4 ms·
Wouldn't it be better to perform a server side lookup to avoid leaking the full list of currently used Barclays numbers in plaintext to fraudsters? The fact th
by wwwaldo 5y ago
Wouldn't it be better to perform a server side lookup to avoid leaking the full list of currently used Barclays numbers in plaintext to fraudsters?
The fact that there isn't any user input sanitization makes me inclined to believe that this implementation decision may not have been well-thought-out (which I'm guessing was the author's point exactly)
- notatoad 5y agowhen you're offering a service designed to expose a list of numbers, there's no way to design it in a way that doesn't expose that list of numbers. given enough time, a motivated person will extract all the data. most likely, this page started out as a list of all 74k phone numbers, and at some point somebody built a lookup tool on top of it. there's no reason to assume that keeping the full list secret was ever a design goal.
- mnd999 5y agoSure, but Barclays made it trivial.
- code_duck 5y agothat is mentioned at the end of the article. >why not POST the number to a service which can be updated?