Live data from Hacker News

Quora engineers accused of vandalizing a clone’s website

greyreview.com

11–20 of 59 posts

Re: Quora engineers accused of vandalizing a clone’s website

#11
Vandalism is a stupid word to use. I imagine the process went something like this: "I wonder what happens if I add $.fadeOut() as the text of the question" "Oh crap, it worked".

This is called experimentation. If you're in chemistry class and you mess up a lab, you're not accused of vandalizing apparatus... it's simply what happens when you are trying something out. Similarly, when you have a text box on a test website, someone is going to type something in, and if that causes the page to disappear, well... fix the bug and move on.

Re: Quora engineers accused of vandalizing a clone’s website

#12
post #9

[edit: Troll answers have been deleted, but you can still read the trolling comment thread: http://www.quora.com/Is-Qato-a-serious-Quora-clone-attempt/a... and http://www.quora.com/Is-Qato-a-serious-Quora-clone-attempt/a... ] On the Quora thread, http://www.quora.com/Is-Qato-a-Quora-clone-attempt-or-a-simi... there are some answers by trolls pretending to represent Qato. "Sameul Codsaw" writes: 'Also, we are using Ru…

Quora has a lot of passionate users.

Re: Quora engineers accused of vandalizing a clone’s website

#13
I just left the following comment:

-- It's pretty lame to copy the design and trade dress of another product. It does not bode well for your skill or ability.

Backstory: A long time ago I wrote Delicious. We had hundreds of copycats and competitors. The ones that weren't direct copies were the ones that did better.

I'm sure this doesn't apply to you for whatever reason.

Re: Quora engineers accused of vandalizing a clone’s website

#14
post #13

I just left the following comment: -- It's pretty lame to copy the design and trade dress of another product. It does not bode well for your skill or ability. Backstory: A long time ago I wrote Delicious. We had hundreds of copycats and competitors. The ones that weren't direct copies were the ones that did better. I'm sure this doesn't apply to you for whatever reason.

[deleted]

Re: Quora engineers accused of vandalizing a clone’s website

#15
post #5

I certainly don't think the Quora Engineers were right to vandalize the clones website in this case. I'm all about people making Q/A websites and releasing products that are clones of other products. Ideally this kind of competition can make the original product better. That being said, I find making a clone of someones product and then releasing said product at least in this sense, distasteful. Seeing that it has su…

Design clones are super lame.

Re: Quora engineers accused of vandalizing a clone’s website

#16

Vandalism is a stupid word to use. I imagine the process went something like this: "I wonder what happens if I add $.fadeOut() as the text of the question" "Oh crap, it worked". This is called experimentation. If you're in chemistry class and you mess up a lab, you're not accused of vandalizing apparatus... it's simply what happens when you are trying something out. Similarly, when you have a text box on a test websi…

Your chemistry class example is nonsensical. In class, if there is an opportunity to explore a few things and a mess is made, maybe you would not be blamed. That's usually not how labs are run--you follow a procedure and mixing chemicals with no forethought is a huge safety hazard to everybody in the lab. Neither the "real world" nor the Internet is a place with a mutual agreement between all participants to experiment with each other's property.

Maybe a better example would be going into your neighbor's backyard and testing how readily his shrubbery lights on fire. Oops, it's burning! Tell him to "fix the bug" and move on.

Re: Quora engineers accused of vandalizing a clone’s website

#17
Everyone's right that it was an ill-advised thing to do, but stepping back ignoring the law (I know..) and just asking yourself the gut question:

What's worse? injecting a relatively harmless script into the product (that frankly caused them to fix an issue that could have been very painful for them if someone more devious had found it first), or Qato's ripoff of Quora in the first place?

Re: Quora engineers accused of vandalizing a clone’s website

#18

Vandalism is a stupid word to use. I imagine the process went something like this: "I wonder what happens if I add $.fadeOut() as the text of the question" "Oh crap, it worked". This is called experimentation. If you're in chemistry class and you mess up a lab, you're not accused of vandalizing apparatus... it's simply what happens when you are trying something out. Similarly, when you have a text box on a test websi…

I disagree.

1. There are plenty of proof of concepts you can develop that don't destroy the page.

2. The Quora engineers in question didn't enter stuff into a textbox and leave it alone. They went and publicly disclosed a cross-site scripting vulnerability in a competitor's website.

Edit: Ben deleted his "answer" which disclosed the XSS. However, the comments on the answer are still accessible (for now) if anyone is curious about them: http://www.quora.com/Is-Qato-a-serious-Quora-clone-attempt/a...

Edit 2: Rick Ross posted a comment there I think is worth highlighting.

"In a way, we're grateful to these guys (Ben and Albert) for helping us close a hole. Their method of publicly vandalizing a test site and bragging about it is another matter. A simple email would have sufficed."

Re: Quora engineers accused of vandalizing a clone’s website

#19

Everyone's right that it was an ill-advised thing to do, but stepping back ignoring the law (I know..) and just asking yourself the gut question: What's worse? injecting a relatively harmless script into the product (that frankly caused them to fix an issue that could have been very painful for them if someone more devious had found it first), or Qato's ripoff of Quora in the first place?

Putting the legal issues aside? It doesn't matter either way: security vulnerabilities trump copycats (in my opinion).

Publicly releasing details of an XSS vulnerability on a third party's site has much bigger ramifications than a copycat site. Plenty of websites deal with copycats all the time: they're frustrating, but they're not necessarily overly threatening. On the other hand, a 0 day could compromise the security of user information. In certain fields, that could completely destroy your business.

Re: Quora engineers accused of vandalizing a clone’s website

#20
post #2

The full quote from Rick Ross is "I am grateful that Ben Newman and Albert Sheu of Quora have identified a (now fixed) XSS vulnerability in our test site, but I am surprised that Quora policy permits developers to engage so openly in vandalizing other people's websites." which is slightly nicer than that article makes it sound. Personally, I think the Quora engineers involved made some poor decisions. Anyone who look…

Or exposes you to a group of individuals who will want to make you regret showing off.
Post reply on HN