The answer is _always_ auth over obfuscation.
The answer is _always_ auth over obfuscation.
For anyone with prior knowledge and experience of UUID, it should be common sense that UUID will not protect any secrets, because that's not what they're for. They're a relatively unique and unguessable identifier, that's all.
Don't use a random id for security 'cause once its known, it's insecure.
This article gives me a lot of AI vibes
All statements, no logic, no solution.
I use YouTube and AWS as example since they both have implementations that are vulnerable to IDOR, but I think they made the right call. Sometimes usability takes preference over security. Sometimes 'obfuscation' is better than proper authorization.
> There are use cases where the effort needed to individually grant users access outweighs the risk of using unlisted. Not everyone is dealing in highly sensitive content, after all.