Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
story
0 points
bagels
2y ago
0 comments
Share
topic_id is public information, and predictable. It's neither secret, nor random.
0 comments
default
newest
oldest
rawling
2y ago
This is a weird use case (deliberately making the hash public) and the usual concept of a salt feels weird here. Any kind of server-side secret would have effectively stopped this attack, even if it was the same in every hash.
j
/
k
navigate · click thread line to collapse