|
|
|
|
|
by codeflo
1844 days ago
|
|
> they are not easily guessable I don't see how that's true. From reading the article you linked, you only need a valid shard ID (which you can extract from known IDs), the millisecond (which is guessable) and a 10-bit sequence (which you can easily brute-force). (And that's completely fine if their security model doesn't require unguessable IDs.) |
|
It will results in a very high number of 404s. These can be monitored and the origin IPs can be banned.