Hacker News new | ask | show | jobs
by HPsquared 1349 days ago
Did you let them know? They of course need to patch this vulnerability by blocking anything containing 11 consecutive digits.
1 comments

That's crazy!

The right thing would be to add a lookup function to first verify the phone number is in use and then call the number to ask for permission to use it; followed by a webhook to send a confirmation back to the database to cache that info because this needs to be efficient!

/s

How do you propose to tackle the cache invalidation challange?

/s