Hacker News new | ask | show | jobs
by Closi 164 days ago
I've posted elsewhere, but I still have lots of issues personally:

* Your deletion policy says you delete images instantly and via the UI in settings, but I've checked and they are retained in the object store. You need to update these policies to be honest and say that the images aren't deleted, and that you currently retain them and just delete the reference to them.

* Your privacy policy says you can't see user content, but you clearly can (as you have both the data and the encryption keys). You might not have developed the functionality to read it yet - but it is trivial to do. Just be honest and say 'your data can technically be accessed by us, but we promise not to look at it'.

* Your privacy policy only limits your access to 'what is allowed by law' - which is clearly the absolute minimum!

I think your policies currently say how you would like it to be, rather than how it is. You need to be honest with users about how their data is actually processed.

1 comments

Respect to you and David for trying to help, but eventually you're going to experience Brandolini's law here.

OP is frantically pasting your findings into an LLM and letting it excrete another blob of untested, unverified shit. "It WILL be secure this time!", the LLM says, hopelessly.

OP does not care about whether the tool is built on solid appsec foundations. OP cares about the 0.00001% chance of getting interest in his tool from $VC_FIRM.

You've indicated that this tool already has a bright glowing all caps DO NOT USE verdict and no reassurance from a coding-agent-in-a-loop will make it better.