Live data from Hacker News

Web Security is Too Hard

textslashplain.com

71–80 of 127 posts

Re: Web Security is Too Hard

#71
post #27

Earlier quoted context omitted.

What’s the point? To save money paying a human to man a support email. That human would have also been hopelessly uninformed for all the same reasons.

I could be the best money saver for them - and ask for a hefty premium for my services - by terminating all support. No costs, nada, full save! Genius, right?! Never gives false info, never! Ok, ok, need to have a tickmark next to the 'support' item in the quarterlies, let it be an eternal spinning wheel presenting on clicking the 'Our award winning instant support is HERE!' button then. Its close to the real experie…

To avoid wasting customer time, simply make that button close the window.

Re: Web Security is Too Hard

#75
post #69

Earlier quoted context omitted.

heh yeah I ran into this with one of the few times I used claude desktop. it had no idea what features it had and didn't have, where buttons were in the app, etc. isn't that kind of a core category of knowledge you'd want the chatbot to know?

in my experience, usually it knows this (it is in the system prompt) but it can still get confused. Especially with skills for example, some skills might only work in claude code/outside of sandbox or in desktop but not on web. And it would sometimes not know if it was on the web or desktop.

The next AI benchmark is can an agent understand the product suite of its creators.

Re: Web Security is Too Hard

#76
post #44

Web Developers, please follow every best practice, I’m begging you Marketing people just make bunch of marketing domains. Business people push all kind of BS ideas. No one is asking Web Developers about their opinion man. STOP making everything developers fault.

Who do we call? CTOs I guess.

Re: Web Security is Too Hard

#77
post #43

Earlier quoted context omitted.

Why is this so, so common? They're subdomains. They're free. It's not hitting anybody's budget to publish a new DNS entry. If someone has permission to publish anything in your name, they probably should be able to go make themselves a subdomain.

Because they point foo.example.com to AWS. They then let whatever the CNAME is pointing to lapse. Then an attacker registers the lapsed AWS and can now put their content on your trusted domain. https://aws.amazon.com/blogs/security/threat-tactic-spotligh... (AWS have since fixed this problem, but it exists on other services.)

[deleted]

Re: Web Security is Too Hard

#79
post #64

This isn't a secfail. Why is pay.cloudflare.com so hard to establish? Why does marketing always get to overpower engineering? I expect Cloudflare services to avoid some sketchy .pay TLD for exactly the reasons this person went through.

Presumably the big scary sysadmins have access to the *.cloudflare.com DNS records, and marketing just needs to push this thing right now and can't wait, so it's easier for them to buy a new domain with a shiny new TLD than wait for pay.cloudflare.com to be authorised. cloudflare.com/pay probably has a similar chain of approval: if every marketing idea had its own top-level route, it would get pretty crazy with such…

Google manages it though. And you could have a labs.cloudflare.com/idea and make it easy to add new ideas internally.

Re: Web Security is Too Hard

#80

What a ride of a read. I was 100% it was phishing and I got really surprised to find out it wasn't.

I thought it wouldn't be as I assume :) CloudFlare scans for new tld and either gets in the sunrise period or at a minimum objects to anyone else registering a straight CloudFlare.tld. But CloudFlarepay.com or cl0udflar3.com have more scam risk.
Post reply on HN