Hacker News new | ask | show | jobs
by martswite 5478 days ago
If what the article says is actually true that simply changing account numbers in the URL allowed them to access other accounts, then I'm completely astounded.

Surely this is one of the first things a programmer learns. It's just basic security.