Hacker News new | past | comments | ask | show | jobs | submit login

I think the author wrote it up factually. Readers can make their own inferences, but Cox did share with him that the service he exploited was only introduced in 2023. Which suggests the security team did do some investigating.

I'm sure* they don't keep raw request logs around for 3+ years. I know what next steps I'd recommend, but even if they undertook those, they're not sharing that in the ticket.

(just based on industry experience; no insider knowledge.)




The point is the statementay or may not be accurate. From a journalistic perspective, unless Cox provided evidence or the author was able to otherwise independently verify the claim, it's a claim, not a fact. The comment is a good suggestion.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: