Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In fairness, that's pretty much a given for any web app.

Whatever user groups they create are only ever going to be an artificial construct - it's all just lists of stuff



Google 'could' open up all their gmail account's inboxes to an unrestricted public read-only rest api and shut down their normal email interface. They 'could' do this tomorrow. So everyone could see everyone else's email inbox.

Yahoo could do that and include even all the emails their users 'deleted'.

At one time, back in the 'olden days, everyone operated on the net as if this was a very real possibility.


Exactly.

I work for one of the large ecommerce tech companies - we have some great devs and run a pretty efficient cdci pipeline, stuff ships fast. There are multiple layers of unit testing, automated testing, manual testing and peer review in place to prevent this sort of thing.

Despite that, I can totally see how it wouldn't take much for a changeset in one area of the site that affected the default option in a drop-down in another to creep under the radar.


Well, my point being, we have an incredible degree of trust that these companies will operate in a continuous way, that their values will be unchanging. I too work at a large ecommerce tech company, and I can't see it suddenly changing. if you look at Yahoo, who knows in 10 years wether Verizon doesn't sell it off and the eventual owners decide that an ad-enabled 'look at everyone's emails' site wouldn't be worth the cost of buying Yahoo Mail's data.


Can E2E encryption not help? It works with WhatsApp or Signal groups, no?


But the app writer, os vendor or dev who wrote a library the app uses can defeat the e2e encryption because they are at the end.


The difference being, this needs malicious intent whereas accidentally configuring visibility defaults wrong or accidentally running `update foo set visibility='all'` are just a single small mistake.


Apple gets a lot of things wrong, but one thing it gets right is (mostly) designing things so that they couldn't get your data, even if they wanted to.


You mean like the iCloud thing where a bunch of famous women had home videos of themselves stolen?


Wasn't that more social engineering and password guessing though? Nothing they can do there apart from more security layers in the password/login but people will still not use string passes and be suspectible to social engineering.


After that they did exactly that, they included multi-factor authentication when it was previously unavailable. The MFA available in 2018 is dramatically better than it was in 2014, when I believe all that occurred.

Companies that don't protect unsophisticated users from simple mistakes or inaccurate mental models will get a reputation for being insecure and lose sales. This is regardless of whether the user "should have known better."


Their iCloud service was susceptible to brute force attacks.


That was caused by stupidity - reckless password management on the victim’s part.


Not really. Apple had no limit on the number of times that you could input a password incorrectly. They brute forced it. That's on Apple.


True, but I won’t put all the blame on Apple here. A good, random 30-char password would be impossible to crack even with thousands of attempts per second.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: