Hacker News new | ask | show | jobs
by timo614 5044 days ago
There was an issue where a user could steal the nickname of other users. https://twitter.com/homakov/status/239061158043213824 https://twitter.com/homakov/status/239107933290520576

It looks like homakov had a little fun with it (the guy who griefed github a bit half a year ago with their whitelisted attributes vulnerability and got the rails core team to put whitelisting on by default).