TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

A Funny Thing Happened on the Way to Coursera

124 pointsby boynamedsueover 10 years ago

6 comments

frankchnover 10 years ago
Here is Coursera&#x27;s official response: <a href="http://blog.coursera.org/post/96686805237/response-to-reported-vulnerability-in-instructor-access" rel="nofollow">http:&#x2F;&#x2F;blog.coursera.org&#x2F;post&#x2F;96686805237&#x2F;response-to-report...</a>.<p>We have already implemented fixes and mitigation strategies for all of the vulnerabilities - including completely disabling type-ahead hinting for email address on our instructor interfaces (instructors must now enter the complete email address of a learner in order to manually enroll him or her in the instructor&#x27;s course) and rate limiting and referrer header checking on APIs to slow down and stop enumeration attacks by third parties to discover learner enrollment status for courses.<p>Finally, we would like to thank Dr. Mayer for reporting these security problems and helping us make Coursera a more secure and privacy conscious platform for our learners.
empressplayover 10 years ago
Tech debt is like monetary debt -- you still have to pay it back, and quick. When it&#x27;s security &#x2F; API related debt, you have to pay it back even quicker, because if you don&#x27;t, someone inevitably forecloses on your metaphorical house and repossesses your metaphorical car.
评论 #8272422 未加载
yeukhonover 10 years ago
&gt; I reported the issue to Coursera on Sunday, and I have not yet received a response. Possible remediation steps include rate limiting (again), referrer checking, and configuring APIs to always return the same HTTP status.<p>Wouldn&#x27;t the 2nd issue (the cross-origin data leak) be better off solved by having a CSRF token instead?
评论 #8272229 未加载
javertover 10 years ago
Accepting a role in an organization, only to turn around and immediately publicly humiliate and embarass them (for no good reason[1]), is just about the biggest dick move one can make.<p>I hope this guy finds his 5 seconds in the limelight to be worth sacrificing his common decency to.<p>[1] Because they appear to be in the process of addressing the issues in a timely manner.
评论 #8272628 未加载
ivanhoeover 10 years ago
Hiding the IDs doesn&#x27;t have to be a security feature at all. Maybe they just didn&#x27;t want to publicly show how many students they&#x27;ve got, simply for marketing reasons?
评论 #8272784 未加载
magicarpover 10 years ago
Was Coursera contacted before this was published?
评论 #8272099 未加载