4 ms·
It seemed to me like they actually got explicit consent to have guest permissions to view this information, I am honestly pleasantly surprised. Once I saw them
by neltnerb 3y ago
It seemed to me like they actually got explicit consent to have guest permissions to view this information, I am honestly pleasantly surprised. Once I saw them looking at the security tokens I got worried, but they pulled it out of a tailspin pretty quick.
> Because we can’t instruct students to copy-and-paste the URL (and thus their session key), we needed another way to access students’ transaction history. We turned our attention to JumboCash’s guest access feature.
I am going to take "can't" as "were not willing to" which is more impressive. It sounds like they could pretty easily have convinced people to give them a lot more access than they realized, and chose not to go that route.
- hunter2_ 3y ago> I am going to take "can't" as "were not willing to" I disagree. I take "can't" as a reference to this earlier statement: > Change to another IP address, and it…breaks? I.e., they would need to not only ask for the key, but also use the same IP address that the key was generated with. Depending on what sort of NAT may or may not exist on campus, that could be difficult or easy.
- deleted 3y ago[deleted]