4 ms·
good idea. actually, we'll just wipe them and force new ones.
by smeagol 14y ago
good idea.
actually, we'll just wipe them and force new ones.
- zacharyvoase 14y agoBut you still should let your users know that their old keys have been compromised.
- adgar2 14y agoDude... this guy clearly doesn't understand security. I'm glad you're trying to help him out... but your time will be better spent elsewhere.
- interg12 14y agoWell that's not a very helpful attitude. People should be instructive rather than discourage someone from pursuing a reasonable project.
- adgar2 14y agoIt's not helpful, it's realistic. My exact wording was "your time will be better spent elsewhere." We each have 24 hours in a day. I spend 8-9 of mine sleeping, 9-10 at work. That doesn't leave much leftover for me. If zacharyvoase wants to spend his precious free time educating people who haven't done any due diligence to learn how to build a secure web app, that's his prerogative. But I don't see it as a good use of his time - there's already tons of resources out there that will do a better job than zachary. Is HN supposed to be a newbie education destination?
- jspthrowaway 14y ago"Whoops, we disclosed everybody's AWS credentials. I know! Rather than tell our users, I'll wipe the database and remove all evidence of it ever happening."
- ainsleyb 14y agoLegally you must disclose any sort of security breach to your users: http://en.wikipedia.org/wiki/Security_breach_notification_laws http://en.wikipedia.org/wiki/Security_breach_notification_la...