[ale] How old is this list?

DJ-Pfulio DJPfulio at jdpfu.com
Wed Feb 3 18:11:27 EST 2021


On 2/3/21 5:58 PM, Pete Hardie via Ale wrote:
> security researcher found out he could edit the response and get free
> pizza

Servers should never trust any client, especially if you wrote it.

I've seen far too many live demos where people discovered they could 
replay client-events to get stuff for little effort. Just because we 
can't do/see something, doesn't mean it isn't possible for someone else, 
maybe even trivial.

Just think of all the IoT devices that people trust when they shouldn't.
Especially door locks and security cameras and vehicles.


More information about the Ale mailing list