Hacker Newsnew | past | comments | ask | show | jobs | submit | larrymcp's commentslogin

I agree; I'm calling "incorrect" on this for now, pending corroborating sources. I run a few sites that don't contain a robots.txt file, and they are showing on Google just fine. I see links to the home page and several interior pages; all good.

Because you can see pages not affected doesn't guarantee they will stay that way.

Ah, I think I recall the story you're referring to: reporter Josh Renaud of the St. Louis Post-Dispatch discovered that a public web site was exposing Social Security numbers of teachers in Missouri. He notified the site's administrators, and later published a story about the leak after it was fixed.

The governor of Missouri at the time, Mike Parson, called him a hacker and advocated prosecuting him. Fortunately the prosecutor's office declined to file charges though.


Can anyone elaborate on what they're referring to here?

> GPT‑5.2-Codex has stronger cybersecurity capabilities than any model we’ve released so far. These advances can help strengthen cybersecurity at scale, but they also raise new dual-use risks that require careful deployment.

I'm curious what they mean by the dual-use risks.


"Please review this code for any security vulnerabilities" has two very different outcomes depending on if its the maintainer or threat actor prompting the model


“Dual-use” here usually isn’t about novel attack techniques, but about lowering the barrier to execution. The same improvements that help defenders reason about exploit chains, misconfigurations, or detection logic can also help an attacker automate reconnaissance, payload adaptation, or post-exploitation analysis. Historically, this shows up less as “new attacks” and more as speed and scale shifts. Things that required an experienced operator become accessible to a much wider audience. That’s why deployment controls, logging, and use-case constraints matter as much as the raw capability itself.


Finding/patching exploits means you also can exploit them better?


They did some interesting wordsmithing here to cover their ass without saying it directly.


What they said sounded pretty direct to me.


probably that it's good on tasks of either color teams, red or blue - and if it is, it means you can automate some... interesting workflows.


Good at finding/fixing security vulnerabilities = Good at finding/exploiting security vulnerabilities.


I think I understand where he's at. If your web site has compatibility issues with smaller browsers like Firefox at 3%, Opera at 2% etc. then you could be losing out on 5% of your sales. If you were to approach any CEO and ask if they'd be interested in an initiative to increase sales by 5%, they would most likely express an interest.


there is good chance whoever site didn't worked for will just switch to chrome for that site. I did that few times.

We have "any browser above 5% market share" in deals with our clients. So FF testing is not even required


I mean, I don't object in principle, I in general consider this to be "doing a good job" that we all strive for, but in this particular case it was a "line of business" app with like 500 users so I genuinely hadn't even considered it. We'll see if it comes up later!


> starting from ground zero

You probably mean "starting from square one" but yeah I get you


> I had one client spending $12,000 per month on Google Ads

In Google Ads you can just turn off the option to run your ads on non-Google sites; I think it's called their Display Network. Just run your campaign only on Google's search pages.

I'm surprised the article doesn't mention this rather common solution.


Here's an archive link: https://archive.is/w0izj


Here's an archive link: https://archive.is/w0izj


Fantastic. Another great one that blew my mind (and P&T's) is Nick Einhorn from the first season, https://www.youtube.com/watch?v=ma-S9-bgvlg&t=77s


Nah this trick is crap, it's just stooging. Kind of disappointing they let it on.


They don't allow stooges in the show.

And the magician cannot lie, since he/she has to convincingly explain how the trick works to the producers, beforehand.


The funny thing is, this error message is hardly less useful than the recent trend of error messages which say only, "Something went wrong".


Have you never dealt with customers reporting errors?

Something went wrong is what they will tell you and expect an answer. Doesn’t matter how fancy and detailed the error, you will get back, “it’s broken fix it.”


Back in the early days of my career and supporting end users, I used to constantly get people say:

   “xxx doesn’t work. I just get an error”
They would never tell me what the error message actually was. And when I asked, the reply often was

   “I don’t remember. I’ve closed it now”. 
It used to wind me up rotten. I can forget non-technical people not understanding the error message. But common sense should have kicked in that the error message is important to share with the person trying to fix said error.


Maybe all errors should be presented with a simple, distinctive and memorable theme - e.g. show a pig photo in that one maybe they'll remember "I got the pig error"


> Maybe all errors should be presented with a simple, distinctive and memorable theme - e.g. show a pig photo in that one maybe they'll remember "I got the pig error"

This sounds like the thing that they do in parking garages where each level will have a color, an image, or sometimes even a musical theme. (Which is to say, it sounds like a good idea!)


Could make cute pictures and brighten support staffs day. 'I got a pig telling a chicken that the barn is closed??'


I was thinking celebrities, but then people will misidentify them.

Each micro-service (in 2025?!?!) would have different pictures of a particular celebrity, for different errors.. so if the user says e.g. "I see Taylor Swift doing..." the support can say "Let me forward you to the S3 people!".


How much do you want to owe in license fees for their likeness?


Oh, boring bean counters...


Animals are way more cross culture compatible


lmfao this is genius and would work better than text


That’s a good idea - and even technical users would find that more memorable than 1198854 versus a 1197854 error.


I think you're going to find people mistaking one animal for another.


Error detecting/correcting codes!

The pig is laying down.

The horse is eating.

The bird is sitting.

If you say you saw a pig eating, you misremember.


You can dunk on lay people all you want, personally I'm a lot more furious about fellow programmers who thinks it's OK to show an error that says "file not found" without any context like the filename.

Like, help a brother out!


Writing helpful error messages is definitely a skill. And I too get annoyed at unhelpful error messages.

But I don’t think your point invalidates mine.


What would you expect? IME these are mostly unforeseen 500 errors, logged internally, and not something a client can do anything about (or should know anything about, for security reasons).



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: