Hacker News new | ask | show | jobs
by brickteacup 843 days ago
it's irrelevant whether they're "cryptographically" random, all that matters is that account IDs are not controlled by the user and therefore have no logical relation to any access-control policies the user may wish to implement