4 ms·
An ID is like social security number. When you give it away on the street corner, who knows what other people will do with it. IMHO, leaking an ID always impos
by rizky05 3y ago
An ID is like social security number. When you give it away on the street corner, who knows what other people will do with it.
IMHO, leaking an ID always impose a risk. It is always have negative impact if leaked, no matter how perfect your system is.
- siva7 3y agoThat's hyperbolic. If your table ID poses security risks like a social security number, you've designed your system horribly wrong.
- sroussey 3y agoIt’s like one small bug that lets you move sideways to you can use a bigger and better one.
- ryanbrunner 3y agoYou're almost always going to have to leak some sort of ID in an API, otherwise your API is going to be exceptionally hard to work with. You could choose to have a separate external ID, but provided that knowledge of an internal ID doesn't convey any information or additional privilege, it's not that big a deal.
- int_19h 3y agoThe only reason why people can do dangerous things with an SSN is because it's used for authorization - i.e. as a secret - not just as ID. That's broken by design, but there's no reason to repeat that design.