LJ staff are claiming to have fixed the bug in their new release that was showing some users other people's locked entries.

However, they are referring to the problem has having lasted 3 minutes, when reports were for at least 24 hours, and saying it was not a security problem. This is not most users' idea of "not a security problem"; at best, it's a less serious problem than if people had also been able to edit or delete random other people's entries. (People also seem unhappy about some of the things that this new release is doing by design.)
mneme: (Default)

From: [personal profile] mneme


I see why they said it wasn't security problem, because there wasn't the possibility of data-manipulating intrusion. It's not unreasonable for them to internally differentiate between privacy breaches and issues that comprimise the data on the site.

But...it was certainly a -data- security problem, so using that particular phrasing was just a terrible, terrible idea even if it fits their internal terminology.
.

About Me

redbird: closeup of me drinking tea, in a friend's kitchen (Default)
Redbird

Most-used tags

Page summary

Powered by Dreamwidth Studios

Style credit

Expand cut tags

No cut tags