Hacker News new | ask | show | jobs
by garblegarble 2911 days ago
>I don't buy this explanation because the setup would be hilariously insecure.

I work in the industry, I 100% buy this explanation. Security is not great on all sides, confusing UIs and opaque IDs pasted into web systems (or excel spreadsheets) with little/no feedback (or excessive feedback that then gets ignored) are standard.

Also, even when media isn't directly available to a user, they may well still have the ability to send a particular file by house number through a pre-approved workflow (e.g. publish to youtube)