Hacker News new | past | comments | ask | show | jobs | submit login

> Don't they have any sort of vulnerability assessment or security code review?

I haven’t seen any evidence that they do. The last time I brought up their history of bad security practices on HN, one of their co-founders decided that the correct course of action was to come on here, accuse me of being a bad actor, and repeatedly make up quotes I didn’t say.[0] All because I tried to warn others in the community that something just like this was likely to happen again. And now it has. So, you know.

[0] https://news.ycombinator.com/item?id=25919105




Wow. After reading about the FB tracking I was wary about Backblaze but teetering on the edge of willing to give it a pass if they fixed it. But after reading brianwski's comments in that thread, the arrogance and unprofessionalism (especially in his last comment) just completely turned me off. That attitude goes beyond a technical fuckup or bad marketing move. I'm moving my backups out of Backblaze today and won't be looking back.


not to me. sounds like someone who is tired of dealing with a user that has an axe to grind for years


OK, except I’m not a Backblaze user and I never have been (except for the 14-day free trial). I haven’t had any private correspondence with them since reporting the vulnerability I discovered in 2019. This exchange on HN was the first time I’ve ever knowingly[0] interacted with this guy. If he has actually been ‘dealing with [me] for years’ in the way you imply, it has been a very one-sided relationship.

As far as having an axe to grind goes… if wanting to protect others is grinding an axe, I guess I’m guilty of that. I don’t feel like a handful of topical messages warning people of a legitimate and clearly ongoing problem is some abusive behaviour on my part, but maybe I’m wrong. I’m happy to learn from others’ perspectives, since I’m sure I could be a more effective communicator.

[0] I suspect he was the one who replied to my vulnerability report since the same attitude was on display in those messages too, but I don’t know since that account was just named “bbqa”.


for years


Astonishing arrogance. Their replies on current incident are also dismissive and arrogant. I can’t even imagine what kind of culture they have internally.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: