Feed Sign in with OpenID OpenID

Simon Willison’s Weblog

3 items tagged “metafilter”

Popular Websites Vulnerable to Cross-Site Request Forgery Attacks. Ed Felten and Bill Zeller announce four CSRF holes, in ING Direct, YouTube, MetaFilter and the New York Times. The ING Direct hole allowed transfer of funds out of a user’s bank accounts! The first three were fixed before publication; the New York Times hole still exists (despite being reported a year ago), and allows you to silently steal e-mail addresses by CSRFing the “E-mail this” feature. 0 29th September 2008, 1:08 pm

The problem of grues is, of course, their recursive nature. To wit: A) Grues are found wherever it is very dark. B) There are no light sources on the inside of a grue. Therefore, being eaten by a grue is a fate which entails being eaten by an infinite number of progressively smaller grues, presumably nested in a geometrically complicated and interesting way.

Arturus 0 13th April 2008, 2:40 am

Flickr users are marked as such in the Yahoo user database. What this means is that the account is permanently protected from deletion, even if you cancel your SBC-Yahoo DSL and even if you never check your Yahoo Mail (if you elect to have one). Both free and pro accounts are protected. And your Yahoo signon name will not be displayed anywhere on Flickr -- your existing Flickr username will stay the same.

crawl on MeFi 0 31st January 2007, 10:27 pm

A django site