3 ms·
> IME It's easier to teach junior devs not to use integers than it is to get them to think holistically about security. IMO, explicitly prohibiting unauthorize
by vectorpush 10y ago
> IME It's easier to teach junior devs not to use integers than it is to get them to think holistically about security.
IMO, explicitly prohibiting unauthorized access to an API endpoint is a basic security tenant, not a "holistic" one. if iterating through an API's integer key sequence results in unauthorized access to data, replacing the integers with UUIDs only masks the problem and I'd say is a classic example of how relying on obscurity for security can be a pernicious mistake, especially for a novice developer.
- drumdance 10y agoYes it is a basic security tenant. But sometimes you're working with a legacy API and/or a bad auth mechanism. Not every project is greenfield or is maintained by senior devs.