Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The mistake betrays so much incompetence that there is really no way for me to trust anything they ever do again. The other mistakes they make might not be quite so easy to find.


I don't think hack-shaming accomplishes anything.

Just yesterday we had someone publish a "securely delete your email" application. 'tptacek found problems in it immediately[1], but he didn't call the guy incompetent or an idiot or "never trust anything he does again." There was no attempt to shame.

I see the more experienced people around here have a lot more sympathy for these guys. If you've done a lot, you've also had some public mistakes. You grow empathy.

I do find the company's follow-up offensive. Hopefully they will learn from that, as well.

[1]http://news.ycombinator.com/item?id=4614474


The thread in question involved a few broad oversights in a tool, not an immediate disclosure due to a trivial oversight. There's a difference between not generating random numbers correctly and immediately disclosing every AWS key you've been given.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: