logoalt Hacker News

Sharlintoday at 1:57 PM2 repliesview on HN

Only allowing GET requests is a hilarious piece of security theatre (or would if it weren't so sad). Everyone knows that GET is read-only only by convention. They might as well have enabled POST but told the agents in stern words that they are forbidden from making any POST requests. (Of course, if these things were anywhere near aligned, they would actually honor that, no matter how many utilons cheating would be worth.)


Replies

mikert89today at 4:49 PM

some ivy league grad with no real world dev experience waved this on

elar_veroletoday at 2:12 PM

didn't notice your comment so posted a similar one - but yeah this is a very high level of inexperience to me... You'd think they would have some of the greatest security experts in there

show 1 reply