Live data from Hacker News

Web Security is Too Hard

textslashplain.com

21–30 of 127 posts

Re: Web Security is Too Hard

#21
Web security wasn't hard before we started trying to make the web a platform for full executable software.

I never got hacked through the web before JavaScript (never got hacked after either, yet, but it wasn't really possible in the same way to hack someone through the web without some way to execute program logic, which in the old days would have required a much more specific browser exploit to gain RCE).

JavaScript was a mistake. Everything else after that involves "running code in the browser" was a mistake.

Program execution needs to be completely separate from "the web". I don't want any code of any sort running in my browser, at least not any that I don't fully control. "The web" was never designed to be an application platform. It was only designed to be a document platform.

Re: Web Security is Too Hard

#22

Cloudflare is your favorite company and they are geniuses? Dear Diary, Today my fanboy bubble was burst. Signed, Author

Note that I said: "One of my", and Cloudflare has hired a HUGE percentage of the best networking talent I've encountered.

Re: Web Security is Too Hard

#23

At one point in the article, the author asks Cloudflare's bot if they're launching a Wallet product, and it says no. > There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt. What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?

The point is to signal to investors that they're all-in on the current fad, thus making the stock price go up.

Re: Web Security is Too Hard

#25

At one point in the article, the author asks Cloudflare's bot if they're launching a Wallet product, and it says no. > There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt. What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?

What’s the point? To save money paying a human to man a support email. That human would have also been hopelessly uninformed for all the same reasons.

> That human would have also been hopelessly uninformed for all the same reasons.

Not really. At minimum, a half-way decent support person would ask a few people internally or search Slack before answering.

In fact, they would have likely already heard about the new product at lunch or something.

Re: Web Security is Too Hard

#26
post #22

Cloudflare is your favorite company and they are geniuses? Dear Diary, Today my fanboy bubble was burst. Signed, Author

Note that I said: "One of my", and Cloudflare has hired a HUGE percentage of the best networking talent I've encountered.

Another company named Cisco used to do that. They built the Great Firewall of China. Hiring talent does not equal good company.

Re: Web Security is Too Hard

#27

At one point in the article, the author asks Cloudflare's bot if they're launching a Wallet product, and it says no. > There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt. What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?

What’s the point? To save money paying a human to man a support email. That human would have also been hopelessly uninformed for all the same reasons.

I could be the best money saver for them - and ask for a hefty premium for my services - by terminating all support. No costs, nada, full save! Genius, right?! Never gives false info, never!

Ok, ok, need to have a tickmark next to the 'support' item in the quarterlies, let it be an eternal spinning wheel presenting on clicking the 'Our award winning instant support is HERE!' button then. Its close to the real experience anyway, right?

Re: Web Security is Too Hard

#28

At one point in the article, the author asks Cloudflare's bot if they're launching a Wallet product, and it says no. > There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt. What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?

What’s the point? To save money paying a human to man a support email. That human would have also been hopelessly uninformed for all the same reasons.

If you have no training or knowledge-base to search, sure. But then you'd be an awful support-team employer.

Re: Web Security is Too Hard

#29
post #3

Another entry in "Marketing department starts a promotion campaign for the new product that's indistinguishable from a phishing attack" list. Starting with not using a subdomain on your own, very well-known domain but instead using a completely different one, then not having it shown with the rest of your services on your main web site, et cetera.

You really would think that at least in theory a company like Cloudflare would make it very easy for internal teams to automatically request new subdomains

Running marketing off a separate domain is often a conscious decision because if they start getting blocked for spam, then critical service/operational emails from your actual domain might also get blocked.

Re: Web Security is Too Hard

#30

At one point in the article, the author asks Cloudflare's bot if they're launching a Wallet product, and it says no. > There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt. What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?

What’s the point? To save money paying a human to man a support email. That human would have also been hopelessly uninformed for all the same reasons.

[deleted]
Post reply on HN