HN user

laurenceputra

436 karma
Posts30
Comments20
View on HN
thenextweb.com 13y ago

BillPin buys BillMonk, the US service that inspired it

laurenceputra
25pts4
blog.geeksphere.net 13y ago

Misinformation on crowdfunding projects

laurenceputra
1pts0
blog.geeksphere.net 13y ago

Dropmyemail's security

laurenceputra
8pts32
addons.mozilla.org 13y ago

UnsocialReader

laurenceputra
1pts0
geekcamp.sg 13y ago

Videos from GeekcampSG, a all geek conference in Singapore

laurenceputra
1pts0
iwasntpaid.com 14y ago

I Wasn't Paid

laurenceputra
325pts185
blog.geeksphere.net 14y ago

Ron Paul – Predictions in Due Time

laurenceputra
1pts0
blog.geeksphere.net 14y ago

Making a difference, from the ground up.

laurenceputra
1pts0
zitseng.com 14y ago

Computer Science Noobs

laurenceputra
2pts0
blog.geeksphere.net 14y ago

Gamification in education. Does it solve anything real?

laurenceputra
5pts1
blog.geeksphere.net 14y ago

You’re an entrepreneur. Really? (Part 2)

laurenceputra
2pts0
blog.geeksphere.net 14y ago

You’re an entrepreneur. Really?

laurenceputra
5pts0
blog.geeksphere.net 14y ago

Where is our humanity?

laurenceputra
1pts0
blog.geeksphere.net 15y ago

Tech Gadgets Vending Machine

laurenceputra
2pts1
blog.geeksphere.net 15y ago

It’s not about being a hero. It’s about being something more.

laurenceputra
1pts0
blog.geeksphere.net 15y ago

Abstractions… Enough is enough…

laurenceputra
2pts0
blog.geeksphere.net 15y ago

Awesome 404 page

laurenceputra
2pts0
blog.geeksphere.net 15y ago

Stop Forwarding That Crap to Me

laurenceputra
1pts0
blog.geeksphere.net 15y ago

So you want to do a startup, eh?

laurenceputra
2pts0
blog.geeksphere.net 15y ago

Why every undergrad should intern for a startup at least once.

laurenceputra
1pts0
nushackers.org 15y ago

Why every undergrad should intern for a startup at least once.

laurenceputra
2pts0
blog.geeksphere.net 15y ago

Is Com Sci as a discipline going downhill?

laurenceputra
2pts0
groups.google.com 15y ago

Very epic C code

laurenceputra
8pts1
blog.geeksphere.net 15y ago

When you(the biz people) are looking for tech cofounders

laurenceputra
1pts0
blog.geeksphere.net 15y ago

Should there be a new major in Computing schools?

laurenceputra
1pts0
nushackers.org 15y ago

Motivations of a Hacker

laurenceputra
51pts10
blog.geeksphere.net 15y ago

In The Muslim World This Is ‘Americans Killing Muslims’ again – Michael Scheuer

laurenceputra
3pts1
blog.geeksphere.net 15y ago

This is definitely a bubble

laurenceputra
11pts14
blog.geeksphere.net 15y ago

What creates successful apps? And why Color is a good deal for Sequoia Capital.

laurenceputra
1pts0
blog.geeksphere.net 15y ago

More on color

laurenceputra
1pts0

yea, you are now aware of the mass assignment bugs, but what about previously? even github got affected by it. are you saying that they are incompetent? what about bugs that have yet to be revealed?

what i am saying is that there may be some things that you forget about, because we are all humans. and in order to mitigate the risk from us being humans, we should not store passwords in a way that is easily recovered.

And again, I am not doubting your competence. What I am saying is that we are all humans. Google might have hired the best computer scientists around the world but they still got hacked. It might even be a problem with the programming language you are using (rmb mass assignment on ROR?)

"We offer people an off-site backup at the cost of trusting a third party with their password."

Yes, this is my main point. People have to learn that they shouldn't be giving out passwords to just about anybody.

I think this guy in the comments here (http://blog.geeksphere.net/2012/09/27/response-to-dropmyemai...) made a pretty good point. Maybe you might want to answer his doubts there?

and by storing the passwords, they are putting their users at risk. and we are in an era where email security means more than anything. it means access to all your services.

they should go think about how they can design a service securely before offering it.

what they could have done is to allow users to autoforward their emails over to their servers or something. not impossible, but i'm not their employee and i'm not responsible for thinking up business strategies for them.

so yea. not necessary

in fact, seeing how your account was created to post that comment and seeing how it doesn't make sense, i would suspect that you actually work for them.

they can't, unless the email service gives them oauth.

and even then allowing a 3rd party to backup your emails is a very dangerous thing to do. they say that credit card is more dangerous, i say no. for credit cards you can claim fraud.

when your email gets hacked, potentially your whole digital life is gone

I'm the author.

1) The app downloads your emails into their server.

2) Yes, they store that actual password. Which is ridiculous.

3) Yes, good for them for that, but still there are others where they store passwords. And that is not acceptable.

4) But that also means that they outsource the security part of things. Which doesn't lend faith to the idea that they know about security. And if someone realises how to control their application, all the passwords will be hacked.

5) Pidgin is stored locally. There's a difference. Not that I support it, but it's still better than someone storing my passwords.

but they actually listened to her all the way, and as one comment said, some sites claimed that she might already have gotten funding.