Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A lot of people are arguing about whether locking down access was justified to resolve the security issues. I guess it's debatable.

But I don't see any excuse for not putting out a statement when you do it. You have to know there will be a fight, and you will look like the bad guy. Perhaps I could see directly communicating to the maintainers that you expect that they'll be reinstated. But to say nothing? To let the post by duckinator float around for days without having a "we did this because of security concerns, we want to work together and find a resolution..." It's incomprehensible that they thought this would go well.



I mean imagine you are at work and you need to so this for SOC2 or something but dont tell your colleagues.


Firstly, you can tell them you’re working on SOC2 compliance, and secondly, those colleagues are getting paid in dollars, not doing it for the love of the work.


> Firstly, you can tell them you’re working on SOC2 compliance

Bingo




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: