Hacker News new | ask | show | jobs
by tinlicker 3350 days ago
See also the HTTP shopping cart: http://ebiz1.uspto.gov/vision-service/ShoppingCart_P/ShowSho...

Probably the only thing keeping this from being abused is that it's the government, it's a low-value target, and they're paying millions upon millions for someone to support this trainwreck with security patches.

1 comments

Of course - obscure as it gets, session state based navigation and top of it off with username/password form over unencrypted HTTP.