Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Did you consider a "silent alarm", that only phones home without displaying an error?


No. Perhaps the most important part of this is keeping the user informed.


What do you think most users would (and should) do if they were told your hosting provider was injecting scripts into the page? Stop using your site?


Hopefully. The alternative (silently alert and hope I pick up the phone) might not be so bad for users if a hosting provider is running analytics or ads, but from a detect-and-alert perspective it's pretty hard to tell the difference between a scummy-hosting-provider script and a credential-scraping bonafide hack. Many people (or robots) who install the latter aren't smart enough to defeat alerting measures, so it's a big benefit if those measures warn the users directly.


Your question is the difference between marketing and craftsmanship. Are you primarily proud of your product or trying to increase your traffic?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: