4 ms·
I thought this article was just stating the obvious over and over? The answer is _always_ auth over obfuscation.
by ctxc 1y ago
I thought this article was just stating the obvious over and over?
The answer is _always_ auth over obfuscation.
- apt-apt-apt-apt 1y agoYeah, the article is a one-liner turned into a 500-liner: Don't use a random id for security 'cause once its known, it's insecure.
- est 1y ago> this article was just stating the obvious over and over? This article gives me a lot of AI vibes All statements, no logic, no solution.
- 8organicbits 1y agoAuthor here. I used a spelling and grammar checker, but nothing LLM based. I think AI generates very poor content so I think this is a criticism. I'll solicit any constructive feedback, I enjoy writing and would love to improve.
- lioeters 1y agoSeems like the article was written as a personal journey of learning why UUID is not suitable for security or authorization in any way. For anyone with prior knowledge and experience of UUID, it should be common sense that UUID will not protect any secrets, because that's not what they're for. They're a relatively unique and unguessable identifier, that's all.
- ctxc 1y agoYeah, I guess I expected something much more interesting when I saw it on the front page (and the other positive comments)
- 8organicbits 1y agoAuthor here. I think you missed the nuance I was going for. I use YouTube and AWS as example since they both have implementations that are vulnerable to IDOR, but I think they made the right call. Sometimes usability takes preference over security. Sometimes 'obfuscation' is better than proper authorization. > There are use cases where the effort needed to individually grant users access outweighs the risk of using unlisted. Not everyone is dealing in highly sensitive content, after all.