Hacker News new | ask | show | jobs
by MrKristopher 1881 days ago
If your object IDs are 1, 2, 3... then attacker can check all the IDs. If instead each object ID is a 256-bit UUID, then the attacker can't make a query for every possible object ID.