Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Making non-guessable IDs for broken authorization is security by obscurity.

If you have integer IDs it is also trivial to find authorization flaws on your own. Any pentester will go for it right away.

If you make non guessable IDs they might skip it and go look for other stuff.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: