Live data from Hacker News

Web Security is Too Hard

textslashplain.com

111–120 of 127 posts

Re: Web Security is Too Hard

#111
post #55
post #11

In the movie Sneakers, a whole scene is taken up sending some guy on a date with Mary McDonnell so she could record clips of his voice. Today she'd just need a phone call or his Instagram. It's getting harder to keep up with who _people_ are online, much less organizations and domain names. Identity is hard y'all.

I don't understand what your point is. Do you disagree with any of the concrete suggestions in the blog post about what should have been done differently, or do you think they're hard to follow?

The blog’s suggestions are fine. I’m pointing out that this issue is less about “security” and more a problem of “identity”.

And that such issues with identity are likely to increasingly be a problem.

Re: Web Security is Too Hard

#112
post #48
post #28

Earlier quoted context omitted.

If you have no training or knowledge-base to search, sure. But then you'd be an awful support-team employer.

I mean, yes? That sounds pretty accurate for most companies before chatbots became the new hot thing

The vast majority of people I know who have done phone/chat support have had a spreadsheet (or fancier tool) of common phrases and mandatory boilerplate answers, an overview of the company they're doing it for (sometimes just a couple pages in a word doc), and tone/tool training at a minimum. And generally that tool has a tree of common steps that are also generally mandatory, because they punish rather harshly for going off-script. It's not much, and it gets you the sort of support that people often think of with ticketing systems: impersonal and inaccurate, favoring the company.

But it's rarely this inaccurate. Or if it is (e.g. missing a major product launch), it's fixed in a day or two.

Re: Web Security is Too Hard

#113
post #75
post #69

Earlier quoted context omitted.

in my experience, usually it knows this (it is in the system prompt) but it can still get confused. Especially with skills for example, some skills might only work in claude code/outside of sandbox or in desktop but not on web. And it would sometimes not know if it was on the web or desktop.

The next AI benchmark is can an agent understand the product suite of its creators.

That would be an amusing test with AWS.

Re: Web Security is Too Hard

#114

At one point in the article, the author asks Cloudflare's bot if they're launching a Wallet product, and it says no. > There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt. What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?

Half the time, those bots don't even respond

Re: Web Security is Too Hard

#115

This isn't a secfail. Why is pay.cloudflare.com so hard to establish? Why does marketing always get to overpower engineering? I expect Cloudflare services to avoid some sketchy .pay TLD for exactly the reasons this person went through.

> Why is pay.cloudflare.com so hard to establish? An engineer who vibes up a marketing site, and attempts to put it on the same origin as *.cloudflare.com now has to jump through 1,000 hoops of security clearance, customer notifications, etc. > `pay.cloudflare.com` can't be launched because it doesn't have the proper WAF preventing 25 year old Wordpress exploits, please make sure pay.cloudflare.com/wp-admin.php is bl…

Probably half those problems are SOP/CORS, which gets in the way in exchange for a false sense of security. I'm on board with ditching that. Websockets already did. (Cookies should still adhere to SOP though.)

Re: Web Security is Too Hard

#116
post #102

Cosmically I feel like the HTTPS certificate on Cloudflare.pay should provide sufficient info to confirm it's the same entity behind Cloudflare.com

How would that association be shown to the user? Currently we're trained to check that the domain name is the same.

Re: Web Security is Too Hard

#117
post #84

Earlier quoted context omitted.

Who made the website?

Dies it matter? Im sitting on the ops end of this myself right now where marketing purchased something like 15 new domains on Godaddy and both me and the Web developers that built the new site found it the new product will live on those domains and launches today. This is an entirely normal experience across every org ive worked in and unless im also surprise promoted to cto today I do not have an ability to question…

I had marketing close their godaddy account and centralized the domain request flow to the ops team, for security reason.

One of the best workflow changes ever implemented, didn't even need to become CTO.

Re: Web Security is Too Hard

#118
Security in general is hard.

It starts on developers own machines, which programming languages get used, how dependencies are added to the projects, how testing is done, how code gets written, how inputs and current user roles get validated.

All of this before even exposing the application to a BSD socket.

Re: Web Security is Too Hard

#119
post #27

Earlier quoted context omitted.

I could be the best money saver for them - and ask for a hefty premium for my services - by terminating all support. No costs, nada, full save! Genius, right?! Never gives false info, never! Ok, ok, need to have a tickmark next to the 'support' item in the quarterlies, let it be an eternal spinning wheel presenting on clicking the 'Our award winning instant support is HERE!' button then. Its close to the real experie…

To avoid wasting customer time, simply make that button close the window.

That's even better! They can start a complaint about the button by contacting the support, of course.

Re: Web Security is Too Hard

#120
post #76
post #44

Web Developers, please follow every best practice, I’m begging you Marketing people just make bunch of marketing domains. Business people push all kind of BS ideas. No one is asking Web Developers about their opinion man. STOP making everything developers fault.

Who do we call? CTOs I guess.

Ghostbusters!
Post reply on HN