Hacker Newsnew | past | comments | ask | show | jobs | submit | dev_256's commentslogin

Damn, HN is turning into Reddit, fast.


All of them are about how awesome life is after quitting. This one is not.


The wire bends when it passes the eyes.


It's hard to see. Would have been better to use a straight wire instead of a bendy glasses arm.


You can still figure out it's hidden.


Sure but the point is that almost nobody does.


What if it was required to encrypt the message? Do you think the number of spam would go down?


I haven't explicitly tried to enforce encryption, but probably the drive-by style reports would require extra steps that their automation might not handle. So probably a good first filter. But then I'm still no wiser since the ability to use pgp isn't a qualifier regarding knowledge of the engineer or quality of their report.

It seems that the underlying problem is that those that do good work in this space don't scan the web to find new customers/leads to pitch their service in shambolic ways. And the skiddies who want to make a quick buck will outnumber the good who might accidentally have ended up on your site (because they like your product etc).

the noise/quality ratio in the whole approach is just too big for this to work well in practice. I'm still waiting for the recruitment industry to catch up with the practice and use the security.txt as a sink for people who want to be added to a list of experts that will be contacted when "the company is ready to do a full security assessment post-MVP". I realize this would be fraudulent and I'm not advocating for it - just saying that fake-job offers aren't uncommon either so this will just be a question of time.


What you're describing is a lot like the bug bounty program I ran for a previous employer. It was mostly low-effort scans and "reports" templated from something a big company had made public once. No understanding of if not using HSTS was actually a vulnerability, just the expectation of burp -> report -> $$$.

There were a handful of genuinely good contributors, but probably under 10% of reports.


I like you. Most of the people criticizing him didn’t bother to watch his lectures or read the book and still act like they know him.


Ended in psychiatric ward because it was “not a big deal”.


By ads free I meant their core business would be about not tracking you and only providing services of showing you content your friends publish.

Like you said it depends on what kinds of guarantees they'd give around use of data. How guarantees can you give?


Link to Privacy Policy from login page is broken https://app.monicahq.com/privacy



Content marketing?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: