frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Tell HN: Medvi (telehealth) hardcodes 999 patient emails in public JavaScript

3•g48ywsJk6w48•3h ago
Medvi is a telehealth pharmacy that has received significant media attention recently. While browsing their site with DevTools open, I noticed that their public JavaScript bundle contains a hardcoded list of 999 patient email addresses — along with each patient's enrollment date, active status, and whether a care manager has been assigned. This data is downloaded by every visitor's browser before any login occurs.

The list isn't a forgotten fixture. It's actively used: the app imports it, filters for active patients, and checks whether the logged-in user's email appears in the list to decide which UI features to display. Client-side feature flagging with real patient data baked into the bundle.

The same bundle also exposes a list of Season Health (Medvi's parent company) employee emails used to bypass checkout flows, and a separate list of Open Loop Health (their clinical provider) staff emails used to bypass intake form logic — both labeled as such in the source.

This is another great demonstration that relying only on large language models for product development is premature.

Comments

speedgoose•1h ago
Looks like you used a LLM to write your post, or am I wrong?

Tell HN: An app is silently installing itself on my iPhone every day

182•_-x-_•6h ago•85 comments

Tell HN: Medvi (telehealth) hardcodes 999 patient emails in public JavaScript

3•g48ywsJk6w48•3h ago•1 comments

Ask HN: What file sharing apps do you guys use?

3•samarthv•4h ago•7 comments

Tell HN: Claude 4.7 is ignoring stop hooks

90•LatencyKills•1d ago•85 comments

Ask HN: Oh, What Places to Go (Seriously Tho)

4•thx•6h ago•7 comments

Ask HN: Do you read differently now that anything could be AI generated?

8•dwa3592•14h ago•16 comments

Ask HN: How did the industry settle on weekly limits?

3•saratogacx•9h ago•8 comments

Batteries Included CLI Framework

5•maxalbarello•14h ago•6 comments

Ask HN: Is anyone working on Gov Digital IDs or have implementation docs / FOSS

4•lifeisstillgood•14h ago•1 comments

Ask HN: Anyone managed to get Google trends API?

7•visox•17h ago•0 comments

Ask HN: Is Zuckerberg just a „one-hit-wonder"?

11•fandorin•19h ago•15 comments

Ask HN: Do you waste AI assisted time looking for answers?

2•Haeuserschlucht•14h ago•2 comments

Ask HN: MicroVM setup for VS Code Dev Container-like experience?

4•Erndob•1d ago•2 comments

Ask HN: Cyberdecks are cool but do they serve a purpose?

7•hamiecod•14h ago•2 comments

How to Attend the Altman vs. Musk Trial

8•major4x•13h ago•0 comments

Ask HN: How do solo devs protect their work in the age of vibe coding?

27•langs•2d ago•15 comments

Ask HN: Scaling a targeted web crawler beyond 500M pages/day

22•honungsburk•1d ago•9 comments

Tell HN: YouTube RSS feeds no longer work

39•019•3d ago•14 comments

GPT-5.5 – No ARC-AGI-3 scores

19•AG25•2d ago•3 comments

Ask HN: Any recommendataions for exporting data from Amazon?

7•coreyp_1•1d ago•2 comments

Ask HN: Chrome, Brave, Firefox or Something Else?

15•wasimsk•1d ago•18 comments

Tell HN: Codex macOS app switches to Fast speed after update without asking

10•mfi•1d ago•1 comments

Ask HN: Anyone still using JetBrains products today?

7•zkid18•1d ago•8 comments

How good is Mac Studio M3 Ultra for Trillion param models like DeepSeekv4?

8•namegulf•1d ago•7 comments

Tell HN: Anthropic won't reset usage limits for those who downgraded

9•vintagedave•1d ago•0 comments

Ask HN: Why are companies so distrustful of remote employees?

24•lyfeninja•2d ago•24 comments

Hey, it's Earth Day today

25•burnt-resistor•3d ago•17 comments

Ask HN: How are you using AI code assistants on large messy legacy code bases?

13•thinkingtoilet•1d ago•13 comments

Can non-developer build commercial products with AI

10•rkorlimarla•2d ago•11 comments

Anthropic bans orgs without warning

44•alpinisme•4d ago•20 comments