5 ms·
I understand the need to shame this platform, but why expose all their clients to this much risk? This disclosure here just named a whole bunch of clients. Why?
by hluska 1mo ago
I understand the need to shame this platform, but why expose all their clients to this much risk? This disclosure here just named a whole bunch of clients. Why?
- root-parent 1mo agoYou need to read the article.
- hluska 1mo agoI read the entire article. Did you? There’s no reason in there to expose this company’s clients. Edit - Are you capable of answering my actual question or was that the best you could do?
- root-parent 1mo agoHe has been emailing the CEO for six months with no replies. This is has also been posted here before with not a single pip or comment ... :-) And these customers absolute lack of technical due diligence, on this nth example, of move fast and break things...makes them deserve what they are getting.
- dpark 1mo ago> And these customers absolute lack of technical due diligence, on this nth example, of move fast and break things...makes them deserve what they are getting. That’s a garbage take. These customers didn’t move fast or break things. They trusted a company that made a promise and that company let them down.
- root-parent 1mo ago>> They trusted a company that made a promise and that company let them down. That is a Boeing and Volkswagen type of excuse. The engineers did it!
- dpark 1mo agoNo it’s not. Blaming customers is Volkswagen saying it’s your fault for buying a TDI.
- stonedivot 1mo agoI totally trusted this vendor selling me this snake oil, and he promised me it would work. I can't believe he let me down. This is all his fault.
- dpark 1mo agoSecurity incompetence doesn’t turn basic meeting recording and transcribing into snake oil.
- Oras 1mo agoTechnical due diligence do not including pep test!
- mikestew 1mo agoRead the article again, then. Anyone that has could get the list with a trivial amount of work. Security through obscurity isn’t going to hide that client list. And who knows? Maybe someone competent whose company is a client will see that list and say, “hey, boss, I was on HN today, and…”
- charlieyu1 1mo agoI think it is fine, the person hasn't really leaked any critical information. He named a few clients that are mostly government departments, and it would be a public interest concern if said issue is ignored for 6 months anyway
- gossamer 1mo agoAs I see it he is not the one exposing clients to risk. He is frustrated that no one is fixing it. The company that left themselves open like this are the ones that are exposing their clients. If this person is doing his best to do the right thing, there are probably other people who know about this vulnerability and are using it without telling anyone.
- masfuerte 1mo agoWhat's the alternative? Seriously. He's spent six months trying to get them to fix it. The risk is already there.
- reilly3000 1mo agoRight. At a certain point, the customers and investors and world need to understand the scope of the negligence so they can prepare for their own fallout of having that information fall into the wrong hands. Public disclosure is a responsibility of being a good citizen and engineer. I’m so sorry for tl;dv ‘s insurance company.
- Ekaros 1mo agoSometimes shame is only option to get things fixed. Sadly we do not have any reliable government institutions that could mandate immediate shut down of services. Before that only way to get things fixed is public shame.