Hacker News new | ask | show | jobs
by badclient 4637 days ago
Looks intriguing and I can tell you guys have spent a lot of time on the feature-set. But the biggest thing that will hold me back(and may be others) is a lack of clarity about security and my data(what happens in the event that you are down? in the event that you close shop?)
5 comments

OP here.

This is something that we are very aware of. We only have good intentions and want our users to feel 100% secure with us. If you don't, please let us know how we can change that! :) We don't have it now, but we will make it possible to export all of the data in UserApp at any time.

Regarding security and privacy we have written a section about it here: https://help.userapp.io/customer/portal/topics/550128-securi...

Additionally, everything is SSL and passwords are stored using bcrypt. And we will make it possible to login using 3rd party providers later (OAuth). From a personal perspective, we will run this ship to the end of the world if we have to. Since we're developing quite a few other services (www.amail.io to mention one) we are also basing all our services on UserApp.

This sounds pretty good at a first look - so why do you bury it somewhere deep in the help section?
Yeah its the number one concern with this type of product. So it might even be good to have a security section on the front page, to ease nerves.
OP here.

I totally agree. Don't know how we could miss putting it up there. I will see to it that this gets the attention it needs on the front page. Thanks! :)

Could you do nightly SCP backup of my entire user database to my own server?
Seconded. How is user information stored? What's your crypto scheme? Can I get all my data out of the system if you go down or I want to change platforms?
Exactly what I thought! I find it nice, but why would I let a third party manage the most critical part of my platform : my users? You close shop unexpectedly, I close shop. You are down? I am down too.

The dependency between my system and this one would be way too great to consider the option.

Yes, same here. Where and how is the data stored, whats about security? After all, their business model means that they are dealing with one of the most precious parts of other businesses, so I would expect way more information here.
I am on the same boat and I'd suggest that apart from answering here you should put the relevant information on the front page of your project also. It'd be a pity to lose customers because of lack of clarification.