Hacker News new | past | comments | ask | show | jobs | submit login
Token Fixation in Paypal (homakov.blogspot.com)
84 points by johnterry_cfc on Jan 12, 2014 | hide | past | favorite | 15 comments



I'm annoyed every time homakov posts a vulnerability. He writes in a way that belittle his target, like everyone is stupid except himself.

Also, I really dislike how he handles his disclosures.


FYI, Homakov started out with a slightly different tone, over a year ago, and posted a few items to HN (https://news.ycombinator.com/item?id=3791281, which got flagged to death, and https://news.ycombinator.com/item?id=3778158).

The reception he got here was really not great.


Public ridicule is sometimes a good tool to move people into action. Sometime not the best approach, but, it's funny for those who dedicate their lives to doing this kind of work.

In the security community there's a pretty deep-rooted sense of humor towards "unexpected enlightenment". It's not really directed at anybody - It's mostly directed towards the mindset or theme of ignorance.

(At least, socially...)


How i belttile target and whats wrong with disclosure after paypal refuses to fix?


Sure, but PayPal is stupid and deserves the condescending tone, so it's not annoying in my opinion.

People who refuse to fix security flaws when informed of them are being stupid, yes?


His writings do carry a condescending tone, with a faint "l33t hax0r" taste. I think it might be a case of a sudden fame multiplied by the teen spirit :)


I would give people the benefit of the doubt. Especially when they're writing in a language that isn't their mother tongue.


Condescending tone? Where omg


I hear from a source very high up in PayPal that a large part of their codebase is evolving at this point and that in the next couple months, we should be seeing a wide range of developer-friendly changes. I'm not advocating PayPal nor do I have any financial interest in PayPal, just pointing out that they acknowledge how far behind they are and desperately trying to catch up.


> how far behind they are and desperately trying to catch up

They are merely the market leader ...


Definitely not a market leader in developer experience.


When you're the market leader, you have to work twice as hard as the next guy in line. Paypal has at least 2 companies plus Bitcoin threatening to replace them at any given moment.


PayPal doesn't have to worry about being replaced as much as it has to worry about being marginalized. If a developer who has never integrated payment into their app asks me what platform to use, I'm going to answer "Stripe" without hesitation because they make it very simple for developers to use. PayPal needs to shift its focus toward making the developer experience better, because right now their documentation is a steaming pile of shit and their web interface is unintuitive.


I've heard this one before. From a source in PayPal. Years ago. (although admittedly I don't know how high up this source is)


Considering they recently rewrote/moved major services to node.js, that might actually be true this time.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: