Hacker News new | past | comments | ask | show | jobs | submit login

Especially for business accounts, the level of friction was STUNNING.

Honestly, that's a feature, not a bug.




Not in an economy that demands rapid, scalable, and infinite growth.


[flagged]


Doesn't capitalism demand infinite growth? If you don't have >= 2% YoY, the market thinks you're dead


Doesn't capitalism demand infinite growth? If you don't have >= 2% YoY, the market thinks you're dead

No, it doesn't. There are plenty of businesses, and even entire industries that have operated for centuries on less than 2% growth. And yet somehow the world kept turning.


Fair enough.


[flagged]


Anything touching the DNS records for the root of your entire web presence is not simple and needs substantial review.


Adding a new DNS record for a new, specific purpose is simple and low-impact, technically.


…which gets promptly forgotten about after it’s initial use case and years later your user database gets sold on the internet.

How many “low-impact” things have been compromised over the years, I wonder?


Unless you have anyone competent running the DNS config, or have a ticketing workflow of any kind, and I can't figure out what you think a DNS record with a onetime validation token could do if left unmanaged beyond some adversary discovery.


That's exactly why DNS verification is a overkill.


For representing and verifying identity, it should need director level approval.


Yes.


That's an overly technical way of looking at things. This issue is a whoopsie, not a catastrophic failure at AWS. It doesn't actually represent identity that much because anything critical has humans in the loop. The bank won't accept this as proof of identity. NYT won't accept this as proof of identity: if this bluesky account confessed AWS murders puppies NYT would call somebody they know at Amazon to check.

A company blog is a much bigger vulnerability when it comes to representing and verifying identity. Rather than let somebody fake identify to a computer system it allows faking identity to humans reading it. Yet I don't think most places require director signoff to post.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: