Why Facebook's API starts with a for loop
dev.to
dev.to
Facebook and Google can avoid security holes like these, sure. Perhaps you will too -- that is, you'll avoid this particular one. What about the fifty others, subtly interdependent sources of security problems?
I don't see how people could have prevented this without the knowledge of such an attack
I mean, I'm assuming there are service worker shenanigans at play here, but given that it's always wrong about my online status, this seems like a fairly big bug on someone's part. Just wish I knew where to file or check its status.