frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Web security is too hard

https://textslashplain.com/2026/08/04/security-is-hard-yall/
87•kevincox•56m ago

Comments

63stack•39m ago
My main takeaway from this is not that "security is hard" but that cloudflare is pretty incompetent.
madeofpalk•15m ago
The takeaway is that everyone makes security hard. Everyone does this anti-pattern of having these other domains that defeat all their own security recommendations.

GitHub for ages had something like githubnext.com where they would make you do this same OAuth dance (except IIRC it was worse - it explicitly said that it WASNT GitHub). Apple has/had an apple.tv microsite or something they hosted content on.

Your bank will send you “legitimate” surveys or communication from some third party domain like qualtropics.com.

Joker_vD•38m ago
Another entry in "Marketing department starts a promotion campaign for the new product that's indistinguishable from a phishing attack" list. Starting with not using a subdomain on your own, very well-known domain but instead using a completely different one, then not having it shown with the rest of your services on your main web site, et cetera.
make3•33m ago
this is the correct take
derektank•33m ago
You really would think that at least in theory a company like Cloudflare would make it very easy for internal teams to automatically request new subdomains
raesene9•19m ago
Same Story as it ever was. The first time I encountered what I thought was a phishing attack at the bank I worked at 25 years ago, it turned out to be a marketing campaign, with URLs that put our company name as a user before the domain name (back in the day when creds could go in the URL).
ericlaw•12m ago
Fun fact: still can in Chromium-based browsers. https://textslashplain.com/2023/03/22/attack-techniques-spoo...
dwedge•38m ago
I guess it's easy to judge from the sidelines but was the screenshot of the site, if not the first tweet, not an obvious scam? And you can say it's from context but I only read the title before my eyes jumped to the screenshot
dwedge•37m ago
I just read the rest of the article and I'm back with my tail between my legs. I guess I made the author's point.
Hovertruck•32m ago
Don't worry, I think everyone probably went on the same roller coaster with this one
yellow_lead•36m ago
At one point in the article, the author asks Cloudflare's bot if they're launching a Wallet product, and it says no.

> There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt.

What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?

mirashii•31m ago
What’s the point? To save money paying a human to man a support email. That human would have also been hopelessly uninformed for all the same reasons.
wslh•26m ago
And as a dark pattern it adds "positive friction" for the company reducing the number of people that will have the motivation of obtaining the real people support.
sholladay•8m ago
> That human would have also been hopelessly uninformed for all the same reasons.

Not really. At minimum, a half-way decent support person would ask a few people internally or search Slack before answering.

In fact, they would have likely already heard about the new product at lunch or something.

bakugo•10m ago
The point is to signal to investors that they're all-in on the current fad, thus making the stock price go up.
thataccount•32m ago
Cloudflare is your favorite company and they are geniuses?

Dear Diary,

Today my fanboy bubble was burst.

Signed,

Author

ericlaw•11m ago
Note that I said: "One of my", and Cloudflare has hired a HUGE percentage of the best networking talent I've encountered.
thataccount•7m ago
Another company named Cisco used to do that. They built the Great Firewall of China. Hiring talent does not equal good company.
thadt•32m ago
In the movie Sneakers, a whole scene is taken up sending some guy on a date with Mary McDonnell so she could record clips of his voice. Today she'd just need a phone call or his Instagram. It's getting harder to keep up with who _people_ are online, much less organizations and domain names.

Identity is hard y'all.

sghiassy•28m ago
Just use LLMs. They can apparently doing everything and all the things
harshreality•23m ago
They probably don't value being contactable by people who can't find higher-level contact info out-of-band, because there's too much noise.
1970-01-01•17m ago
This isn't a secfail. Why is pay.cloudflare.com so hard to establish? Why does marketing always get to overpower engineering? I expect Cloudflare services to avoid some sketchy .pay TLD for exactly the reasons this person went through.
epochbtc•11m ago
Ironically, this might be at least partially because the internal security controls at Cloudflare for using or provisioning new domains/subdomains is so difficult and arduous that the team decided the fastest way to go to market is to get an entirely new domain. Possible bonus that the official bug bounty program won't apply either, since it's on a new domain so any vulnerabilities found won't have to be paid out (as much).
LocalH•11m ago
Web security wasn't hard before we started trying to make the web a platform for full executable software.

I never got hacked through the web before JavaScript (never got hacked after either, yet, but it wasn't really possible in the same way to hack someone through the web without some way to execute program logic, which in the old days would have required a much more specific browser exploit to gain RCE).

JavaScript was a mistake. Everything else after that involves "running code in the browser" was a mistake.

Program execution needs to be completely separate from "the web". I don't want any code of any sort running in my browser, at least not any that I don't fully control. "The web" was never designed to be an application platform. It was only designed to be a document platform.

andremendes•8m ago
What a ride of a read. I was 100% it was phishing and I got really surprised to find out it wasn't.

Why some people mow a lawn better than others

https://pudding.cool/2026/06/mow/
52•carlos-menezes•1h ago•38 comments

Show HN: Simple algorithm and color space to generate diverse skin tones

https://toneyalexander.github.io/inclusive-color-space/
295•automatoney•4h ago•68 comments

Hop.earth – OpenStreetMap based car racing game

https://hop.earth/?server=lkhr7&route=fQ5nuu9R
32•faebi•1h ago•21 comments

The Warp Agent CLI

https://www.warp.dev/blog/introducing-the-warp-agent-cli-coding-agent
52•emschwartz•2h ago•20 comments

Waymo – Dallas Open to All

https://waymo.com/blog/shorts/dallas-open-to-all/
16•xnx•56m ago•3 comments

Mistral's Shieldstral: 3B open-weights model for multimodal moderation

https://mistral.ai/news/shieldstral/
47•riadsila•2h ago•7 comments

Launch HN: EdotEnv (YC S26) – Quant Trading RL Envs to Teach LLMs Research

https://edotenv.com/
11•Mzzzzz•49m ago•3 comments

Investors in Situational Awareness deserved to lose their shirts

https://www.economist.com/finance-and-economics/2026/08/04/investors-in-situational-awareness-des...
6•Anon84•7m ago•2 comments

DeepSeek V4 Flash on a Single AMD MI300X

https://github.com/ryanzhou/deepseek-v4-flash-mi300x
318•zhoutong•9h ago•73 comments

When AI Benchmarks Plateau: A Systematic Study of Benchmark Saturation

https://arxiv.org/abs/2602.16763
39•doppp•3h ago•54 comments

Truemetrics (YC S23) Is Hiring in Berlin – GTM Lead

https://www.ycombinator.com/companies/truemetrics/jobs/bIQQ7tP-founding-gtm-lead
1•truemetricsIngo•2h ago

Vlt 1.0 and Hosted Package Registries

https://www.vlt.io/blog/1-0
33•patrikcsak•1h ago•4 comments

U.S. used 'virtually all' of its long-range precision missiles during Iran war

https://www.cnbc.com/2026/08/04/us-has-used-virtually-all-of-its-long-range-precision-missiles-re...
173•tcp_handshaker•8h ago•248 comments

Web security is too hard

https://textslashplain.com/2026/08/04/security-is-hard-yall/
89•kevincox•56m ago•27 comments

Keyv and friends compromised in active Shai-Hulud supply chain attack

https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack
193•cimi_•8h ago•98 comments

Apple says more ex-employees may have taken confidential data to OpenAI

https://techcrunch.com/2026/08/04/apple-says-more-ex-employees-may-have-taken-confidential-data-t...
213•thewebguyd•3h ago•155 comments

The Red Strings Club

https://www.vegard.net/the-red-strings-club-review/
5•meysamazad•1d ago•0 comments

Most countries provide between 20 and 40 paid days off

https://www.not-ship.com/not-ship-summer-vacation/
50•speckx•3h ago•38 comments

Xbox goes down. You can't play games you own on disc

https://birchtree.me/blog/xbox-goes-down-you-cant-play-games-you-own-on-disc/
457•surprisetalk•7h ago•515 comments

Blackmail Fail (2013)

https://gwern.net/blackmail
8•simonebrunozzi•1h ago•0 comments

Perspec 1.0

https://adriansieber.com/announcing-perspec-1-0/
25•surprisetalk•3h ago•4 comments

Dates That Don't Exist (2015)

https://blog.yossarian.net/2015/06/09/Dates-That-Dont-Exist
87•EndXA•3d ago•58 comments

Everything I Know (1975)

https://www.bfi.org/about-fuller/everything-i-know/
107•simonebrunozzi•7h ago•31 comments

Online ad giant Adform was hacked, proving once again why ad blockers are needed

https://this.weekinsecurity.com/online-advertising-giant-adform-was-hacked-proving-once-again-why...
159•speckx•4h ago•52 comments

Harness engineering for self-improvement

https://lilianweng.github.io/posts/2026-07-04-harness/
255•tosh•13h ago•55 comments

There Will Come Soft Rains (1950) [pdf]

https://users.wpi.edu/~zrbutzke/Docs/BradburyStories(1).pdf
298•pmg101•20h ago•335 comments

Stephen Wolfram's Wife Has Died

https://writings.stephenwolfram.com/2026/08/in-memory-of-my-wife-elise-cawley-1961-2026-with-than...
22•jdcampolargo•34m ago•0 comments

The Pedagogy Behind the Studio

https://gail.wharton.upenn.edu/gen-ai-studio/the-generative-ai-studio-pedagogy/
6•ray__•5d ago•1 comments

MariaDB: Promote getting to 10k GitHub stars in server log and client prompt

https://github.com/MariaDB/server/pull/4262
19•petecooper•3h ago•11 comments

Where .env Went Wrong

https://secretspec.dev/blog/where-env-went-wrong/
76•domenkozar•4d ago•56 comments