Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm ex-Y! as well, but do you any basis for "I find this to be not 100% true"?

Is there any possibility of someone someone caching the details for convenience's sake on login, and said service not going through the Paranoid review process? I haven't done this personally, but I have had to work with some absolutely dreadful internal APIs that I needed to cache information from out-of-band to make them usable.

(In all fairness, though, I'm find it hard to believe this report. I'll guess we'll find out the truth pretty soon.)



I suppose a rouge developer can show their own login dialog box, but that is such a hack and should be pointed out by their boss, local paranoid (guess they are all gone?), or QA. They would have to capture the user's credentials and post it to the login handler themselves. Even the user might realize that it is not the login page and assume it is a phishing site.

The secret code for the encryption of the cookies is only installed on the login servers, and without that package installed, there would be no way to generate a valid signed cookie.

In short, there is no 100% guarantee a rouge developer could not do any damage, but it would be pretty hard to go unnoticed.


Ex-Yahoo and former local paranoid. I agree with you. That's so unlikely that I'd be willing to put money that it wasn't a rogue developer.


How does an Acquired Company fit in with all of this?

(An entire acquired company full of rogue developers? :-) )




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: