Skip to main content

Tumblr blames ‘human error’ for weekend security lapse

Tumblr LogoPopular blogging service Tumblr has cited “human error” as the cause behind a security glitch that may have revealed users’ passwords, API keys, IP addresses and other personal data.

The alarm was sounded Saturday morning via Twitter. “OMG…The Tumbeasts are spitting out passwords!,” the tweet read. The news quickly spread, with armchair hackers taking to forums to debate the extent and cause of the glitch. As it turns out, a PHP coding error was likely to blame for 748 lines of information being made visible.

Recommended Videos

Tumblr responded quickly to fix the problem and followed up with an official statement posted about five hours later. Here’s what Tumblr had to say for itself:

“A human error caused some sensitive server configuration information to be exposed this morning. Our technicians took immediate measures to protect from any issues that may come as a result.

We’re triple checking everything and bringing in outside auditors to confirm, but we have no reason to believe that anything was compromised. We’re certain that none of your personal information (passwords, etc.) was exposed, and your blog is backed up and safe as always. This was an embarrassing error, but something we were prepared for.

The fact that this occurred at all is still unacceptable, and we’ll be seriously evaluating and adjusting our processes to ensure an error like this can never happen again.”

The explanation was likely enough to assuage the fears of Tumblr loyalists, but on the Hacker News forum a contingent was left unconvinced that the breech was merely “an embarrassing error.”

Some commentators went as far as to blame Tumblr for “criminal negligence.” Others were content to point a finger at the idiosyncrasies of the PHP programming language. A few defended Tumblr, saying that the breach wasn’t as severe as it was made out to be. Either way, Tumblr had dozens of sideline developers offering their debugging expertise pro bono.

In December, Tumblr was taken offline for almost a full day following an issue with its database cluster.


Topics
Aemon Malone
Former Digital Trends Contributor
Windows 11 can now run on unsupported systems, but there’s a catch
A laptop sits on a desk with a Windows 11 wallpaper.

Microsoft is now allowing users to update to Windows 11 on older, unsupported hardware, including systems that don’t meet the operating system’s strict hardware requirements.

While the company initially set these requirements — including the need for a TPM 2.0 chip and specific processor models — to ensure performance, reliability, and security, it has now provided a manual installation option for those who want to use Windows 11 on unsupported machines.

Read more
This little retro gaming monitor is seriously adorable
JapanNext gaming monitor on a desk.

If you like themed products and interesting designs, this new retro-style monitor from Japannext (JN-V236G180F-RETRO) has everything you could want. Spotted by Tom's Hardware, it aims to blend nostalgia with modern technology to make a fun product complete with the perfect gimmick -- you can watch or play anything you want in monochrome.

In terms of specs, it hardly qualifies as of the best gaming monitors, but that isn't really a deal breaker since the price is just 20,000 yen (around $200). It's a 23.6-inch panel with a 16:9 aspect ratio, 1080p resolution, and 180Hz refresh rate. It has a 1ms response time, an sRGB gamut of 90%, and a DCI-P3 coverage of 80%, along with 300 nits of brightness.

Read more
One of ChatGPT’s latest features comes to the free tier
ChatGPT's Canvas screen

In October, OpenAI debuted its Canvas feature, a collaborative interface that visually previews the AI response to the user's writing or coding request. However, it was only made available as a beta feature for Plus and Teams subscribers. On Tuesday, the company announced that it is bringing Canvas to all users, even at the free tier.

While one could easily mistake Canvas for a blatant knockoff of Anthropic's Artifacts feature, OpenAI is also incorporating a swath of new capabilities into Canvas. For one, Canvas is now integrated directly into the GPT-4o model so that it runs natively within ChatGPT, eliminating the need to select it specifically from the model-picking list.

Read more