Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't understand why you would have been expected to report this to Google. It's not an issue or bug with Google, it's a simple gray hat social engineering trick.

People linking to fake sites as a dark pattern is nothing novel, you just did so too capture analytics instead of, say, installing a virus or taking someone's credentials. That said, you certainly could have done the latter and gotten views into your competitors' user portals. In my head that's not fundamentally different or more unethical from what you ended up doing.

I don't necessarily begrudge you for trying it, but I don't think it's for a noble reason nor do I think it was particularly innovative and the end result is Google doing something unsurprising.



The expectation isnt to report to Google. The expectation is to not do this on live sites affecting real people.


the reference is to text in the article, not comments from HN.

From the second paragraph:

> Many are suggesting the right way is to approach Google directly with security flaws like this instead of writing about it publicly.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: