Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Expiration helps very little if the valid IDs are still easily enumerable. Access control, not expiration, is what is called for here.

Edit: expiration would limit the scope of data leakage, and should also be looked into, but expiration without access controls still allows patient attackers to collect all of the data being generated and store it for future use.



Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: