Tell HN: Fiverr left customer files public and searchable
Fiverr left customer files public and searchable due to using public URLs for sensitive client-worker communication. This exposed hundreds of files containing PII in Google search results. Fiverr bought Google Ads for keywords related to sensitive work products despite this issue. This violates the GLBA/FTC Safeguards Rule. The issue was reported to Fiverr's security team 40 days ago but received no response.