Hacker News new | ask | show | jobs
by street 3407 days ago
Yup, perhaps they put the username of the logged in user in an encrypted/signed cookie, and the private key was in the source code.