Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

[flagged]


Very believable. Many, many years ago when auditing a health company website we found a similar "exploit". If any member of the public created a record, there was a page which was (something like) /display.php?record=123. Needless to say if you altered the ID you could read every other medical record. The company took some persuading to even understand that this was a problem, never mind actually fixing it. (Since this was a commercial job, I won't mention the company name)


It happened as described. Before it happened, I didn't think there were people like that in this world.

To his credit, the family member took it as a life lesson and moved on (probably more than I have given my posting here). These days he deals with companies that value his contributions, and it turns out that his ex-employer's loss is other companies' (significant) gain.


[flagged]


What's so utterly unbelievable about this story? Like, almost none of it is surprising at all.


[flagged]


This is true, but I'm not gonna shout you down as a liar for such a statement either, unless I had some evidence to the contrary.


So you're so utterly convinced they're lying about this because....




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: