Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Have you read the SpiderOak disclaimer though?

NOTE: Logging in via the SpiderOak website does temporarily allow SpiderOak employees access to your password.

https://spideroak.support/hc/en-us/articles/115001854583-ONE...



That works for any service where you don't fully control the other endpoint. They are just being transparent. Although the wording re: website is peculiar. Could it be their form of a canary like warning?


As a developer, I expect that smaller shops' infrastructure isn't as thoroughly locked down and things like passwords getting logged to splunk/ELK is tech debt, and par for the course. However that's a very specific exception though, to the point that instead of putting work into adding that into their disclaimer, they could have made sure the password wasn't being logged instead.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: