Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
neon_erosion
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
neon_erosion
1y ago
Don't forget the `githubusercontent.com` domain, which is specifically used to host risky, user-generated content, and fully documented in https://docs.github.com/en/authentication/keeping-your-accou... (usin
2.
▲
by
neon_erosion
1y ago
This is the kind of thing that customers rely on you to do _before_ it causes an incident.
3.
▲
by
neon_erosion
1y ago
Then that would be an example of a system having failed and one that needs to change. Instead, this is an example of a hosting company complaining about the consequences of skipping some of the basic, well-documented safety and security pra
4.
▲
by
neon_erosion
1y ago
There are well-documented solutions to this that don't rely on the PSL. Choosing to ignore all of that advice while hosting user content is a very irresponsible choice, at best.
5.
▲
by
neon_erosion
1y ago
Exactly, this has been documented knowledge for many years now, even decades. Github and other large providers of user-generated content have public-facing documentation on the risks and ways to mitigate them. Any hosting provider that choo
6.
▲
by
neon_erosion
1y ago
How does flagging a domain that was actively hosting phishing sites demonstrate that Google has too much power? They do, but this is a terrible example, undermining any point you are trying to make.
7.
▲
by
neon_erosion
1y ago
What point are you trying to make here? You hosted phishing sites on your primary domain, which was then flagged as unsafe. You chose not to use the tools that would have marked those sites as belonging to individual users, and the system w