3 ms·
I'm sure that will change sooner rather than later, otherwise enterprising hackers will be able to claim that the model they were using went rogue.
by fastball 2mo ago
I'm sure that will change sooner rather than later, otherwise enterprising hackers will be able to claim that the model they were using went rogue.
- pjc50 2mo agoThis would be bad; we've already had a few cases on HN where someone noticed that they could increment the customer number in a URL or similar, resulting in police action.
- OliverGuy 2mo agoGot a source for that?
- voxic11 2mo agoNot from the US but https://www.cbc.ca/news/canada/nova-scotia/freedom-of-information-request-privacy-breach-teen-speaks-out-1.4621970 https://www.cbc.ca/news/canada/nova-scotia/freedom-of-inform... This news segment goes into more detail about how he downloaded the documents (by incrementing the document id in the url) https://x.com/Brett_CBC/status/984751373525901313 https://x.com/Brett_CBC/status/984751373525901313
- bornfreddy 2mo agoWow, just wow. How about charging the website builders for negligence, for failing to protect sensitive data? Simply incredible.
- jfyi 2mo agoIDOR is a well known security issue that can result in exactly the scenario described (someone incrementing a counter in a url) and has on many occasions in different jurisdictions caused legal issues for the person doing it. Unless you are specifically asking for a hn reference, which I don't understand the relevance but I'm sure they exist.