Hacker Newsnew | past | comments | ask | show | jobs | submit | dha's commentslogin

What? It's bad for security bugs to be exposed to the public rather than to have people silently exploit them?


Agreed. How about making the fnid a signed cache of often used environment variables(instead of a random string), which could also be looked up via a more time consuming method if needed. Depends really on your traffic profile how much data could reasonably and cost-effectively be cached, but it could be a very sizable portion saved by retrofitting the current method.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: