logoalt Hacker News

javaunsafe2019last Monday at 11:22 AM1 replyview on HN

So We make things hard in the backend because of leaky abstractions? Doesn't make sense imo.


Replies

jcimslast Monday at 11:35 AM

Decades of security vulnerabilities and compromises because of sequential/guessable PKs is (only!) part of the reason we're here. Miss an authorization check anywhere in the application and you're spoon-feeding entire tables to anyone with the inclination to ask for it.