logoalt Hacker News

chinathrowyesterday at 6:33 PM2 repliesview on HN

It's also trivially easy to fix. 1 min delete and deploy.


Replies

varencyesterday at 7:33 PM

I'm guessing it's not trivial to fix without breaking other things? The weakness seems to be that anyone can turn UUIDs into details like email. But I assume this functionality is necessary for other flows so they can't just turn off all UUID->email/profile look ups. And similarly hiding author UUIDs on posts also isn't trivial.

Conceptually, I agree it should be easy, but I suspect they're stuck with legacy code and behaviors that rely on the current system. Not breaking anything else while fixing this is likely the time consuming part.

show 2 replies
UqWBcuFx6NV4rtoday at 12:33 AM

You literally don’t know that. Add this to the mammoth file titled “HN comments in which the author makes some completely unsubstantiated technical claim”