Hacker News new | ask | show | jobs
by cartothemax 957 days ago
Yep, you're correct. Panera had an issue where folks could scrap every user profile due to sequential profile ids. The bigger part of the exploit was they just openly exposed user data but making the profiles ids sequential made it really easy to scrap

https://krebsonsecurity.com/2018/04/panerabread-com-leaks-mi...