Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Really useful messages might contain a lot of details about the tech stack you use (giving a nice hint into which CVEs to try).

Nope. Useful messages contain details about what your software does. Anything about your tech stack is redundant and can be removed.

> The best solution is to aggressively log errors AND prioritize having dev teams push that error count to 0.

Many errors can only be replicated talking to users. And on the cases your dev team is not all capable enough to remove all errors, you will still want to provide customer support and work-arounds.

> The next way to solve it is simply a report button.

A report button is good. But neither session ID nor any data that you can reasonably add to your logs will be enough to let dev know what went wrong. Besides, your report button will have errors too.

And anyway, anything that you said applies exclusively to people that create web applications. Many other types of application exist, and everybody writing them are better off not following any of your recommendations.



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: