On January 29th a HN user, 'jiganti', posted this: "Ask HN: I think I've been scammed - what now?" (http://news.ycombinator.com/item?id=2157281)
Starting in the evening of January 30th, posts began to appear on complaint forums with my name. These posts claim that I am a pedophile and that I have stolen money. These posts are false and I find it unsurprising that they began to appear after I provided information about the possible identity of jiganti's scammer. My name and phone number are easily Google-able, however, I provide it here in case anyone wishes to call me: Louis Marascio, 512-964-4569.
I'm posting this because although jiganti's post fell off the front page, this story is not over. Other HN'ers and I dug up some information about the possible scammer in the original thread. Also, I believe jiganti might not be the only person who's been taken by this guy. Please read the post and thread in full. This sub-thread specifically discusses our findings: http://news.ycombinator.com/item?id=2158590
Our most promising evidence is this: the responsible party is a single user that has at least three handles here on HN: pinksoda, sinkfloat, and BrianHolt. This has not been proven nor has it been denied, and I repeat the last sentence of my findings: I encourage the owner(s) of the HN accounts pinksoda, sinkfloat, and BrianHolt to speak up--and if I'm wrong I apologize.
I re-urge you to read the post, the subsequent conversation, and the other linked-to Hacker News posts and make up your own mind. Hacker News is a tight-knit community, and if there is an unsavory character here who's using it as a way to find and exploit young entrepreneurs, then I feel we need to all be made aware of this. If a scammer does exist amongst us, let's all hope a little light will cause him to slither back into the hole he came from.
It is important to note that 'mahmud' is mentioned in the first paragraph of the original post. mahmud IS NOT THE SCAMMER. The original poster lost his ability to edit the post before he could clear up what he meant. This is specifically discussed in this sub-thread on the post: http://news.ycombinator.com/item?id=2157602
Passwords and cookies in clear HTTP are no good. Anyone here (should) knows it. Firesheep proves it. GMail and Zuckerberg suffered it.
Just buy or get a free SSL certificate, and let nginx or stunnel handles SSL and proxies HTTP to/from Arc. Total cost, being pessimistic: 150$ for the certificate verification, and 2 hours to set-up the certs & nginx.
I know, it's awesome, it's a custom Arc webserver and all, and good practices are for PHBs only, but still. For a "hacker" website, news.ycombinator.com is a shame regarding to privacy/security (see also: passwords stored as shasums (without even a salt), funny things like <img src="http://news.ycombinator.com/logout>, outdated versions of software used [http://news.ycombinator.com/item?id=516122], etc.)