Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Just don't do what? Receive the information you are sending them?

If you don't want someone to have this information, the sensible thing is not to offer it. I cannot conceive of any way in which sending the information and then yelling at the recipient for receiving it is "more correct" than just not telling people things you don't want them to know.



Why don't site operators take responsibility for themselves to not leak their users information unnecessarily? We've taken it upon ourselves to chastise any web property that doesn't properly hash their passwords--we could just have easily say "if you don't want your password to other sites leaked, use different passwords". But we recognize the unfair burden we are placing on end users in that case. The case with CDNs and information leak is similar.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: