frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Why UUIDs won't protect your secrets

https://alexsci.com/blog/uuids-and-idor/
18•8organicbits•2h ago

Comments

lmm•36m ago
Why would you use UUIDv7 rather than UUIDv4 though?
magnio•32m ago
UUIDv4 is much more scattered (i.e., uniformly distributed), which heavily degrades indexing performance in databases.
monkaiju•24m ago
Great piece, but worth mentioning that you generally can't use a presigned URL with CDN endpoints. So great for sensitive content, but if you rly want the thing to be widely and quickly accessible there's more work to be done
inopinatus•2m ago
Well, you can if the signed URL is signed for the CDN's verification instead of the underlying storage.

Generalising this: you don't need stateful logged-in authentication to defeat IDOR, you can include a system-specific HMAC in the construction of a shared identifier, optionally incorporating time or other scoping semantics as necessary.

This tends to make identifiers somewhat longer but still well inside the scope of an email'd URL to download your bill without having to dig up what your telco password was.

ronbenton•16m ago
I am a bit "meh" on the YouTube "unlisted video" example. The name itself is fairly transparent in implying that there's really no security, the video is just not listed in a public-facing way. This is significantly different than the article's billing example, where customers would be quite right in assuming their bills will be only accessible to them.
shoo•11m ago
> If you use secret UUIDs, think of them as toxic assets. They taint anything they touch. If they end up in logs, then logs must be kept secret. If they end up in URLs, then browser history must be kept secret. This is no small challenge.

a fun retail banking variation of this misadventure is (1) someone designs an elegant RESTful API for doing something or other (2) and it gets applied to credit cards, where the credit card number is used as the natural primary key and is RESTfully embedded in URLs, which people endeavour to avoid logging, but then when you (3) integrate middleware to report metrics to some SaaS monitoring platform, the end result is that you're spraying all your customers credit card numbers into the monitoring platform

Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

https://www.csoonline.com/article/4074962/foreign-hackers-breached-a-us-nuclear-weapons-plant-via...
1•jnord•2m ago•0 comments

Marine artillery shell detonates over freeway during Camp Pendleton event

https://taskandpurpose.com/news/camp-pendleton-marines-artillery-freeway/
1•uticus•2m ago•0 comments

iOS 26.1 Beta 4 Adds Liquid Glass Transparency Toggle

https://512pixels.net/2025/10/os-26-1-beta-4-adds-liquid-glass-transparency-toggle/
1•soheilpro•2m ago•0 comments

Normalize.css

https://csstools.github.io/normalize.css/
1•Leftium•4m ago•0 comments

Google's Pixel 10 can now run Linux apps better than other Android phones

https://www.androidauthority.com/pixel-10-linux-apps-gpu-acceleration-3608754/
1•sipofwater•5m ago•3 comments

Thoughts? "Nvidia in 5y btw $1300 and $4K" based on analysis from the link

https://www.nasdaq.com/articles/prediction-nvidia-stock-price-will-skyrocket-range-5-years
1•nomendos•6m ago•1 comments

Argentine peso weakens to fresh low despite US interventions

https://www.ft.com/content/815ef487-0d0e-430c-b140-9bc39dbd1a53
3•zerosizedweasle•11m ago•0 comments

Supreme Court will consider whether people who smoke pot can legally own guns

https://apnews.com/article/supreme-court-marijuana-guns-e86c342bf248c7822722ad027980b72b
2•Jimmc414•12m ago•0 comments

Wikipedia says traffic is falling due to AI search summaries and social video

https://techcrunch.com/2025/10/18/wikipedia-says-traffic-is-falling-due-to-ai-search-summaries-an...
2•gmays•18m ago•0 comments

OpenAI is not a serious company

2•johnnyApplePRNG•21m ago•1 comments

George F. Smoot, Who Showed How the Cosmos Began, Is Dead at 80

https://www.nytimes.com/2025/10/20/science/space/george-f-smoot-dead.html
3•bookofjoe•23m ago•2 comments

Can a University from Tennessee Help Accelerate Growth in West Palm Beach?

https://www.nytimes.com/2025/10/19/business/vanderbilt-university-expansion.html
1•paulpauper•24m ago•0 comments

An IKEA Catalog from the Near Future

https://shop.nearfuturelaboratory.com/products/ikea-catalog-from-the-near-future
1•dannyrosen•24m ago•0 comments

One Star

https://www.vice.com/en/article/one-star/
1•prawn•26m ago•0 comments

Space Debris Hits Plane (?)

https://twitter.com/Turbinetraveler/status/1979652027345940536
2•boringg•26m ago•0 comments

Lottery-Fication of Everything

https://www.dopaminemarkets.com/p/the-lottery-fication-of-everything
1•_1729•29m ago•0 comments

Tech PACs Are Closing in on the Almonds

https://www.astralcodexten.com/p/tech-pacs-are-closing-in-on-the-almonds
1•toomuchtodo•30m ago•0 comments

God Mode Unlocked – Hardware Backdoors in x86 CPUs [video]

https://www.youtube.com/watch?v=_eSAF_qT_FY
1•gjvc•35m ago•0 comments

Argentina Could Be a Superpower

https://unchartedterritories.tomaspueyo.com/p/argentina-could-be-a-superpower
13•paulpauper•40m ago•3 comments

Thoughts on everything I have written

https://www.sebjenseb.net/p/thoughts-on-everything-i-have-written
1•paulpauper•40m ago•0 comments

Explores Medellín's rebirth through the eyes of its skaters

https://wepresent.wetransfer.com/stories/lauren-luxenberg-touching-ground-medellin-photography
1•herbertl•41m ago•0 comments

Wine, Cheese and ChatGPT: Ladies' Night in San Francisco

https://www.nytimes.com/2025/10/20/style/ai-chatbot-prompt-parties-san-francisco.html
1•thoughtpeddler•42m ago•0 comments

A Day in the Life of an Infrastructure Security Engineer at Reddit

https://old.reddit.com/r/RedditEng/comments/1obos37/a_day_in_the_life_of_an_infrastructure_security/
2•herbertl•43m ago•0 comments

On Withdrawal from Social Media

https://markcarrigan.net/2025/10/20/%f0%9f%93%b1%f0%9f%9a%ab-on-withdrawal-from-social-media/
2•herbertl•44m ago•0 comments

The Rubygems.org takeover

https://lwn.net/SubscriberLink/1040778/77d921001b26d061/
5•chmaynard•44m ago•0 comments

Should Designers Prompt?

https://philip.design/blog/should-designers-prompt/
1•knowingathing•44m ago•0 comments

Trump Official Warns China Against Penalizing Companies Investing in US

https://www.bloomberg.com/news/articles/2025-10-20/trump-official-warns-china-against-penalizing-...
3•zerosizedweasle•46m ago•1 comments

Anyone here work on Amazon Kindle iOS app?

1•stmw•48m ago•1 comments

Scalability and Load Testing for Valorant (2020)

https://technology.riotgames.com/news/scalability-and-load-testing-valorant
1•prydt•49m ago•0 comments

Trump claims 'unquestioned power' in vow to send troops to San Francisco

https://www.theguardian.com/us-news/2025/oct/20/trump-san-francisco-troops
10•mitchbob•53m ago•3 comments