Hacker News new | past | comments | ask | show | jobs | submit login

That’s a pretty big leap to malice you just made there.



Don't think poster meant the APIs were designed to maliciously allow exploits. He meant they were intentionally developed to allow rotten code to work (because, sadly, rotten code is everywhere), and a by-product of that lax attitude unintentionally allows exploits.


“intentionally enable exploit smuggling” seemed pretty clear to me, but happy to be wrong


It may not be malice, but it is a design decision often made for robustness or future proofing that seems to backfire every time it ends up in a security critical context.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: