Live data from Hacker News

Lulu: An App No One Should Accept

compylr.com

271–280 of 356 posts

Re: Lulu: An App No One Should Accept

#271

Earlier quoted context omitted.

I suppose so, but this heavily relies on no one in your operation having made a mistake, or that mistake having been caught before it was pushed live. You have to be lucky every time, an attacker only needs to be lucky once .

Above you are essentially saying every application has SQL injection vulnerabilities and any good security guy will find them. This is a very specific and dubious conclusion to draw from the more general principle that there will be some vulnerability, somewhere. SQL injection specifically is quite easy to avoid. With some frameworks it would actually be rather laborious to introduce an SQL injection vulnerability. T…

Well, statistics of pentests does show that, if tested, the vast majority of good quality, generally securely built applications have some vulnerabilities, and average applications have a huge multitude of vulnerabilities.

SQL injections are just one class of many. There are ways to vastly reduce SQL injection risks but that still leaves many other venues of attack.

Re: Lulu: An App No One Should Accept

#272
post #69

Where are all the feminists now? This is the perfect example of double-standards implied by women. Imagine an alternative scenario where men could rate their female counterparts on the basis of their 'assets' as defined by some vague methodology. Imagine how much fire under men would be, with ALL men being broadly labelled as sexists because this app was targeted at men. I am seriously asking - Where are all the femi…

I'm a feminist. I'm not outraged. If I was outraged because destructive things exist, I would be a bundle of rage 24 hours a day and never get anything done. What enrages me is sensible people supporting sexism, and no one I respect supports this.

I also am not driven by blind principle, I focus on practicality. As a futurist, I don't see this catching on, let alone abuse of if becoming a big problem. Why would I put energy into solving a vaguely possible future violence when there is documented violence happening right now?

If this app were supporting and accelerating an existing tragedy of men being unable to control their reputations, this might be worth getting angry about.

Re: Lulu: An App No One Should Accept

#273

Earlier quoted context omitted.

I suppose so, but this heavily relies on no one in your operation having made a mistake, or that mistake having been caught before it was pushed live. You have to be lucky every time, an attacker only needs to be lucky once .

No, I never have to be lucky at all. I literally can not put an SQL injection vulnerability into production unless I do so deliberately, my code wouldn't compile. Not everyone uses terrible rails style "lets automagically do shit behind your back so security holes are hidden from you" frameworks.

You're being too harsh. You seem to be talking about Haskell, so saying "not everyone" is a weird way to put it. You really mean a tiny fraction of people use Haskell to be safe in advanced ways. Well, Haskell is ahead of its time. Of course not that many people use it.

Even Haskell is not a silver bullet against every kind of security problem. Didn't Snap have a directory traversal bug a while back?

Re: Lulu: An App No One Should Accept

#275

Earlier quoted context omitted.

Not to mention, female privilege lets them call men "creepers" or "perverts" without question. I've pressed female friends about this and they just answer with "I didnt like the look he gave me" or "we just didnt click." So instead of understanding that most people are not compatible, we're now building a db to slander them based on purely emotional reasoning? If women are using this then it says a lot about the woma…

Until we, as a society, can stop blaming women for their rapes (she was so sloshed, what did she think would happen when she got into bed with him?) women are going to be EXTREMELY conservative about these kinds of things. When it's your fault if he rapes you, you put "creepy" on a hair trigger.

You're being disingenuous. There are thousands of rape convictions a year regardless of whatever cherry-picked anti-women sentiment you think exists. Some of which are purely on hearsay and men go to prison with little to no physical evidence. Brian Banks is a good example.

Also, this app is to rate men. Its not an anti-rape app. Stop playing the rape card to defend every lousy idea.

Re: Lulu: An App No One Should Accept

#276
post #273

Earlier quoted context omitted.

No, I never have to be lucky at all. I literally can not put an SQL injection vulnerability into production unless I do so deliberately, my code wouldn't compile. Not everyone uses terrible rails style "lets automagically do shit behind your back so security holes are hidden from you" frameworks.

You're being too harsh. You seem to be talking about Haskell, so saying "not everyone" is a weird way to put it. You really mean a tiny fraction of people use Haskell to be safe in advanced ways. Well, Haskell is ahead of its time. Of course not that many people use it. Even Haskell is not a silver bullet against every kind of security problem. Didn't Snap have a directory traversal bug a while back?

I don't understand what you are trying to convey. It appears like a deliberate red herring to try to distract from what I actually said. I personally use haskell, but you do not need to do so to get a complete guarantee against SQL injection. Nobody said anything about silver bullets or protecting against every security problem. I very clearly said SQL injection is a solved problem, in reply to someone claiming every single web app has SQL injection vulnerabilities in it and that any security researcher can easily sit down and exploit them, and the only way to deal with SQL injection is to be lucky over and over.

Re: Lulu: An App No One Should Accept

#277
post #25

Wow, it's like everything that I used to fear about the dating world put into one shiny app. Had this been out years ago when I was single, it would've definitely given me a lot of anxiety. Having been happily married for 5 years, all I can say to single folks is that if someone actively rates people on apps/sites like this, they are most likely not the kind of people you want to be with in the long run. As for the s…

Not to mention, female privilege lets them call men "creepers" or "perverts" without question. I've pressed female friends about this and they just answer with "I didnt like the look he gave me" or "we just didnt click." So instead of understanding that most people are not compatible, we're now building a db to slander them based on purely emotional reasoning? If women are using this then it says a lot about the woma…

Well, the classic sketch http://www.break.com/usercontent/2007/5/7/more-sexual-harass... is a bit exaggerated but it does have some truth in it.

Re: Lulu: An App No One Should Accept

#278
post #25

Wow, it's like everything that I used to fear about the dating world put into one shiny app. Had this been out years ago when I was single, it would've definitely given me a lot of anxiety. Having been happily married for 5 years, all I can say to single folks is that if someone actively rates people on apps/sites like this, they are most likely not the kind of people you want to be with in the long run. As for the s…

Not to mention, female privilege lets them call men "creepers" or "perverts" without question. I've pressed female friends about this and they just answer with "I didnt like the look he gave me" or "we just didnt click." So instead of understanding that most people are not compatible, we're now building a db to slander them based on purely emotional reasoning? If women are using this then it says a lot about the woma…

It only solves itself if the users are non anonymous. Otherwise, how do you know if a creeper posts to the site after your date?

Re: Lulu: An App No One Should Accept

#279

I used to be unhappy about this app until I found an SQL injection vulnerability that allowed me to log in and access the accounts of my previous dates by only needing to know their email addresses. This meant I was able to manipulate the ratings and comments people had made about me. Now I like the app :) Thanks Lulu!

As the former CTO of that company, I really doubt this. When I was there, the app was built on Django, and I left some pretty competent people behind, so I'm quite sure they wouldn't have made a mistake so rudimentary. However, I don't know what happened after I left, so there might have been some dubious decisions.

This complacent overconfidence tells me that Lulu probably has major security holes that the staff refuse to look for.

Re: Lulu: An App No One Should Accept

#280

Earlier quoted context omitted.

With all the commentary here you'd think all feminists are the kind that want to "overthrow" men and it's women's fault a company primarily consisting of men were funded, and have developed and marketed this app. There are far creepier and more intrusive apps and services out there. Instead of blindly blaming feminists (without actually understanding what most feminists actually stand for) for them being on the marke…

>Instead of blindly blaming feminists (without actually understanding what most feminists actually stand for) for them being on the marketplace Why do discussions like this always get such ridiculous strawman arguments tossed around? Nobody is blaming feminists. People are pointing out that the vocal, hateful group of internet "feminists" constantly claim they are against sexism in all forms, and thus men's rights ad…

Men's rights advocacy is, as a movement, pretty much the same thing as the whole "war on Christmas" crap that comes up on right wing TV every year.

It has no legitimacy because it's not legitimate.

Instead it is largely the same old prejudices, finding renewed strength under a thin mask of collective victimhood, desperately clung to.

Post reply on HN