|
|
|
|
|
by Robin_Message
4677 days ago
|
|
Putting the user id in the request is obviously wrong, since the owner can looked up from the photo id. Automated testing/fuzzing could find this, but probably better training/practices would be easier to get right and save time/money in the long run. |
|
While Facebook most likely does do some form of threat modeling for their main site, without a rigid process for all code that goes public you'll run into issues like this that are just as severe. Just because it's a mobile support site for requesting photo removals doesn't mean it is less important surface area in terms of security.