Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>> Images of these driver’s licenses are publicly accessible web addresses, allowing anyone with the links to access them using their web browser.

Not justifying it, but many applications consider the uniqueness of the URL enough protection to prevent discovery.

> Is this just bad development? Are these just things could be missed by any developer or team?

It's not knowing them. And when you vibe-code something, and don't prompt for it, it's not gonna do it.



> Not justifying it, but many applications consider the uniqueness of the URL enough protection to prevent discovery.

Yes, that's why it's the #1 most common web security vulnerability in production code:

https://owasp.org/Top10/A01_2021-Broken_Access_Control/

"Permitting viewing or editing someone else's account, by providing its unique identifier (insecure direct object references)"

What vibe coding promoters don't understand is that the average web developer hasn't learned web security 101. Proof: HN commenter points out that "A01:2021 – Broken Access Control" is completely normal in production code.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: