Comment on: Security Is Hard, Y'all
At one point in the article, the author asks Cloudflare's bot if they're launching a Wallet product, and it says no.> There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt.What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?
Comment on: Show HN: Solving a very old problem — passwords
I think there's a big chicken-and-egg problem here since why would websites use it before there are users?But it also seems like it would be too much of a hassle for users. If they let their browser or Lastpass save the passwords, they can log in automatically without multiple steps involving a phone. I mind having to take out my phone for regular 2-factor authentication but I normally only need to do that once for each device. I also find that I would rather type in a couple digits than wait for a camera and QR code recognition.
Comment on: Web security is too hard
Web security wasn't hard before we started trying to make the web a platform for full executable software.I never got hacked through the web before JavaScript (never got hacked after either, yet, but it wasn't really possible in the same way to hack someone through the web without some way to execute program logic, which in the old days would have required a much more specific browser exploit to gain RCE).JavaScript was a mistake. Everything else after that involves "running code in the browser" was a mistake.Program execution needs to be completely separate from "the web". I don't want any co
Comment on: Web security is too hard
If you have no training or knowledge-base to search, sure. But then you'd be an awful support-team employer.
Comment on: Web security is too hard
Several weeks ago I had an issue not being able to login to Verizon's website, so I tried to chat with someone. The chatbot that was gatekeeping was predictably useless said it would redirect me to a human except...it kept prompting me to log in first. It was literally impossible to differentiate from if they literally had no humans online to talk to at all.
Comment on: Cloudflare enforces engineering standards using AI
Meanwhile: https://textslashplain.com/2026/08/04/security-is-hard-yall/> The Cloudflare folks apparently want security issues reported via HackerOne (which wouldn’t let me log in because the Cloudflare CAPTCHA HackerOne uses seems to be broken…).