Y
Hacker News
new
|
ask
|
show
|
jobs
by
MrKristopher
1881 days ago
If your object IDs are 1, 2, 3... then attacker can check all the IDs. If instead each object ID is a 256-bit UUID, then the attacker can't make a query for every possible object ID.