Hacker News new | ask | show | jobs
by freedomben 1400 days ago
That's undoubtedly true, but you'll also get a lot of assholes and script kiddies hoping to pwn your site for lulz, and they often don't care who gets hurt along the way. By posting you've just given them an easy legal defense. If it were me, I wouldn't do it. Not worth the risk.

I would however, probably be willing to DM people individually after doing a small amount of due diligence on their comment history. I guess it depends on sensitivity of the site and how desperate they are.

2 comments

That is such a weird take. You get assholes and script kiddies the moment your IP interface starts accepting packets. If you don't advertise to people who can help you (be it customers or potential advocates/partners) then what on earth are you doing?

I put my company's website in my HN profile. Go ahead, make my day.

(I'm not the OP and as far as I know don't have any security issues)

> you'll also get a lot of assholes and script kiddies hoping to pwn your site for lulz, and they often don't care who gets hurt along the way.

Yes... "Free security assessment" was a euphemism I'm afraid.