Hacker News new | ask | show | jobs
by RKearney 5005 days ago
Perhaps you're misunderstanding my course of action.

1. I didn't disclose how to do it, merely that it was possible.

2. By "get" I in no way mean harvested. I just manually incremented the ID in the URL by hand in my web browser to see how many users could be affected.

3. Since I never saved any of the information (just viewed the pages) I no longer have it since the flaw was patched.

Nothing malicious was done.

1 comments

Sorry, I think I misunderstood your comment. I thought you saved some info to yourself.

I'll update my comment above.