Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

They weren't in any way attempting to rely on security by obscurity.

They didn't assume nobody would guess the URL.

They did take active steps to ensure the data was only available at the correct time.

But they didn't check that their access control was working, and it wasn't.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: