Live data from Hacker News

'Impossible-to-hack' security turns out to be no security

jltee.substack.com

151–157 of 157 posts

Re: 'Impossible-to-hack' security turns out to be no security

#151

Earlier quoted context omitted.

Not a journalist or a reporter, posts aren't meant to be professional. The only reason I even write any of my posts is because companies DO NOT disclose incidents at all, so I have to do it for them.

I thoroughly enjoyed the post and thought your tone was appropriate, entertaining, and kind of kethartic. You didn't call them names, engage in ad hominem, or do anything click-batey. You were understandably irritated at how they talked to you and how they were clearly trying to hide a massive exposure from their users. And then you shredded them with data. A+ - And thanks for trying to keep folks like this honest!

(*cathartic)

Re: 'Impossible-to-hack' security turns out to be no security

#152

The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.

The tone is perfect here, you don’t have to play nice with people who are not nice to you.

You only get the benefit of professionalism if you act like one.

Re: 'Impossible-to-hack' security turns out to be no security

#153
post #144
post #6

Even if a guy is an easily hackable asshole, usually accessing the stuff directly and downloading his database is still a crime (at least in the US), stay safe buddy.

Is it hacking when there is no "breach?" If I serve a file with info I didn't intend for the world to see at example.com/secret and you access it, did you commit a crime? Clearly no. Given that, you have no way to even know if the data which was available publicly contained any private information. This guy is doing a fine public service, and any company he helps should pay him for saving their asses.

Prosecutors are not famous for caring about internet arguments, weev (who is a piece of shit for other reasons) got sentenced to 41 months for effectively incrementing an integer in a url - https://www.justice.gov/usao-nj/pr/new-york-man-sentenced-41...

"he concocted the fiction that he was trying to make the Internet more secure, and that all he did was walk in through an unlocked door. The jury didn’t buy it, and neither did the Court in imposing sentence upon him today.”"

Re: 'Impossible-to-hack' security turns out to be no security

#154

Earlier quoted context omitted.

I thoroughly enjoyed the post and thought your tone was appropriate, entertaining, and kind of kethartic. You didn't call them names, engage in ad hominem, or do anything click-batey. You were understandably irritated at how they talked to you and how they were clearly trying to hide a massive exposure from their users. And then you shredded them with data. A+ - And thanks for trying to keep folks like this honest!

> You didn't call them names, engage in ad hominem Well, the author wrote: > Teammate App CEO, Sean Banayan, who has the reading comprehension and IT knowledge of a toddler So it wasn't very nice, but deserved imo.

To be fair that doesn't appear to be an ad hominem because the author lists many facts supporting his assertion none of which was particularly personal. Nor is it name calling as he compared the CEO to a toddler, but did not say that he was a toddler.

Re: 'Impossible-to-hack' security turns out to be no security

#155

Earlier quoted context omitted.

The author is not acting in a professional role here. He, in his own time, discovered a pretty serious exposure of information and politely informed them. They decided to not be polite in return. He responded in the same tone as them. There was never any professional obligation, nor any obligation for the author to inform them of their breach at all, nor was there any obligation to give them time to notify clients be…

To double down here, the author did the correct thing by using their snarkiness. If someone who in theory is a professional (the company that left all of this in the open) responds in an unprofessional way from the start - you are done using professional tone. That tool isn't producing results. Stop using that tool. The goal is not to model perfect manners - it is to bring attention to a breach so it can be remedied.…

Exactly. The stakes of the conversation are quite high. Innocent people could suffer real harms.

Professional norms exist to support people in taking responsibility for the power they have. The CEO is manifestly failing in his responsibilities.

Post reply on HN