2 ms·
Using UUIDs externally is not only for privacy, but for security as well. There are attacks that are easier if you can guess the IDs that are being used. Also,
by pazvanti 6y ago
Using UUIDs externally is not only for privacy, but for security as well. There are attacks that are easier if you can guess the IDs that are being used. Also, not all systems are meant to be scrapped or deal with user-generated content.
I remember a few years back a data leak of stored financial information because the IDs provided for them in the "My Cards" section used sequential IDs. A simple script could scrape credit card data. Yes, I know that there were other security problems as well (not checking if a user has access to that card, storing it in a non-PCI compliant way, etc.), but still, the fact that the internal sequentially-generated PK was provided to the outside world, made things a lot easier.