Live data from Hacker News

Web Security is Too Hard

textslashplain.com

91–100 of 127 posts

Re: Web Security is Too Hard

#91

Cloudflare seems to be trying to do EVERYTHING.

Every company has to try to do everything, before any other company does, especially related ones.

It's why Valve moved into OSes and hardware. If they didn't, Microsoft were holding a nuclear bomb over their heads. It's why Google has a phone platform, because Apple has been replacing the Google apps one-by-one. It's also why Samsung has a parallel suite of apps to the Google ones. It's why the pizzeria makes fries, because they're threatened by the fry shop across the street starting to serve pizza. It's why Uber tried to make self driving taxis. It would be good if the fry shop made only the best fries and the pizza shop made only the best pizza and Valve made only the best game store and Microsoft made only the best OS, but it's a very unstable equilibrium. Does your ISP still give you an email address?

Re: Web Security is Too Hard

#92
post #38

Earlier quoted context omitted.

Another company named Cisco used to do that. They built the Great Firewall of China. Hiring talent does not equal good company.

I hadn't read that so I looked it up to verify, and it appears true: https://www.eff.org/deeplinks/2016/04/ciscos-latest-attempt-... Cisco looks to have made money from repression and torture. Meanwhile a large fraction of neo-nazis, credit card thieves, and DDoS-for-hire sites are on Cloudflare. It takes serious talent (not morals) to attack humanity at scale.

> sites are on Cloudflare

And robbers can hire cars, buy battery angle grinders, and charge the batteries from the electricity network then drive on roads to your house.

Are Cloudflare supposed to be the police?

Does the UN provide a registry list of criminal domains that should not be livened?

Re: Web Security is Too Hard

#93
post #21

Web security wasn't hard before we started trying to make the web a platform for full executable software. I never got hacked through the web before JavaScript (never got hacked after either, yet, but it wasn't really possible in the same way to hack someone through the web without some way to execute program logic , which in the old days would have required a much more specific browser exploit to gain RCE). JavaScri…

> "The web" was never designed to be an application platform. It was only designed to be a document platform. And then it expanded to serve the needs of billions of people instead of the needs of a few researchers. Womp, womp. Get over it, use a JS-free browser to browse your documents, and accept that the world has moved on. Or don't, and rant at clouds, I guess.

You realize the same argument applies to Word macros.

Re: Web Security is Too Hard

#94
post #38

Earlier quoted context omitted.

Another company named Cisco used to do that. They built the Great Firewall of China. Hiring talent does not equal good company.

I hadn't read that so I looked it up to verify, and it appears true: https://www.eff.org/deeplinks/2016/04/ciscos-latest-attempt-... Cisco looks to have made money from repression and torture. Meanwhile a large fraction of neo-nazis, credit card thieves, and DDoS-for-hire sites are on Cloudflare. It takes serious talent (not morals) to attack humanity at scale.

Doesn't even matter who CF is hosting - the fact they're sending all our HTTP requests to the NSA should be enough reason already!

Re: Web Security is Too Hard

#95
post #75
post #69

Earlier quoted context omitted.

in my experience, usually it knows this (it is in the system prompt) but it can still get confused. Especially with skills for example, some skills might only work in claude code/outside of sandbox or in desktop but not on web. And it would sometimes not know if it was on the web or desktop.

The next AI benchmark is can an agent understand the product suite of its creators.

That would clearly be superhuman intelligence, as I suspect the employees would struggle with that one.

Re: Web Security is Too Hard

#96
post #84
post #44

Web Developers, please follow every best practice, I’m begging you Marketing people just make bunch of marketing domains. Business people push all kind of BS ideas. No one is asking Web Developers about their opinion man. STOP making everything developers fault.

Who made the website?

Dies it matter? Im sitting on the ops end of this myself right now where marketing purchased something like 15 new domains on Godaddy and both me and the Web developers that built the new site found it the new product will live on those domains and launches today.

This is an entirely normal experience across every org ive worked in and unless im also surprise promoted to cto today I do not have an ability to question it.

Re: Web Security is Too Hard

#97
post #66
post #50

It looks like they've updated the cloudflare.pay site to link to the blog post on cloudflare.com that introduces wallets. So they fixed it on the same day they launched. That's not too bad, in my book.

I mean, what would stop someone from registering mycloudflare.pay and doing the same thing? Having the link in the other direction seems like what matters more

I mentioned it because the blog post itself links back to cloudflare.pay. Of course just linking to a blog post is useless.

Re: Web Security is Too Hard

#98

At one point in the article, the author asks Cloudflare's bot if they're launching a Wallet product, and it says no. > There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt. What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?

heh yeah I ran into this with one of the few times I used claude desktop. it had no idea what features it had and didn't have, where buttons were in the app, etc. isn't that kind of a core category of knowledge you'd want the chatbot to know?

Things like this change fast, it has a skill it can use now to find out. I'm not sure when they added it, I only noticed it last week.

Re: Web Security is Too Hard

#99
post #84
post #44

Web Developers, please follow every best practice, I’m begging you Marketing people just make bunch of marketing domains. Business people push all kind of BS ideas. No one is asking Web Developers about their opinion man. STOP making everything developers fault.

Who made the website?

Who designed the customer flow?

In TFA there is no single issue of actual things that web developers could be blamed for.

CSP not mentioned I assume it was correctly configured, site has https, site is using SSO from providers not storing passwords.

All security failures in this instance are stemming from bad customer flow, using silly domain, even "poorly placed" security element was most likely designed to be in that place by some designer not any web developer. While all the other things done by a business/marketing/UX and I bet Cloudflare has loads of cybersecurity people who should be asked to review the customer flow and not a web developer.

Re: Web Security is Too Hard

#100
post #83

At one point in the article, the author asks Cloudflare's bot if they're launching a Wallet product, and it says no. > There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt. What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?

The point is to show how AI you are.

Why would Cloudflare want to lose credibility and reputation though? Doesnt seem to make sense.
Post reply on HN