PHP servers ignore auth headers (and, I suspect, other APIs), so you need to set general-purpose frameworks and servers to use GET arguments, but that’s a security issue, for exactly the reason you state. Too easy to leak logins. If you use headers, then copy and pasting URLs won’t leak logins.

In any case, the token should be timed, but that’s a fairly weak precaution.


That's true, I just checked. I will edit my post, thanks!


I have an account and I can confirm that the URL's of shared files are still publicly accessible. Google is giving 404's indeed.


Interesting. Did the URL scheme change with any expiry or signature params (like S3s X-Amz-Expires)?


I tried to alert other freelancers on Fiver Forums about htis, but my post got deleted on for 'violating community rules'. I don't see how it did violate the rules, suspicious to say the least.


I am a freelancer on Fiverr, this is VERY concerning. The amount of PII that I have sent over Fiverr, after sending NDA's is potentially all out in the public. I hope there will be accountability for this. IMO Fiverr has had terrible management for years! They simply do not care about their freelancers (and apparently also not about their customers).


Amazing that a company whose whole brand is based on hiring people for $5 turns out to not respect the workers who created value on their platform.


I get your criticism, however, there was a lot of talent working on the platform for many years. I was averaging 150 USD per project, significantly more than 5 USD.

Last year Fiverr started to push AI to the detriments of their freelancers, as well as a new "success score" metric, but never specifying how these metrics are calculated, making it very hard for freelancers to do something about it. This caused many accounts to "lose value" and thus rank lower on searches, causing a drop in income.

I've reported this on the Fiverr Freelancer Forums, let's see how long my post stays up...


> This caused many accounts to "lose value" and thus rank lower on searches

wouldn't this make some other accounts rank higher on searches then? I mean it couldn't have been a problem that affected absolutely everyone so for someone it must've been a positive change.


I assume it did not affect everyone indeed. However, a lot of "Top Rated" sellers, who were raking in good amounts of money saw their income fall drastically, while still providing the same quality of work. The only thing that changed was their Success Score being lower.

It's very hard to improve a metric when you don't know what are the criteria affecting the metric. I've reached out to Fiverr regaring this and they never bothered to tell anyone what impacted your Success Score. "Just do better", they told me.


There were also a ton of ArtIsts of the "Take the job, generate it with AI, throw the slop" rip and run kind of artistry.


Even before AI I remember reading that many of the "custom designed" logos on Fiverr were just ripoffs of existing trademarks.


There are sites where you can buy 200 different shape stencils for $100, and most logos are just those with text added.

When I found out years down the track that I paid like $1000 for a “premium experience” to be offered 6 or so stencils like this, I was pretty furious. Luckily, I picked none of them, and made the artist draw it exactly as I later described.


One founder of Fiverr's LinkedIn photo is in a racecar and posted about supply chain security a week ago.

The other also runs an insurance company (Lemonade) and just posted his drink to celebrate their 1B customers.

I never used their platform but tried a couple jobs on Upwork and drove Uber for 1000 trips. It is absolutely enraging how the CEO class lives day to day like they are some sort of "visionary" for taking a cut of other people's work while taking zero responsibility for even their own app's quality.

At one point the Uber app still told you to call a phone number for some support paths that had a recording telling you to use the app instead. Companies have systematically cut any kind of support, testing, and apparently security.

This also ties in nicely with the Delve debacle about how perfunctory those security certifications are.


Seems interesting, however, the article is behind a paywall.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: