Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It also makes it slightly easier to perform certain attacks since it's trivial to figure out other IDs.


Making non-guessable IDs for broken authorization is security by obscurity.

If you have integer IDs it is also trivial to find authorization flaws on your own. Any pentester will go for it right away.

If you make non guessable IDs they might skip it and go look for other stuff.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: