Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is something I argue with coworkers et al to no end: differential privileges are targets for privilege escalation!

From their perspective, they want the ability to ban/kick/etc as special powers; but from my perspective that feature is an exploitation target that's vulnerable to any unknown bugs, and probably in twitter's case, social exploitation.

I would _much rather_ see all users be equally powerful and find some means by which the services can be designed such that everyone can be comfortable and safe.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: