Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This approach sounds like a great way to get a lot of security holes into your code. Maybe your competitors will be faster at first, but it’s probably better to be a bit slower and not leaking all your users data.




I'm mostly thinking about the frontend.

If I had a backend API that was serving user data, I'd of course check more carefully.

This kind of mistake always seemed amateurish to me.


Fair enough. I would still personally feel uneasy about it, but I guess it’s alright if it works for others.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: