frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Web security is too hard

https://textslashplain.com/2026/08/04/security-is-hard-yall/
81•kevincox•53m ago

Comments

63stack•36m ago
My main takeaway from this is not that "security is hard" but that cloudflare is pretty incompetent.
madeofpalk•12m ago
The takeaway is that everyone makes security hard. Everyone does this anti-pattern of having these other domains that defeat all their own security recommendations.

GitHub for ages had something like githubnext.com where they would make you do this same OAuth dance (except IIRC it was worse - it explicitly said that it WASNT GitHub). Apple has/had an apple.tv microsite or something they hosted content on.

Your bank will send you “legitimate” surveys or communication from some third party domain like qualtropics.com.

Joker_vD•35m ago
Another entry in "Marketing department starts a promotion campaign for the new product that's indistinguishable from a phishing attack" list. Starting with not using a subdomain on your own, very well-known domain but instead using a completely different one, then not having it shown with the rest of your services on your main web site, et cetera.
make3•30m ago
this is the correct take
derektank•30m ago
You really would think that at least in theory a company like Cloudflare would make it very easy for internal teams to automatically request new subdomains
raesene9•16m ago
Same Story as it ever was. The first time I encountered what I thought was a phishing attack at the bank I worked at 25 years ago, it turned out to be a marketing campaign, with URLs that put our company name as a user before the domain name (back in the day when creds could go in the URL).
ericlaw•9m ago
Fun fact: still can in Chromium-based browsers. https://textslashplain.com/2023/03/22/attack-techniques-spoo...
dwedge•35m ago
I guess it's easy to judge from the sidelines but was the screenshot of the site, if not the first tweet, not an obvious scam? And you can say it's from context but I only read the title before my eyes jumped to the screenshot
dwedge•34m ago
I just read the rest of the article and I'm back with my tail between my legs. I guess I made the author's point.
Hovertruck•29m ago
Don't worry, I think everyone probably went on the same roller coaster with this one
yellow_lead•33m ago
At one point in the article, the author asks Cloudflare's bot if they're launching a Wallet product, and it says no.

> There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt.

What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?

mirashii•28m ago
What’s the point? To save money paying a human to man a support email. That human would have also been hopelessly uninformed for all the same reasons.
wslh•23m ago
And as a dark pattern it adds "positive friction" for the company reducing the number of people that will have the motivation of obtaining the real people support.
bakugo•7m ago
The point is to signal to investors that they're all-in on the current fad, thus making the stock price go up.
thataccount•29m ago
Cloudflare is your favorite company and they are geniuses?

Dear Diary,

Today my fanboy bubble was burst.

Signed,

Author

ericlaw•8m ago
Note that I said: "One of my", and Cloudflare has hired a HUGE percentage of the best networking talent I've encountered.
thadt•29m ago
In the movie Sneakers, a whole scene is taken up sending some guy on a date with Mary McDonnell so she could record clips of his voice. Today she'd just need a phone call or his Instagram. It's getting harder to keep up with who _people_ are online, much less organizations and domain names.

Identity is hard y'all.

sghiassy•25m ago
Just use LLMs. They can apparently doing everything and all the things
harshreality•20m ago
They probably don't value being contactable by people who can't find higher-level contact info out-of-band, because there's too much noise.
1970-01-01•14m ago
This isn't a secfail. Why is pay.cloudflare.com so hard to establish? Why does marketing always get to overpower engineering? I expect Cloudflare services to avoid some sketchy .pay TLD for exactly the reasons this person went through.
epochbtc•8m ago
Ironically, this might be at least partially because the internal security controls at Cloudflare for using or provisioning new domains/subdomains is so difficult and arduous that the team decided the fastest way to go to market is to get an entirely new domain. Possible bonus that the official bug bounty program won't apply either, since it's on a new domain so any vulnerabilities found won't have to be paid out (as much).
LocalH•8m ago
Web security wasn't hard before we started trying to make the web a platform for full executable software.

I never got hacked through the web before JavaScript (never got hacked after either, yet, but it wasn't really possible in the same way to hack someone through the web without some way to execute program logic, which in the old days would have required a much more specific browser exploit to gain RCE).

JavaScript was a mistake. Everything else after that involves "running code in the browser" was a mistake.

Program execution needs to be completely separate from "the web". I don't want any code of any sort running in my browser, at least not any that I don't fully control. "The web" was never designed to be an application platform. It was only designed to be a document platform.

How dementia is being defeated

https://economist.com/briefing/2026/07/09/how-dementia-is-being-defeated
1•andsoitis•23s ago•0 comments

Neural Coding as Software Engineering Augmentation, Not Abdication

https://cacm.acm.org/opinion/neural-coding-as-software-engineering-augmentation-not-abdication/
1•champagnepapi•1m ago•0 comments

iOS 27 New Apple Map and Google Earth Comparison

https://www.reddit.com/r/applemaps/comments/1ve75td/ios_27_new_apple_map_google_earth_comparison/
1•Congeec•1m ago•0 comments

The hidden logic behind #, @, & and §

https://www.youtube.com/watch?v=cSsyG2pE-GY
1•CharlesW•2m ago•0 comments

Investors in Situational Awareness deserved to lose their shirts

https://www.economist.com/finance-and-economics/2026/08/04/investors-in-situational-awareness-des...
5•Anon84•4m ago•2 comments

New Node.js API Documentation

https://nodejs.org/en/blog/announcements/new-api-docs-beta
1•araujogui•4m ago•0 comments

Agentic Minimalism: The Human Control Loop

https://leverageloops.substack.com/p/agentic-minimalism-the-human-control
1•tosh•5m ago•0 comments

F*Ex: Frams' Fast File EXchange

https://fex.belwue.de/index.html
2•marvinborner•5m ago•0 comments

Show HN: TormentNexus – Local-first Go control plane with persistent memory

https://tormentnexus.site
1•TormentNexusAI•5m ago•0 comments

The CPU Cost of Protobuf Varints in Go

https://kmcd.dev/posts/protobuf-varint-vs-fixed/
1•ingve•7m ago•0 comments

Mixture-of-Kittens: An MoE training megakernel for NVL72

https://twitter.com/cursor_ai/status/2084670806613737919
1•OsamaJaber•7m ago•0 comments

Airtable hides a recap in plain sight

https://www.marginpoints.com/issues/2026-08-04-airtable-hides-a-recap-in-plain-sight
1•historian1066•8m ago•0 comments

White House plans to keep AI framework under wraps

https://www.axios.com/2026/08/04/white-house-ai-framework-under-wraps
2•thm•9m ago•1 comments

The Nodebook

https://www.thenodebook.com
2•handfuloflight•10m ago•0 comments

Southern California Edison equipment blamed for 2025 Eaton fire in Los Angeles

https://www.cnn.com/2026/08/04/us/california-eaton-wildfire
1•rawgabbit•10m ago•0 comments

AI-generated websites converge on each other more than human designs do

https://ai-design-convergence.vercel.app
1•Stackrift•11m ago•0 comments

Nuclear Safety Authority supports spent nuclear fuel final disposal facility

https://stuk.fi/en/-/the-radiation-and-nuclear-safety-authority-supports-the-licence-for-a-spent-...
2•iljah•12m ago•1 comments

Agentic Coding in the Wild: Characterizing GitHub Copilot Traces at Production

https://arxiv.org/abs/2608.00101
1•matt_d•13m ago•0 comments

Code Like a Pirate with AI

https://bitfieldconsulting.com/posts/code-like-pirate
1•ingve•13m ago•0 comments

Show HN: SindriCAD – open-source parametric CAD for Linux, Windows and macOS

https://github.com/MakerViking/sindricad
1•muninworks•14m ago•0 comments

People are mysteriously disappearing off WhatsApp

https://www.the-independent.com/tech/whatsapp-account-removed-deleted-rules-b3027160.html
2•Markoff•14m ago•1 comments

The session that synced itself

https://github.com/craigstoller/claude-code-sessions/blob/main/docs/the-session-that-synced-itsel...
2•craigstoller•17m ago•0 comments

Design by Contract and Effects for LLMs

https://gavinray97.github.io/blog/design-by-contract-and-effects-for-llms
2•caminanteblanco•18m ago•1 comments

A peculiar way to install apps

https://unsung.aresluna.org/as-a-windows-user-its-a-very-surreal-way-to-install-a-program/
2•colinprince•21m ago•0 comments

Surveillance-based advertising: why ad AI economics always demand more data

https://www.adreva.ai/learn/ai-in-advertising
1•abasicodes•21m ago•0 comments

Asana's Tab Shortcuts

https://unsung.aresluna.org/asanas-fascinating-tab-shortcuts/
1•speckx•21m ago•0 comments

Show HN: And now for a break: The Swimmer (1968) in Frogger Form

https://fun-things.vercel.app/the-swimmer/
1•bethanyhunt•24m ago•0 comments

Learning the ropes: why Germany is building risk into its playgrounds (2021)

https://www.theguardian.com/world/2021/oct/24/why-germany-is-building-risk-into-its-playgrounds
2•downbad_•24m ago•0 comments

New unlimited use coding agent (Standard Code)

https://standardcode.ai/
3•jpschroeder•24m ago•0 comments

Show HN: Single Reference to 3100 APIs

https://github.com/mindcloud-inc/universal-api-reference
3•frabjoused•25m ago•1 comments