Hacker News new | ask | show | jobs
by ben509 2761 days ago
I can confirm that names and email addresses are classified as saltysugar states, and the security reviews. So they do have to pass all those requirements for secure storage and transmission, but then names and emails are made visible by default through mechanisms like reviews, profile, wishlists, and that passes the review because it is the user's choice.

I don't even think this is anything nefarious by Amazon. It's more that teams dedicated to security issues consider it out of their lane to deal with conflicts between the designed UX and actual user expectations; especially for privacy issues where even asking the person isn't a reliable way to understand what they want.

1 comments

> saltysugar

Can you elaborate? I've never heard this phrase before and google results aren't very helpful.

It's not a policy, it's the username of the parent's poster.
LOL, now I realize the wisdom of not referring to people by usernames... "saltysugar states" sounds completely plausible.