TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Buffer: Bug in Login System

10 点作者 chmars将近 6 年前
I have just received the following e-mail from Buffer:<p>Hi there,<p>We wanted to proactively reach out to you about a bug in our login system that we identified on Friday and resolved over the weekend.<p>This bug affected 0.00599% of Buffer users (467 out of 7,800,000), and we have reached out to those 467 people separately.<p>When a user logs in, we create an access token that secures their login and gives them access to Buffer. We identified a bug with this login system that made it possible in very rare cases for two accounts to share one access token. This would cause one of those Buffer users to log in to the incorrect account.<p>This issue is fully resolved. Our team has implemented a more secure system for granting these tokens, which ensures that all account access is private, safe, and secure.<p>To be especially clear: No passwords were compromised. No credit card details were at risk. This was a technical bug within our system and not a malicious event or hack from an outside party.<p>We’ve taken precautions to upgrade all Buffer accounts to our new login system. If you use a Buffer mobile app, you will need to log back in; if you use a third party app (like Zapier), you will need to reconnect.<p>Lastly, I’d like to send a big thank you to the customer who made us aware of this. We’re always amazed by the community we get to serve.<p>Photo of Dan. Dan Farrelly, CTO

3 条评论

uri3000将近 6 年前
How can this even happen, technically?
评论 #20569779 未加载
评论 #20571517 未加载
tnolet将近 6 年前
My only question is why they built their own login system? Isn&#x27;t this a golden rule: never build your own auth.
评论 #20566114 未加载
评论 #20566006 未加载
评论 #20566008 未加载
评论 #20566831 未加载
jamespetercook将近 6 年前
I got this email too
评论 #20567807 未加载
评论 #20568821 未加载