Hacker News new | ask | show | jobs
by TZubiri 5 days ago
should be 5xx then
1 comments

Not in fact. On systems with permissions/privileges, you always return a 404 when a page does exist but the user doesn't have permission. Because sometimes leaking the existence of an item is a problem in itself.
I get the idea, but empirically, we know of the existence of that item, it's clearly very public, at least you and I have access to the fact that it exists.

On the security spectrum I'm quite schizoid, but I'd say that's too much security.

Note, curiously enough, the companies I've seen have this level of paranoid defensive security, is Microsoft. Try to send an ICMP ping to servers of different companies, you'll notice that Microsoft servers don't respond to pings. Just thought it's funny that one of the most closed source companies coincides with a source code repo on secops philosophy.