|
|
|
|
|
by 0xeeeeeeee
4373 days ago
|
|
It's a data leak...very similar to snapchat's issue and the Apple iPad fiasco found by weev. It's pretty sad that an App with almost no functionality had any problem. It's also interesting how these developers seem to repeat this exact mistake over and over. I don't understand how people don't see a public facing API call for mapping usernames to phonenumbers or phonenumbers to usernames as a bad idea... |
|
E.g. https://news.ycombinator.com/item?id=7920558
Like I said, security is hard. Microsoft is the only large corporate I know of with a published security development lifecycle, and while it's starting to benefit their products they're still not getting it 100% either. Security is also contentious, because doing it right means forsaking the idea of an MVP. It also requires design up front. And experience. These sorts of things are not exactly aligned with the hacker mindset, nor with startup culture.