Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm interested in learning more about _how_ secure random URL parts are, and what kinds of attacks are seen in practice. Presumably an IP would get blocked after enough 404s?


I'm pretty certain 4channers are good at tracking down profile URLs from just a Facebook image URL/filename. I don't think you can access the full album per se, but you can definitely locate the profile.


that's because the image urls actually include the profile id.


I thought they changed this behaviour months ago?


I just tried it and it definitely still has the profile ID in the URL.


Why even include the original name of the file to begin with, though?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: