Skip to content

Comment on XSS Twitter in minutes; Why you shouldn't store important data with 37signalsparent

Comments

He addressed your second point, and your first point isn't reasonable. Product "security" pages don't need to read like SEC disclosures.

Compare their security page to:

* http://www.salesforce.com/company/security.jsp

* https://www.paypal.com/us/cgi-bin/webscr?cmd=xpt/Marketing/g...

* http://www.apple.com/macosx/security/ (heh)

* http://www.webex.com/pdf/wp_security_overview.pdf

* http://www.netsuite.com/portal/infrastructure/main.shtml

Don't ask 37s to meet a standard that nobody else meets. It's just muddying the real issue, which they're clearly trying to address.

This comment, btw, isn't about 37s. It's about the singularly bad advice that web startups should have a fully-transparent conservative "security" page that talks about cross-site scripting and CSRF attacks, when their competitors have pages about "state of the art firewall security". To normal people (ie, customers), the "state of the art firewall security" people sound like they know what they're doing.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.