Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you're relying on a cloud-hosted startup to secure gold or the president, you're doing it very, very, very wrong.

The level of complexity of an attack and the ridiculousness of a hole are almost completely arbitrary in terms of compromising the security of a service. The biggest attacks of the past 6 months were performed either using social engineered credentials or extremely common web application vulnerabilities (so common that probably every hole used is on OWASP's Top 10 security holes).

The only reason Fort Knox or the Secret Service works is because it relies on humans spending 100% of their time actively focusing on security, 24 hours a day, every day. No web service I have ever heard of has that level of security.

As far as this particular hole: it's probably a bug somebody left in some code by accident and nobody foresaw the consequences. There are bugs like this in every system. The only reason you don't see more of these holes is because either nobody's looking for them or somebody found it and is keeping it very secret.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: