Thanks for your valuable comment and advise. I appreciate it. Definitely something to be learnt here.
HN user
benhomie
I assume what Ben meant was that it's impossible to implement reCAPTCHA entirely in an API. The nature of reCAPTCHA requires you to have a UI element, which would be impossible in an API.
That’s exactly what I meant. Thanks for picking up on this.
The fact that attackers are exploiting this in the wild seems to be the most salient point, but I'm not sure that Ben knew that from the correspondence shown.
I know that and hence was working on a fix for the next update.
Even though some of my comments may not be in agreement with the author, but I did mentioned in my email conversation that I am looking into it. But of course that was being left out of the post, no screenshots of that comment was found in the author’s post.
If I had released the next update without addressing this issue then yes feel free to write a post with these accusations. But I wasn’t given the benefit of the doubt.
An update of Sendy had just been released to address the reCAPTCHA issue → https://sendy.co/get-updated
I am the author of Sendy.
There are a lot of miscommunication between me and the author of this post. The selected snippets of messages posted on the article seem to put me in a bad light, however it's only one side of the story. The selected messages posted on the article are ones that are favorable to his argument. For example the author did not post a screenshot of me saying that I will be looking into this but went ahead to write an elaborate blog post immediately to put Sendy in an unfavourable light.
Bugs and issues with security has been and always will be the top priority with Sendy over the years. I agree the client side parameter 'subform' bypasses the reCAPTCHA and should be fixed. It is an oversight. And it will be fixed.
I was pretty shocked when I saw this article, didn't think about it much other than to share it. Glad that this isn't true, thanks for all the verifications.
This has been fixed. A CA certificate bundle is now included in the build for curl to check against when connecting to SSL enabled URLs, so there'll be no more certificate errors even if a default CA certificate bundle isn't available on the server. Also, user inputs are sanitized, the code posted there are from an older version of Sendy. Thanks for the heads up.
You can have a unique link for the lightbox simply by using a query string to automatically launch the lightbox.
Might have stole my heart from Fancybox.