Hacker News new | ask | show | jobs
by mattbeckman 2655 days ago
Company I work for was using an email verification service for the first time. We have a lot of brands, so I was being my white hat self and checking it out before we risked importing our largest subscriber brands.

It took me all of 10 minutes to find a convenient JSON endpoint with incrementing IDs that didn't disallow cross-account pulls. It wasn't a public MongoDB endpoint like the above, but we did get a pretty sweet discount rate for reporting it to them and, you know, not abusing some other customer lists with 300M+ emails.

1 comments

So you still went with them after exposing their incompetence?
„They fixed the bug and promised the data would be secure now.“ /s