Live data from Hacker News

Klarna users are being signed in to random accounts

twitter.com

401–410 of 517 posts

Re: Klarna users are being signed in to random accounts

#401
post #311

Earlier quoted context omitted.

If you find truthful and accurate statements of fact to be hostile, I don't know what to tell you, other than perhaps clarifying that I wasn't intending to be convincing or persuasive. Those that care about the truth will be persuaded sufficiently by facts, and everyone outside of those that care about the truth I am not interested in spending any effort persuading.

Does that mean you do not care about the truth, as you seem unpersuaded by the fact your missives are found to be hostile?

opinions != facts

Re: Klarna users are being signed in to random accounts

#402
post #310

Earlier quoted context omitted.

I worked with a team that owned a service that resizes images. An engineer was assigned a task to add support for auto rotating images. His solution involved saving the image to a file and then using a library to handle the rotation. He used a hardcoded value for the file name. In a local environment where requests are sparse this looked fine to him and other engineers on the team missed it in code reviews. It wasn't…

"An engineer was assigned" Nope. That definitely wasn't an engineer.

Mistakes happen. I've never met an engineer who has never made a mistake. However, I have met brilliant engineers who have written incredibly complex software and have also managed to make some silly mistakes along the way.

Re: Klarna users are being signed in to random accounts

#403
post #400

Earlier quoted context omitted.

You're cheating: you know your username and can recall which of your comments were mod log entries. Imagine creating such a log system in a company and expecting your colleagues to find such logs in such a manner. I'd move to get you fired.

This feels like it's swerving into just the sort of cross-examination that I describe in the comments I just took the time to dig up for you. My purpose in doing that was not to tell you "see? anybody can just go and find these". It was, rather: here is a set of past explanations about the question you're raising, which describe our thinking on this topic. If you want to understand why we don't do what you're suggest…

I’m done if you’re playing the victim card lol. Bye

Re: Klarna users are being signed in to random accounts

#404

I'm just guessing, but... "developer gets a great idea - let's push an update to the API as a GET request so we can cache this on the CDN... forgetting that the JWT token is potentially returned in the call. Now, whoever makes the call first gets their JWT token stored for everyone else to load instead when the API call is made." Ta-da, Klarna.

I can 100% see this being the cause if this comes out as the root. But... API's really shouldn't be cached? At least not at the CDN level. The risk of serving up stale dashboard data alone makes users go ????... and we definitely don't want - not even mentioning the problem here, that's crazy.

100% agree with this. A database is, in some form, a cache of its own. If you have to add additional cache on top, it's an additional source of complexity and risk. If you are building a financial platform, you should DESIGN around this.

Re: Klarna users are being signed in to random accounts

#405
post #389

Earlier quoted context omitted.

It's true - I use those comments to provide detailed explanations, which I often link back to. They're sort of the case law of HN moderation. It's my intention to someday compile them into some sort of compendium of moderation heuristics or something...not sure yet what that should look like.

So it's meant to be as inscrutable as law? I think you're mocking now. This is satire. So instead of a simple web page explaining how HN works/see what happened to entries, you expect new users to a) discover the moderators (also not public, nothing in your profile denotes you as a mod), b) read through all your comments - a mixture of moderation notes and general comments, c) interpret all the comments and figure it…

"Case law" is just a metaphor. The official rules are at https://news.ycombinator.com/newsguidelines.html (that would be "the law", in the metaphor), but they leave a ton of questions unanswered—there are many complexities and nuances, too many to list, and they only really make sense if you talk about them in the context of specific examples (those would be the "cases", in the metaphor).

Since people ask about specific examples all the time, and we always want to satisfy their curiosity, I post replies that go into detail about how we think about moderation, how what we did in any specific case relates to the guidelines, and ultimately how it all derives from the single thing we're trying to optimize HN for, which is curiosity (https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor...).

Over the years, those replies have grown into a body of explanations that add context to the site guidelines and the other brief things that have been 'officially' published about HN. That is analogous to how case law (the specific examples of how laws have been applied in the past) adds context to legal codes, which as you say can be inscrutable—they need examples to make sense. Another metaphor one could use for this is hermeneutics or midrash, but that has religious associations which would lead to distracting objections, so I don't go there. Yours is the first objection I remember anyone making to "case law"!

Of course this is not formal documentation, but it does contain all the explanation anyone could ask for—detailed answers to every conceivable question about HN moderation; just not in an easily discoverable form, as you say. That's why I'd like to compile this material into a more accessible format. We'd probably do that instead of making a public moderation log of every mod action—to come back to your original question—because it is more likely to help people understand what they're seeing. I've been waiting for the answers to converge into something that's worked-out enough to deserve publishing, but that has started to happen.

No one is expected to read that stuff, let alone find it for themselves; but I do include links to past explanations in current answers, so that anyone who wants to read more can click and get to them fairly easily. For example, here's such a link regarding the point I made in the previous paragraph: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que.... You'll notice that it contains the current comment, as well as 3 past ones on the same issue. It's an informal mechanism and it doesn't work perfectly (because the search links can also dig up extraneous stuff), but it's a lot better than nothing and has proven to be a good way to spread knowledge amongst the community—which is a hard problem btw.

I get why you might feel offended if we were telling you "just go dig up your answers in HN search"—that would be a little like customer support telling a user "look it up in the code, it's on Github". What we're actually telling you (and all users) is: if you have a question about how HN moderation works, just ask. If I see your question in the thread, I'll be happy to answer it—often at length, as I've done here—but we don't see everything in the threads, so it's better to email hn@ycombinator.com. The answer might end up including some links to past explanations, but you don't have to dig them up—we do that for you.

Although this mechanism is messy and insufficient, it has an interesting advantage: knowing that explanations can be reused in the future allows me to answer specific users' questions in much greater depth. If the only people reading this were you and the few others who ended up in this obscure corner of a thread while it was live, it wouldn't make sense to spend an hour writing an essay-length answer. But because the answer is helping to build a corpus of reusable explanations, the "economics" work: it's an investment in future readers in addition to current readers. Sometimes I take this to extremes, as with https://news.ycombinator.com/item?id=27162386 from a couple weeks ago—that was a lot of writing for answering a single user, even though we value single users. But it was also a big step in expanding the "corpus", making it worth doing.

It is a nice feedback loop: individual users benefit by getting richer explanations, the "case law" (can I use that term now?) benefits by getting a new detailed entry (a worked example, you could say), and the previous examples can be linked back to, making future explanations more meaningful.

This "system" emerged spontaneously over many years, in a bottom-up way very much in keeping with the exploratory, hackerish spirit that animates HN (at its best). That's what makes it so weird and esoteric, but also why it's alive and it works. Indeed, it's the only reason why any rich body of HN explanations exists at all. A top-down, bureaucratic approach would have led to "policies"—more the line of the manichean archenemy of the HN spirit. And anyway we'd never do that in the first place.

This approach has even changed how we moderate HN: it has evolved into a continuous, multi-sided dialogue (multilogue?) between the moderation subsystem and the community subsystem, that goes deeply into the why of things, tries to discover underlying principles and reflect them back to the community. For example, it led to "we're trying to optimize for just one thing", which I linked to above. This dialogue shapes the community in turn—it helps the forum regulate itself, even (I believe) when moderators aren't present.

The next step is to mine this material out of the subterranean thread-niches it's currently buried in, and to "scale" the economics by compiling it into more definitive forms that can be linked to and browsed. Perhaps it will look like an extended HN moderation FAQ or blog. That will be easier for new users to find and hopefully also save us a lot of time in the future, because as I said above, the answers have started to converge, which makes them more repetitive.

Re: Klarna users are being signed in to random accounts

#406
post #400

Earlier quoted context omitted.

This feels like it's swerving into just the sort of cross-examination that I describe in the comments I just took the time to dig up for you. My purpose in doing that was not to tell you "see? anybody can just go and find these". It was, rather: here is a set of past explanations about the question you're raising, which describe our thinking on this topic. If you want to understand why we don't do what you're suggest…

I’m done if you’re playing the victim card lol. Bye

Hey, relax. He’s not playing the victim. He’s just explaining how moderation works at HN.

Re: Klarna users are being signed in to random accounts

#407

Earlier quoted context omitted.

To get around this, one could include the request IP address in the JWT and required a refresh token to be sent when the user's IP switches.

This is not a safe method for protecting against this type of cache vulnerability. IP addresses are regularly shared by multiple users, especially when behind NAT (even mobile ISPs are doing carrier grade NAT these days).

So there should be no fail safe since it can't be guaranteed to work in every scenario.

Re: Klarna users are being signed in to random accounts

#408
post #320

Earlier quoted context omitted.

To get around this, one could include the request IP address in the JWT and required a refresh token to be sent when the user's IP switches.

In this context, this would just prevent everybody from logging in. The JWT would correctly get rejected but people would still be getting the wrong token from the CDN over and over.

Which would you rather? The situation you just described or users accidentally spoofing each other's session?

Re: Klarna users are being signed in to random accounts

#409
post #388

Earlier quoted context omitted.

Entirely

So users are meant to first discover the key (the username) to lookup the logs? Then find a needle in a haystack of comments? Again, are you being serious.

I'm not sure what exactly you're asking me. There's a thing that fulfills the function of a public moderation log, an answer to your original question. What is the other stuff about? HN is absolutely full of not-particularly-discoverable UI, it's practically made of it. You've been here for over a decade.

Re: Klarna users are being signed in to random accounts

#410

I worked in a project over 10 years ago where something very similar happened! We had built and authentication service that, among other things, was used by a SyncML service that was used back in the day of feature phones to syncs contacts etc. You can imagine that getting someone else's contacts on your phone isn't exactly ideal. This was how we came to know about the problem, from customers getting other customers…

Something similar happened a few years ago in Norway, when the yearly tax returns were released. Everyone of course logs in at the same time. It goes down, and the cache serves someone else's data instead.

Happened for the danish tax authority about 10 years ago as well. Although I think the issue for them was that the unique login token was based on a timestamp that several users happened to share during very busy peaks.
Post reply on HN