4 ms·
Exactly. All they did was remove an open source repository. It's still trivial to access their services in a way that they admit is harmful to their customers'
by slimed 7y ago
Exactly. All they did was remove an open source repository. It's still trivial to access their services in a way that they admit is harmful to their customers' privacy. As a bonus, now it's on the front page of Hacker News.
It's almost as if they're making the same error as OP who identified the library as "an API" rather than a client of an insecure API implemented by Instagram. Presumably they know better.
- amylene 7y agoPerfect is the enemy of good. And we don’t know what work they’re doing on the engineering side. What if it turns out they detected this code was run by other people and responsible for 50% of the unauthorized access? Just because it doesn’t entirely solve the problem, does not mean they shouldn’t pursue all partial tactics.
- slimed 7y agoThe problem is that they are abusing a statute that we all know is harmful more generally and creating precedent for others to do it.