Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ah, makes sense. I guess they just assume that any client who is requesting to sit in that seat is authorized to.


Yeah, the seat is the problem. There are a LOT of security systems that depend on assuming the holder of a large random string, like a guid, is the proper holder of that string so it's not necessarily a bad thing for the match. They should have made the seat index random as well though they are probably now just checking credentials.


Looks to me like they only verified match ids, not the seats at all.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: