Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The results absolutely do matter. If you're running a site, you should be auditing the areas where the security risk is the greatest and taking extra precautions, and those areas are hopefully few. If you're not first taking care of the places where the results are disastrous, then you're doing it wrong.

Obviously if there is a known attack vector, you would fix any similar issues everywhere, but not all code is the same.



The point I was making is that this particular flaw is indeed the same as the UPS flaw when considered at a high level - modifying a URL caused sensitive data to be disclosed.

In practical terms, of course the nature of data that is disclosed is relevant. AWS keys are incredibly valuable, and should be treated as such.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: