top | item 37796923

(no title)

nemacol | 2 years ago

How do you hide authenticating 1.3+m unique accounts? A distributed system? A mess of VPN's? Or they don't hide it because the auth system is not checking for 1.3 million auth attemps?

discuss

order

juunpp|2 years ago

The latter. Forget tracking auth attempts:

> The researcher added that he discovered another issue where someone could enter a 23andme profile ID, like the ones included in the leaked data set, into their URL and see someone’s profile.

jtriangle|2 years ago

Ah, so they were able to use a few accounts, then fuzzed the URLS to victory...

Amazingly incompetent.