Anyone remember the bug as everyone had access to private photos of Marc Zuckerberg?
http://www.telegraph.co.uk/technology/facebook/8938725/Faceb...
Same auth-bypass shit.
Anyone remember the bug as everyone had access to private photos of Marc Zuckerberg?
http://www.telegraph.co.uk/technology/facebook/8938725/Faceb...
Same auth-bypass shit.
Facebook has some of the best engineers in the world. They also have their own modified version of PHP.
And really it doesn't what they use, they could use Lua and still have this issue. Don't think just because ebay used C++ or cgi or what ever they used doesn't mean ebay didn't ever have issues. Same goes for every other site/language out there.
The PHP hate is getting a little old.
I certainly agree that the problem wasn't the technology here, but I disagree with your conclusion. "some if missing somewhere" is far easier to avoid technologically than a high-level design flaw like this. It's fairly easy for a type system to notice that not all cases in a conditional are accounted for, but it's much harder for a type system to understand that it's inappropriate to use client-submitted data as a profile ID for a password reset request (as opposed to operations like submitting a friend request, where it's perfectly valid).