Live data from Hacker News

XSS Twitter in minutes; Why you shouldn't store important data with 37signals

brian.mastenbrook.net

1–10 of 61 posts

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#3
You found a security exploit, feel special. Finding an exploit isn't a voucher to rant against the people responsible for it. The bottom line is that nobody can be 100% sure that their data is secure after they've put it in the hands of a third party.

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#4
post #3

You found a security exploit, feel special. Finding an exploit isn't a voucher to rant against the people responsible for it. The bottom line is that nobody can be 100% sure that their data is secure after they've put it in the hands of a third party.

I think my point was a lot more nuanced than you give it credit for.

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#5
post #3

You found a security exploit, feel special. Finding an exploit isn't a voucher to rant against the people responsible for it. The bottom line is that nobody can be 100% sure that their data is secure after they've put it in the hands of a third party.

The author did not claim anybody can expect or provide 100% security. The write-up was (among other things) about something more important - how do companies respond when presented with an important security issue. 37signals responded fairly poorly and that's useful information. Interestingly, this is not the first report of a somewhat strange attitude they seem to have regarding possible exploits -

http://evilpacket.net/2009/jul/9/basecamp-one-wrong-click/

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#6

For all the horrible, terrible, awful things about Internet Explorer (namingly: standards support and UI) ... they are innovating heavily in security: http://www.microsoft.com/windows/internet-explorer/features/...

Microsoft is actually decent at security now. The AV they released for free was actually on par with a few commercial products out there (all AV at the moment is pretty bad though, if you're curious). The really difficulty with Microsoft and security is countering their reputation for bad security that they earned over the past several years.

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#7
post #3

You found a security exploit, feel special. Finding an exploit isn't a voucher to rant against the people responsible for it. The bottom line is that nobody can be 100% sure that their data is secure after they've put it in the hands of a third party.

I didn't read the post as a rant at all. If anything I think that the author has articulated an important factor in evaluating any third party provider's security infrastructure: attitude.

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#8
post #6

For all the horrible, terrible, awful things about Internet Explorer (namingly: standards support and UI) ... they are innovating heavily in security: http://www.microsoft.com/windows/internet-explorer/features/...

Microsoft is actually decent at security now. The AV they released for free was actually on par with a few commercial products out there (all AV at the moment is pretty bad though, if you're curious). The really difficulty with Microsoft and security is countering their reputation for bad security that they earned over the past several years.

That's because Microsoft is good at anything that they throw resources at. Unfortunately, we haven't thrown enough resources at determining what to throw resources at.

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#9
post #6

Earlier quoted context omitted.

Microsoft is actually decent at security now. The AV they released for free was actually on par with a few commercial products out there (all AV at the moment is pretty bad though, if you're curious). The really difficulty with Microsoft and security is countering their reputation for bad security that they earned over the past several years.

That's because Microsoft is good at anything that they throw resources at. Unfortunately, we haven't thrown enough resources at determining what to throw resources at.

Well, good enough at least. ;-) Honestly the AV was a good move. Give stuff like that away for free for long enough and the public perception of Microsoft and security may change.

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#10
Can someone help to compile a good security policy and guideline for web apps?

I guess every web app should have a page dedicated to security similar to privacy policy and terms of service.

What are the essential information should go there? Special email dedicated to report security issues? PGP key to encrypt emails? and What else?

Post reply on HN