Live data from Hacker News

At Blind, a security lapse revealed private complaints from tech employees

techcrunch.com

111–120 of 141 posts

Re: At Blind, a security lapse revealed private complaints from tech employees

#111

Earlier quoted context omitted.

> That's not how hash functions work... Kind of. A hash function just provides a near random set of characters of fixed length for a given set of input in a way where the output characters are reproducible for the given input. Passwords are not stored. It is the computed hash value that is stored. When a user attempts to login with a username and password the password is hashed and compared to the stored hash. That s…

It's cool that you jumped on the opportunity to explain how password hashing works. However, the reporter actually cracked hashes, so we can bypass all of this discussion and plainly see the hashes were insecure. And for what it's worth: > To be secure the salt must be stored in a different location from the stored hashes and the salt value should not be statically visible in the source code provided a source code co…

You cannot crack a hash though. It is just a string of fixed length. Nobody says crack a string because it sounds ridiculous.

> Your salt can be totally public if you're using a robust key derivation function.

That is a deliberate strawman. If your salt is based on keys there is still information you aren't exposing even if you are exposing the salt itself.

Re: At Blind, a security lapse revealed private complaints from tech employees

#112

Using Blind with your company email on the company WiFi seems really dumb? Maybe I'm paranoid, but I act as though everything that goes through my company WiFi and on my company computer is being tracked and stored in some database forever under my name. And I assume the company email is used to send you a verification email, which means your employer is now tipped off to the fact that you're using a site to anonymou…

Correct, it's very easy to find out who in the company is on Blind -- most corporations use Exchange.

Easy as this: http://ivan.dretvic.com/2011/05/remove-specific-email-from-a...

The article says "remove" but before you remove, you need to list all employees that have that email - if you just make a test account or look for the domain then you can pipe the results to a text file and that's your list of company insiders who are on the platform.

What leadership does with that info, is well, never good.

Re: At Blind, a security lapse revealed private complaints from tech employees

#113

Earlier quoted context omitted.

My first look at Blind rated cities to work in by how hot/available women were there (e.g. comments like "SF sucks, you have to settle on dating uglies" or "NYC women are so much hotter than SV women, no contest where to live"). The question asked to the Blind community was just "where would it be better to live long term" or something completely not to do with dating or women, but the majority of responses were abou…

> outright racism against Indians in particular. Racism is not illegal and should not be suppressed. It does should also not be encouraged, however. At the end of he day, people do not have the right to feel good. > My first look at Blind rated cities to work in by how hot/available women were there (e.g. comments like "SF sucks, you have to settle on dating uglies" or "NYC women are so much hotter than SV women, no…

> Nothing wrong with rating women. People do it all the time. It's about time it is made less taboo.

In the current context of rampant sexual discrimination, there is everything wrong with "rating women". To be very clear, when "rating women" I presume you are talking about the snap judgements made based on stereotypical beauty attributes relating to physical appearance.

The problem with "rating women" in this way is that ranking people according to a very small set of "desirable" attributes neglects or diminishes other very important aspects of what makes a person worth knowing and loving. Appearance becomes a top priority over and against other perhaps more important attributes including loyalty, kindness, and intelligence.

Additionally, "rating women" along such lines reinforces the sense that people are fungible sources of (aesthetic) value rather than worthy individuals in their own right. None of this even touches upon the social and psychological problems that result when people are judged on such a small set of shallow traits.

While people do judge each other based on appearance all the time, such tendencies are to be resisted and questioned because, for one, the standards of physical beauty are well-known to be shaped by the imperatives of advertising which have established that making people feel insecure drives sales.

In fact, it's not taboo to judge people on appearance at all. "Rating women" is a social norm. Not judging women based upon on their appearance is actually the rare exception.

EDIT: add preposition; remove duplicate word; delete extraneous space.

Re: At Blind, a security lapse revealed private complaints from tech employees

#114

Using Blind with your company email on the company WiFi seems really dumb? Maybe I'm paranoid, but I act as though everything that goes through my company WiFi and on my company computer is being tracked and stored in some database forever under my name. And I assume the company email is used to send you a verification email, which means your employer is now tipped off to the fact that you're using a site to anonymou…

What someone at my org did was send an invite to everyone, so pretty much everyone got an email. We use outlook webapps so it is easy enough to login on a non company device to click the link.

My company knows everyone that got a link (everyone) but not who clicked the link.

Re: At Blind, a security lapse revealed private complaints from tech employees

#115

Using Blind with your company email on the company WiFi seems really dumb? Maybe I'm paranoid, but I act as though everything that goes through my company WiFi and on my company computer is being tracked and stored in some database forever under my name. And I assume the company email is used to send you a verification email, which means your employer is now tipped off to the fact that you're using a site to anonymou…

Correct, it's very easy to find out who in the company is on Blind -- most corporations use Exchange. Easy as this: http://ivan.dretvic.com/2011/05/remove-specific-email-from-a... The article says "remove" but before you remove, you need to list all employees that have that email - if you just make a test account or look for the domain then you can pipe the results to a text file and that's your list of company insid…

Posted above but someone at my org sent an invite to everyone. Having a list of everyone that received an invite does not mean they signed up...

Re: At Blind, a security lapse revealed private complaints from tech employees

#116

I'd never checked out Blind before. I just went there and checked out a few of the front page posts & comments. It has some of the most toxic and destructive "advice" I've seen for people asking for help or insight. I'm a bit astounded. Is this typical?

Same - I have friends telling me about Blind but had never looked at it until now. Just the comments on the top posts are awful.

Re: At Blind, a security lapse revealed private complaints from tech employees

#117
"Blind claims on its website that its email verification “is safe, as our patented infrastructure is set up so that all user account and activity information is completely disconnected from the email verification process.”

"Patented infrastructure"? It smells like BS to me.

Re: At Blind, a security lapse revealed private complaints from tech employees

#118

Earlier quoted context omitted.

It's cool that you jumped on the opportunity to explain how password hashing works. However, the reporter actually cracked hashes, so we can bypass all of this discussion and plainly see the hashes were insecure. And for what it's worth: > To be secure the salt must be stored in a different location from the stored hashes and the salt value should not be statically visible in the source code provided a source code co…

You cannot crack a hash though. It is just a string of fixed length. Nobody says crack a string because it sounds ridiculous. > Your salt can be totally public if you're using a robust key derivation function. That is a deliberate strawman. If your salt is based on keys there is still information you aren't exposing even if you are exposing the salt itself.

[deleted]

Re: At Blind, a security lapse revealed private complaints from tech employees

#119

I stopped reading after reading a thread of grown men throw hissy fits because they thought they were screwed over by their $300k salary when they felt they “deserved” $400k+

It never fails to amuse me how a worker desiring a better wage is something frequently and deeply mocked here.

Re: At Blind, a security lapse revealed private complaints from tech employees

#120
They say "anonymous" but right after signing up with my work email they followed me on Twitter. The two are only connected by my name. Could be coincidence, but probably not.

Also, the community there is pretty toxic. I understand it's mostly the design of the app to be a place where people can say what they want, but I think it attracts a certain type that I'm not terribly interested in getting close with.

Post reply on HN