Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is the one of the best (if not the best) solution out there I tried so far, congratulations. I am very happy to see it is from fellow HNer.


Thanks for the encouragement! I think I found your username in our DB, and I've added extra bandwidth credits to your account :)


I know you're being nice here, and I have no idea if that particular user cared, but like, as someone who has to take frequent user data/trust/privacy/handling trainings, like, don't ever do that.

Firstly, you really want to engineer your systems as much as possible so that you can't look at any PII -- and that includes things like usernames that aren't displayed to the public, and maybe even ones that are! -- as an administrator of your system, without going through some sort of "break glass in case of emergency" process that leaves an audit trail with a clear policy of when it is acceptable.

Second, even if you have access for job-related tasks, you shouldn't spontaneously try to tie user accounts to outside identities; that should be like line 4 or 5 in your data access policy. The right way to do the above would be something like saying "Thanks for vouching for us! If you message me your username @XYZ, I'll add some extra bandwidth credits to your account. :)"; that turns the interaction/demasking into something voluntary on the user's behalf, rather than you creepily stalking them through your user DB.


I can't find the pricing anywhere. How much do they charge?


1 USD/GB which is cheap




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: