Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So far I've found that making it seem to the bad actors that nothing has changed is most effective at keeping them from getting worse.

Right. The quality of feedback information is one of the biggest factors in development cost. The bugs you can't reliably recreate are the biggest problems, sometimes by one or two orders of magnitude.

This should be used as a weapon in the security battle. Seems like not enough people use it.

In all likelihood, the scam initiator is not the same person as the scam implementor, so "making it seem to the bad actors that nothing has changed" is likely to inflate their costs tenfold. This also works when the scam is entirely the work of one person, but it's especially effective when multiple parties are involved.



    Seems like not enough people use it.
Well, since this is a tactic that works best if the bad actor never finds out about it, isn't it possible lots of people do it without ever talking about it?

Relevant Coding Horror http://www.codinghorror.com/blog/2011/06/suspension-ban-or-h...


isn't it possible lots of people do it without ever talking about it?

I hope it's the case.


Some following this thread might find Tarpits interesting if they don't already know about them: http://en.wikipedia.org/wiki/Tarpit_(networking)

Do you guys know of any other techniques that waste the malicious actor's time making it think everything is a-okay?


Disciplined users - (http://meatballwiki.org/wiki/UsAndThem)

This usually fails because someone isn't strong enough to not respond. Or someone engages because it's a fun conversation for them. Examples of this on HN are some of the political discussions (eg Palestine) where people really should just flag and ignore but often people engage.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: