←back to thread

668 points wildmusings | 1 comments | | HN request time: 0s | source
Show context
JorgeGT ◴[] No.13027099[source]
And without an "edited" mark, which means that any comment of any user can be covertly modified by an admin. Very concerning since Reddit comments have provoked even Congress hearings: http://thehill.com/policy/national-security/296680-house-pan...
replies(7): >>13027119 #>>13027125 #>>13027136 #>>13027240 #>>13027734 #>>13028391 #>>13033721 #
dhruval ◴[] No.13027240[source]
He changed a 'F U CEO' (upvoted by 1.6k users) comment to 'F U unpaid reddit moderator', without any indication that the comment was edited.

Very juvenile and unprofessional way of dealing with the situation, really erodes trust in the platform (simply deleting the comment would have been a better response).

Would maybe expect this from the founder of a young fledgling startup, but the 33 year old CEO of a company like Reddit ought to know better.

replies(7): >>13027341 #>>13027345 #>>13027894 #>>13028550 #>>13028557 #>>13031901 #>>13032509 #
ozgune ◴[] No.13028557[source]
I met Steve several years back while going through YC. He's a much calmer and nicer person than most founders I've met, myself included.

If I read this Reddit thread without knowing him, I would have deemed him unprofessional and maybe even upvoted some of the comments.

When I read the thread knowing who he is, I'm thinking "I can't imagine how stressful it must be to run Reddit. He made one mistake in a bad day, apologized for it, and now everyone's talking about it. Steve's way nicer and more professional than I am, so I would probably have messed up big time in his shoes."

replies(5): >>13028602 #>>13028796 #>>13030391 #>>13030533 #>>13031284 #
icelancer ◴[] No.13028602[source]
This is a mistake that has profound implications. Not just your average mistake like "I broke the build and didn't tell anyone" nonsense.
replies(1): >>13028820 #
yarou ◴[] No.13028820[source]
You're being awfully charitable. It's on the order of magnitude of royal fuck-up. How can any user expect to be safe on Reddit anymore?

This is the sort of situation that irrevocably damages trust. What's the guarantee that this won't happen again?

What bothers me more is that this sort of functionality exists in the first place. All it would take is one compromised admin account, and boom, you can rewrite somebody's entire comment history without it being logged anywhere.

replies(2): >>13029014 #>>13033681 #
thecatspaw ◴[] No.13029014{3}[source]
the functionality is probably a UPDATE comments where id=x set content="newcontent"
replies(2): >>13029097 #>>13030030 #
iguana ◴[] No.13029097{4}[source]
Operationally, the CEO should probably not have write access to a master DB.
replies(1): >>13029348 #
thecatspaw ◴[] No.13029348{5}[source]
the CEO is one of the original developers as I understand it, which is probably why he has access to it. but you are right, he should not have it
replies(1): >>13030470 #
1. ryanSrich ◴[] No.13030470{6}[source]
So since the founding of Reddit in 2005 and now—we're expected to believe that Reddit hasn't hired a single security expert, engineer or otherwise which has rightfully removed any unnecessary access to user data? This seems incredible to me.