Hacker News new | ask | show | jobs
by Me000 637 days ago
Why is this a big deal? Hiring a contractor is 100% more insecure than this. I’m not recommending you do it, but it’s basically just people celebrating they now how to do this, but it’s actually never been exploited once in human history. Yet big brain security people trust contractors to write code and nobody bats an eye.
1 comments

This is an attack called "credential stuffing" and the OWASP page for it has multiple examples of it being used in the real world: https://owasp.org/www-community/attacks/Credential_stuffing .