logoalt Hacker News

0x3flast Monday at 12:35 PM1 replyview on HN

The whole point though is that the ID itself leaks info, even if the profile is not public. There are many cases where you reference an object as a foreign key, even if you can't see the entire record of that foreign key.


Replies

nish__last Monday at 5:49 PM

I can't think of any.

show 1 reply