Live data from Hacker News

Tl;dv: Over 180k meetings left wide open

bobdahacker.com

91–100 of 231 posts

Re: Tl;dv: Over 180k meetings left wide open

#91
> tl;dv names their microservices after pasta. A subdomain scan reveals cappellini, carbonara, fusilli, pasta, penne, puttanesca-v0, and ravioli, all under tldv.io. An entire Italian restaurant worth of Express servers.

Pretty appropriate, given a vulnerability of this severity. Literal microservice spaghetti.

(Also, please, let's all move back to boring names for services and servers. Nobody likes trying to decode what all these silly names mean.)

EDIT:

omg, the disclosure communication is infuriating.

> We're on it. It needs some time, but rest assured we're following through. For further communication, i'll recommend reaching out to our CTO

This should have been a P1 that was fixed same day, and they strung him along for months. Absolute amateurs.

Re: Tl;dv: Over 180k meetings left wide open

#93

It's hilarious how these companies handle security breaches. I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault . I had just started working there and found it in the first week. Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years ev…

At a few companies I've worked at, they squelch this kind of bug/security breach reporting by immediately making it the discoverer's job to fix the problem and champion it through the system to production, taking on all responsibility if something breaks of course. You only have to go through that once to get the message.

Re: Tl;dv: Over 180k meetings left wide open

#94

It's hilarious how these companies handle security breaches. I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault . I had just started working there and found it in the first week. Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years ev…

More proof that software engineering isn't real engineering. If a civil engineer made a mistake that bad in my country, he'd likely lose his engineering licence.

The entire reason the company was funded is the US government started enforcing FCRA compliance on 1099 Uber drivers.

So the government did get involved and regulated Uber and the entire gig economy, and the private sector is so powerful they just made their own background check company with hundreds of millions of dollars in VC and hype, gave them Uber as their flagship customer and wiped their hands.

No doubt in my mind these people were "just happy to be here" at best, criminals at worst, and have no business working with PII and background checks. Founders and everyone there.

But I still think the company should be found liable, not an individual engineer. They would be a lot more incentivized to hire based on merit, and not incentivized to literally be corrupt like they are now.

With your idea of punishing the engineer... these VCs would love that. Shift even more blame onto the worker, why not, we've taken it for everything else

Re: Tl;dv: Over 180k meetings left wide open

#95

Earlier quoted context omitted.

Idk licensing and regulation sounds like involving more institutional arrogance. We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed). The CTO shouldn't have to pay, the company should. And then maybe they will be incentivized to hire somebody who knows what they're doi…

this idea that government regulation is the problem and the companies need economic incentives to self regulate is a religion around here, and after incredible amounts of evidence that is untrue, like all religions, it’s practitioners have made zero changes to their opinion.

There is exactly zero evidence that any religion isn’t true.

How could there be?

Evolution can’t disprove the existence of God.

Re: Tl;dv: Over 180k meetings left wide open

#96
post #89

Earlier quoted context omitted.

More proof that software engineering isn't real engineering. If a civil engineer made a mistake that bad in my country, he'd likely lose his engineering licence.

Software lost that status in the vibe coding era. It's an art form now, not necessarily something worse or easier, just different than engineering. But probably not the career path anymore for those who prefered math over philosophy in college.

It was this way well before vibe coding. Over a decade of zero interest rates combined with talent wars and other anticompetitive behaviors by large tech companies did the industry in.

Re: Tl;dv: Over 180k meetings left wide open

#97

Earlier quoted context omitted.

Idk licensing and regulation sounds like involving more institutional arrogance. We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed). The CTO shouldn't have to pay, the company should. And then maybe they will be incentivized to hire somebody who knows what they're doi…

> Idk licensing and regulation sounds like involving more institutional arrogance. Well it works . Aviation for example is incredibly safe if you think about it, and mostly because the governments worldwide joined forces and introduced an amount of safety regulations everywhere that sounds insane until you remember that these rules were literally written in blood. And similarly, losing your life or getting injured on…

> Trades licensing is merit based.

Only on the bottom end. People with zero merit get forced out - eventually in most cases. However a lot of people who have merit are not allowed in.

Re: Tl;dv: Over 180k meetings left wide open

#98

Seems like they fixed this a few days ago: https://tldv.io/blog/our-thoughts-on-the-darkreading-com-art... But they try to play it off as though this were public data: > Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search. Also, interesting, they are SOC2 compliant [1], p…

Once again proof that SOC2 is nothing but a marketing tactic, and busywork

Re: Tl;dv: Over 180k meetings left wide open

#99
This breach will help with tl;dv's awareness. More people will suddenly become aware of it. The downside is that less private conversations will be hooked up to tl;dv, and more public seminars will be fed instead. This is a win-win overall. And it is a PSA to all other companies to secure their servers a little bit better.

Re: Tl;dv: Over 180k meetings left wide open

#100

Earlier quoted context omitted.

Idk licensing and regulation sounds like involving more institutional arrogance. We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed). The CTO shouldn't have to pay, the company should. And then maybe they will be incentivized to hire somebody who knows what they're doi…

> Idk licensing and regulation sounds like involving more institutional arrogance. Well it works . Aviation for example is incredibly safe if you think about it, and mostly because the governments worldwide joined forces and introduced an amount of safety regulations everywhere that sounds insane until you remember that these rules were literally written in blood. And similarly, losing your life or getting injured on…

Commercial aviation involves other people's lives in real-time. I put that more like being a lifeguard or EMT.

Recreational aviation has a lot less regulation. I saw a guy with nothing but a fan and a parachute just flying around the cliffs off Hwy 1. No license or certification needed.

Shouldn't need a license to make React components, sorry.

Post reply on HN