Hacker News new | ask | show | jobs
by ineedasername 3108 days ago
The bug response was laughable "yes with unrestricted acess to an account you can steal data from it".

This makes it sound like "with enough time and patience anything is possible"

But the steps described aren't even what i would call a hack. You could do them by accident if you were trying to log in to your own account under someone elses computer using chrome, in less than a minute if you're quick. It requires no technical knowledge and can be done with time to spare during someone's bathroom break.

Here's the process in a nutshell:

1) logout of their account in chrome.

2) login to you're account

3) lie and say you were the previous per person

This isn't a hack. There is no hack! This is a very small step above the "honor system" as your security!