Earlier quoted context omitted.
What’s the point? To save money paying a human to man a support email. That human would have also been hopelessly uninformed for all the same reasons.
I could be the best money saver for them - and ask for a hefty premium for my services - by terminating all support. No costs, nada, full save! Genius, right?! Never gives false info, never! Ok, ok, need to have a tickmark next to the 'support' item in the quarterlies, let it be an eternal spinning wheel presenting on clicking the 'Our award winning instant support is HERE!' button then. Its close to the real experie…
Web Security is Too Hard
71–80 of 127 posts
Re: Web Security is Too Hard
#72Re: Web Security is Too Hard
#73[1]: https://www.troyhunt.com/thanks-fedex-this-is-why-we-keep-ge...
Re: Web Security is Too Hard
#74Re: Web Security is Too Hard
#75Earlier quoted context omitted.
heh yeah I ran into this with one of the few times I used claude desktop. it had no idea what features it had and didn't have, where buttons were in the app, etc. isn't that kind of a core category of knowledge you'd want the chatbot to know?
in my experience, usually it knows this (it is in the system prompt) but it can still get confused. Especially with skills for example, some skills might only work in claude code/outside of sandbox or in desktop but not on web. And it would sometimes not know if it was on the web or desktop.
Re: Web Security is Too Hard
#76Web Developers, please follow every best practice, I’m begging you Marketing people just make bunch of marketing domains. Business people push all kind of BS ideas. No one is asking Web Developers about their opinion man. STOP making everything developers fault.
Re: Web Security is Too Hard
#77Earlier quoted context omitted.
Why is this so, so common? They're subdomains. They're free. It's not hitting anybody's budget to publish a new DNS entry. If someone has permission to publish anything in your name, they probably should be able to go make themselves a subdomain.
Because they point foo.example.com to AWS. They then let whatever the CNAME is pointing to lapse. Then an attacker registers the lapsed AWS and can now put their content on your trusted domain. https://aws.amazon.com/blogs/security/threat-tactic-spotligh... (AWS have since fixed this problem, but it exists on other services.)
Re: Web Security is Too Hard
#78 The Cloudflare folks apparently want security issues reported via HackerOne (which wouldn’t let me log in because the Cloudflare CAPTCHA HackerOne uses seems to be broken…).
That's just goldRe: Web Security is Too Hard
#79This isn't a secfail. Why is pay.cloudflare.com so hard to establish? Why does marketing always get to overpower engineering? I expect Cloudflare services to avoid some sketchy .pay TLD for exactly the reasons this person went through.
Presumably the big scary sysadmins have access to the *.cloudflare.com DNS records, and marketing just needs to push this thing right now and can't wait, so it's easier for them to buy a new domain with a shiny new TLD than wait for pay.cloudflare.com to be authorised. cloudflare.com/pay probably has a similar chain of approval: if every marketing idea had its own top-level route, it would get pretty crazy with such…
Re: Web Security is Too Hard
#80What a ride of a read. I was 100% it was phishing and I got really surprised to find out it wasn't.