Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm not an hnreplies user, but IMO this is exactly what an incident disclosure should look:

  - What happened  
  - The extent of the damage  
  - Why it happened  
  - Why it is less likely to happen again in the future
Software is made by people, and people make mistakes. I don't think anyone is asking for perfect software (particularly not on this forum, and particularly not for free services offered by the community). But a clear picture of the breach and why it occured allows the user to make an informed decision about whether a service is worth using.

Maybe this is evidence of how low the bar is for incident reporting, or maybe its evidence of of "no publicity is bad publicity," but I just signed up for hnreplies.

Great service idea, and thanks for the honest and helpful disclosure!



Plus it does not contain the classic line "At [...] we take security very seriously" which to me is one of the most stupid things to say when you've just been breached.


To be fair, accidents do happen. Nuclear reactors take things pretty seriously but they get breached / melt down occasionally too.


I agree and it's why we must be prepared for WHEN "it" happens, NOT IF "it" happens.


"I am convinced that there are only two types of companies: those that have been hacked and those that will be. And even they are converging into one category: companies that have been hacked and will be hacked again."

-- Robert Mueller, 2012, when he was Director of the FBI [yes, that Robert Mueller]

https://archives.fbi.gov/archives/news/speeches/combating-th...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: