Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yep, this alone is a borderline fatal flaw. The practice of sharing links, whether done intentionally or unintentionally through email forwarding, is pervasive and people won't stop to think about whether the url contains an embedded login token. This practice opens up a new class of vulnerabilities in the human error realm.

Now there could of course be ways around this like time/ip/geo pattern tracking, but that's no trivial enterprise.



And not without their own set of flaws either.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: