Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Do not assume that UUIDs are hard to guess; they should not be used as security capabilities

It is not just about being hard to guess a valid individual identifier in vacuum. Random (or at least random-ish) values, be they UUIDs or undecorated integers, in this context are also about it being hard to guess one from another, or a selection of others.

Wrt: "it isn't x it is y" form: I'm not an LLM, 'onest guv!





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: